🇨🇾

Cyprus (CY)

Updated 27 Jun 2026Schema world-payments-v1Baseline wpm-2026-06-27

Lead Signal

The World Payments Monitor establishes its full standing baseline for Cyprus this cycle, mapping the operating environment across all fourteen modules and surfacing a jurisdiction that is consolidating its position as an EU-harmonised, multi-pillar payments and crypto venue. The defining structural fact is that Cyprus runs an EU-harmonised dual PI/EMI authorisation regime supervised by the Central Bank of Cyprus: payment institutions under Law 31(I)/2018 (PSD2), electronic money institutions under Laws 81(I)/2012 & 2018 (EMD2), with authorisation granted only to legal persons incorporated and headquartered in Cyprus, and AISPs registering under section 34. This incorporation and head-office requirement constrains shell-only structures and defines the market-access route for any non-bank operator seeking to passport across the EEA.

Layered on top of this licensing spine, Cyprus applies MiCA (Reg (EU) 2023/1114) with a clear competent-authority split: EMTs (Title IV) are economically assimilated to e-money and fall to the CBC, while CySEC supervises ARTs (Title III), other crypto-assets (Title II) and CASPs (Title V), with EMT issuance restricted to credit institutions and EMIs. That issuance restriction is a structural gating constraint — a MiCA CASP licence alone is insufficient to launch a stablecoin from Cyprus. The most visible commercial validation of the jurisdiction's CASP regime is Revolut formally receiving a MiCA CASP licence from CySEC in October 2025, allowing regulated crypto services across all 30 EEA countries and making its Cyprus base the centre of its EEA crypto operations.

Outlook

The near-term horizon is dominated by the MiCA transitional cliff-edge: CASPs operating under national transitional rules must hold full MiCA authorisation by 1 July 2026 or cease, with the precise application-lodgement milestone still ambiguous in the sourcing. Over the medium term, the CBC targets readiness for a possible first digital-euro issuance in 2029, conditional on EU legislation being adopted during 2026. Commercially, Bank of Cyprus signalled in March 2026 that it remains open to strategically targeted fintech and insurance acquisitions under its 2026-2028 plan, identifying fintech as a greater competitive challenge than traditional banks, against a backdrop of rising sector M&A and the new 8% flat tax on crypto-asset disposal gains effective 1 January 2026. The overall direction of travel is stable-with-tightening conduct: an EU-harmonised framework attracting crypto re-domiciliation inflow while the CBC steadily raises governance and suitability expectations.

Confidence
Confirmed
Forward deadlines
1

Other Developments

The conduct and governance layer is tightening. The CBC introduced new directives effective from 2025 strengthening the EMI/PSP framework across capital adequacy, governance and risk-management oversight — including the Internal Organisation and Governance of EMIs Directive (with ICT/DORA-aligned obligations, outsourcing, complaints and whistleblowing provisions) and the 2025 Suitability Directive assessed via CBC e-platform personal questionnaires. Safeguarding of user funds through segregation or insurance/guarantee cover is mandated under the EMI/PI laws, with the CBC adopting EBA safeguarding guidance (EBA/GL/2018/05); critically, deposit protection does not apply to non-bank PIs and EMIs.

On operational resilience, DORA (Reg (EU) 2022/2554) is directly applicable from 17 January 2025, with CySEC and the CBC supervising in-scope entities and CySEC issuing Circular C751 in early 2026, subject to proportionality relief on advanced threat-led penetration testing for smaller PIs and EMIs. Card-scheme economics are governed by the EU Interchange Fee Regulation (EU 2015/751), implemented by Cyprus Law N.77(I)/2018 with caps of 0.2% (debit) and 0.3% (credit), while SEPA SCT Inst rails operate under the EU Instant Payments Regulation with mandatory Verification of Payee via the Eurosystem TIPS service.

On enforcement, CySEC reported imposing approximately EUR 2.3 million in fines and around 600 inspections in its 2025 review, approving 47 new licences including 8 CASPs. Two challenger-identified quantitative discrepancies remain unreconciled and are carried at Assessed: the supervised PI/EMI population (research cites 26 EMIs and 11 PIs against an official figure of 29 EMIs and 10 PIs) and the sanctions-criminalisation penalty ceiling (EUR 5 million or 10% of turnover against a divergent EUR 40 million or 5% of global turnover figure). Both require reconciliation to official sources before any downstream reliance.

The domestic market structure is bank-led at the acquiring layer, dominated by JCC Payment Systems Ltd, a bank-owned consortium in which Bank of Cyprus holds a controlling interest. High-risk merchant categories are typically refused by the domestic acquirer, leaving a structural gap filled by specialist and cross-border PSPs.

Cross-Monitor Connections

The W11 AML/CFT surface for Cyprus is Sentinel-fed: the framework rests on the AML/CFT Law of 2007 and Sanctions Law of 2016, with MOKAS as the FIU and CASPs subject to the EBA Travel Rule and CDD thresholds. Original illicit-finance analysis — including CASP Travel Rule application, MOKAS reporting and the bank-versus-CASP supervision gap — is flagged to the Financial Integrity Monitor rather than analysed here. The EMT-issuance framework and the new 8% crypto-disposal tax carry corridor and stablecoin-integrity significance that is also referred to FIM for review of the sanctions-evasion dimension.

View as
Standing baseline position per module · click a card to expand its full sub-brief

Domains

14 regulatory modules · click to expand the full sub-brief
W1a

Licensing, Authorisation & Market Access

Confirmed

Cyprus operates an EU-harmonised dual PI/EMI authorisation regime supervised by the Central Bank of Cyprus.

W2

Stablecoins & Digital Money

Confirmed

Cyprus applies MiCA (Reg (EU) 2023/1114) with a defined competent-authority split.

W12

Correspondent Banking, Settlement & Access

Confirmed

The analytical spine of this module is the bank-versus-non-bank settlement-access asymmetry.

W1b

Conduct, Safeguarding & Promotions

Confirmed

Safeguarding of user funds — through segregation or insurance/guarantee cover — is mandated under the EMI/PI laws, with the CBC adopting EBA safeguarding guidance (EBA/GL/2018/05) and EBA authorisation guidance (EBA/GL/2017/09) for both application and ongoing supervision.

W3

Operational Resilience & Critical Infra

Confirmed

DORA (Reg (EU) 2022/2554) is directly applicable from 17 January 2025, with CySEC and the CBC supervising in-scope entities including banks, PIs, EMIs, investment firms, CASPs and critical ICT third parties.

W4

Scheme & Network Compliance

Confirmed

Card-scheme economics are governed by the EU Interchange Fee Regulation (EU 2015/751), implemented in Cyprus by Law N.77(I)/2018, with caps of 0.2% on debit and 0.3% on credit.

+ 8 more domains — W5 Payment Corridor Dynamics, W6 Industry Structure & Commercial, W7 Legal & Litigation, W8 Merchant Acquiring & Risk, W9 Product Innovation & Market Development, W10 Consumer Protection & APP Fraud, W11 AML/CFT & Financial Crime (Sentinel.gi-fed), W13 Commercial Intelligence (M&A, Investment & Product).
Full per-domain detail — all 14 modules

W1aConfirmedLicensing, Authorisation & Market Access

see this theme across all jurisdictions →5 claims

EU-harmonised dual PI/EMI authorisation regime under CBC: PIs Law 31(I)/2018 (PSD2), EMIs Laws 81(I)/2012&2018 (EMD2). EMI initial capital EUR 350k; PI tiered EUR 20k/50k/125k; no small-institution regime. CASP/MiCA sits with CySEC.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Licensing, Authorisation & Market Access

Cyprus operates an EU-harmonised dual PI/EMI authorisation regime supervised by the Central Bank of Cyprus. Payment institutions are authorised under Law 31(I)/2018 (transposing PSD2) and electronic money institutions under Laws 81(I)/2012 & 2018 (transposing EMD2). Authorisation is granted only to legal persons incorporated and headquartered in Cyprus, with at least part of the payment-service business carried out there; account information service providers register under section 34. This is a non-bank PI/EMI authorisation track, distinct from the bank-PSP route, and the incorporation and head-office requirement directly constrains shell-only structures.

Capital tiering defines the cost of entry. EMI initial capital is EUR 350,000; PI initial capital is tiered — EUR 20,000 for money remittance only, EUR 50,000 for PIS only, and EUR 125,000 for full services under Annex I points 1-5. No small-institution regime exists, and the CBC may prevent the multiple use of own-funds elements within a group. The absence of a de-minimis PI route raises the floor relative to jurisdictions offering one, a direct cost-of-entry signal for non-bank operators weighing Cyprus as a passporting base across the EEA. CASP and MiCA competence sits with CySEC rather than within this licensing track.

Outlook

The W1a standing position is established and Confirmed on two Tier-1 CBC anchors. No near-term change to the core authorisation architecture is signalled; the live pressure is at the conduct and governance layer (W1b) rather than in licensing thresholds. Watch for any movement on a small-institution route, the absence of which remains the distinguishing competitive feature of the regime.

W1aLicensing, Authorisation & Market AccessConfirmed
EU-harmonised dual PI/EMI authorisation regime under CBC: PIs Law 31(I)/2018 (PSD2), EMIs Laws 81(I)/2012&2018 (EMD2). EMI initial capital EUR 350k; PI tiered EUR 20k/50k/125k; no small-institution regime. CASP/MiCA sits with CySEC.
all · compliance · analyst · board
Evidence 5 claims ›

W2ConfirmedStablecoins & Digital Money

see this theme across all jurisdictions →4 claims

MiCA (Reg (EU) 2023/1114): CBC is competent authority for EMTs (Title IV); CySEC supervises ARTs (Title III), other crypto-assets (Title II) and CASPs (Title V). EMT issuance restricted to credit institutions/EMIs. Transitional window to 1 July 2026.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Stablecoins & Digital Money

Cyprus applies MiCA (Reg (EU) 2023/1114) with a defined competent-authority split. EMTs (Title IV) are economically assimilated to e-money and excluded from CySEC's mandate, leaving the CBC as the competent authority for EMTs; CySEC supervises ARTs (Title III), other crypto-assets (Title II) and CASPs (Title V), with significant ARTs and EMTs drawing additional EBA supervision. EMT issuance is restricted to credit institutions and EMIs. The practical consequence is structural: a MiCA CASP licence alone is insufficient to launch a stablecoin from Cyprus — an issuer must hold credit-institution or EMI status, a gating constraint that separates crypto-service activity from stablecoin issuance. This carries the bank-versus-non-bank distinction directly into the digital-money layer.

A transitional window is closing. CySEC transitional guidance under MiCA Art.143 allows CASPs compliant with national rules before 30 December 2024 to continue until 1 July 2026 — the hard enforcement deadline — or until granted or denied MiCA authorisation, whichever is first. Research cites a 10 January 2025 compliance-evidence submission deadline, but a 2026 source reports the existing-CASP application lodgement deadline as 27 February 2026; this procedural milestone is carried at Assessed pending reconciliation, while the 1 July 2026 hard deadline is robust.

Outlook

The W2 standing position is established and Confirmed on the competent-authority split and issuance restriction. The dominant forward event is the 1 July 2026 transitional cliff-edge, forcing incumbent CASPs to obtain full MiCA authorisation or exit. The distinct application-lodgement milestones should be disambiguated before publication-level reliance.

W2Stablecoins & Digital MoneyConfirmed
MiCA (Reg (EU) 2023/1114): CBC is competent authority for EMTs (Title IV); CySEC supervises ARTs (Title III), other crypto-assets (Title II) and CASPs (Title V). EMT issuance restricted to credit institutions/EMIs. Transitional window to 1 July 2026.
all · compliance · analyst · board
Evidence 4 claims ›

W12ConfirmedCorrespondent Banking, Settlement & Access

see this theme across all jurisdictions →3 claims

Settlement via T2-CY (replaced TARGET2 20 Mar 2023); Settlement Finality Law; TIPS + CCBM connectivity; non-euro flows exposed to de-risking.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Correspondent Banking, Settlement & Access

The analytical spine of this module is the bank-versus-non-bank settlement-access asymmetry. Settlement runs through T2-CY, the Cyprus component of the Eurosystem T2 RTGS, which replaced TARGET2 on 20 March 2023; participants are Cyprus credit institutions, the Cyprus Stock Exchange, CY-SDD, the Cyprus Clearing House, JCC Cards and the CBC. Settlement finality is provided by the Settlement Finality Law, and Cyprus is connected to TIPS and the CCBM for collateral mobilisation. Direct euro settlement finality is therefore a bank-PSP privilege.

Non-euro flows, by contrast, depend on correspondent relationships exposed to global de-risking, with an approximately 25% reduction in correspondent relationships between 2011 and 2022. The result is a structural settlement-access constraint that falls hardest on smaller Cyprus institutions and on non-bank PIs and EMIs that lack direct access to the euro RTGS layer.

Outlook

The W12 standing position is Confirmed on three Tier-1 anchors. The euro settlement layer is stable; the live risk vector is the de-risking-driven fragility in non-euro correspondent access, which the corridor tracker records as closing for smaller institutions and PIs/EMIs.

W12Correspondent Banking, Settlement & AccessConfirmed
Settlement via T2-CY (replaced TARGET2 20 Mar 2023); Settlement Finality Law; TIPS + CCBM connectivity; non-euro flows exposed to de-risking.
all · compliance · analyst · board
Evidence 3 claims ›

W1bConfirmedConduct, Safeguarding & Promotions

see this theme across all jurisdictions →4 claims

Safeguarding of user funds (segregation or insurance/guarantee) is mandated under the EMI/PI laws, with CBC adopting EBA safeguarding guidance (EBA/GL/2018/05). In 2025-2026 the CBC issued new directives strengthening EMI/PSP governance, capital and suitability, and the Internal Organisation and Governance of EMIs Directive (incorporating by analogy the Internal Organisation and Governance of Payment Institutions Directive of 2026) moved governance to a structured, board-accountable obligation. Suitability of management body members is assessed under the 2025 Suitability Directive.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Conduct, Safeguarding & Promotions

Safeguarding of user funds — through segregation or insurance/guarantee cover — is mandated under the EMI/PI laws, with the CBC adopting EBA safeguarding guidance (EBA/GL/2018/05) and EBA authorisation guidance (EBA/GL/2017/09) for both application and ongoing supervision. The mechanism applies to non-bank PIs and EMIs, for which deposit protection does not apply; the segregation-versus-insurance choice directly affects operating-account structure and client-trust positioning. This is the bank-PSP versus non-bank PI/EMI distinction in operational form: customer-fund protection here is a prudential and conduct obligation, not a depositor-guarantee backstop.

The conduct layer is tightening. The CBC introduced new directives effective from 2025 strengthening the EMI/PSP framework across capital adequacy, governance and risk-management oversight — covering fund safeguarding and AML — including the Internal Organisation and Governance of EMIs Directive (incorporating by analogy the Internal Organisation and Governance of Payment Institutions Directive of 2026: management body, internal controls, ICT/DORA-aligned obligations, outsourcing, complaints and whistleblowing) and the 2025 Suitability Directive assessed via CBC e-platform personal questionnaires. Board-level accountability and suitability assessment raise the compliance and governance overhead for EMIs and PIs domiciling in Cyprus.

Outlook

The W1b trajectory is tightening, held at High. Governance and suitability obligations are moving toward board-accountable standards, and challenger reporting of further May-2026 governance-rule tightening is consistent with this direction. Expect continued upward pressure on conduct and governance compliance for non-bank PIs and EMIs.

W1bConduct, Safeguarding & PromotionsConfirmed
Safeguarding of user funds (segregation or insurance/guarantee) is mandated under the EMI/PI laws, with CBC adopting EBA safeguarding guidance (EBA/GL/2018/05). In 2025-2026 the CBC issued new directives strengthening EMI/PSP governance, capital and suitability, and the Internal Organisation and Governance of EMIs Directive (incorporating by analogy the Internal Organisation and Governance of Payment Institutions Directive of 2026) moved governance to a structured, board-accountable obligation. Suitability of management body members is assessed under the 2025 Suitability Directive.
all · compliance · analyst · board
Evidence 4 claims ›

W3ConfirmedOperational Resilience & Critical Infra

see this theme across all jurisdictions →3 claims

Operational resilience is governed by DORA (Regulation (EU) 2022/2554), directly applicable from 17 January 2025, with CySEC and CBC as the supervising authorities for in-scope entities (banks, PIs, EMIs, investment firms, CASPs). DORA mandates ICT risk-management frameworks, incident classification/reporting, digital operational resilience testing (TLPT every three years for significant entities, with proportionality exemptions for smaller PIs/EMIs) and ICT third-party/outsourcing oversight. CySEC issued implementing guidance, including Circular C751 in early 2026.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Operational Resilience & Critical Infra

DORA (Reg (EU) 2022/2554) is directly applicable from 17 January 2025, with CySEC and the CBC supervising in-scope entities including banks, PIs, EMIs, investment firms, CASPs and critical ICT third parties. Non-microenterprise entities must run a digital operational resilience testing programme, with advanced threat-led penetration testing every three years for those carrying significant ICT risk, and exemptions available for PSD2/EMD-exempt PIs and EMIs. CySEC issued Circular C751 in early 2026. The regime applies across both bank-PSP and non-bank PI/EMI populations, imposing a fixed resilience compliance baseline on all Cyprus payments entities while preserving TLPT proportionality relief for smaller PIs and EMIs.

Outlook

The W3 trajectory is established and Confirmed: the direct-applicability date is a supranational fact, and multiple Cyprus-specific sources plus the named CySEC circular support the standing position. ICT-risk, incident-reporting and third-party oversight obligations are now embedded; the operational focus shifts to supervisory implementation under Circular C751.

W3Operational Resilience & Critical InfraConfirmed
Operational resilience is governed by DORA (Regulation (EU) 2022/2554), directly applicable from 17 January 2025, with CySEC and CBC as the supervising authorities for in-scope entities (banks, PIs, EMIs, investment firms, CASPs). DORA mandates ICT risk-management frameworks, incident classification/reporting, digital operational resilience testing (TLPT every three years for significant entities, with proportionality exemptions for smaller PIs/EMIs) and ICT third-party/outsourcing oversight. CySEC issued implementing guidance, including Circular C751 in early 2026.
all · compliance · analyst · board
Evidence 3 claims ›

W4ConfirmedScheme & Network Compliance

see this theme across all jurisdictions →4 claims

Card-scheme economics are governed by the EU Interchange Fee Regulation (EU 2015/751) implemented domestically by Cyprus Law N.77(I)/2018, with the CBC, the Commission for the Protection of Competition and the Consumer Protection Service as joint competent authorities. Caps are 0.2% (debit) and 0.3% (credit). Visa, Mastercard, Diners and China UnionPay schemes run through JCC, the domestic acquirer/processor. PCI DSS and 3-D Secure apply at the acquiring layer. SEPA SCT Inst rails operate under the EU Instant Payments Regulation with mandatory Verification of Payee.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Scheme & Network Compliance

Card-scheme economics are governed by the EU Interchange Fee Regulation (EU 2015/751), implemented in Cyprus by Law N.77(I)/2018, with caps of 0.2% on debit and 0.3% on credit. The CBC, the Commission for the Protection of Competition and the Consumer Protection Service are joint competent authorities. Acquirers must individually specify merchant service charges by card category and brand unless blended charging is requested in writing — an unblending requirement that shapes MSC transparency for Cyprus merchants and fixes the acquiring-side cost floor.

On the account-to-account side, SEPA SCT Inst rails operate under the EU Instant Payments Regulation with mandatory Verification of Payee; the CBC acts as lead operator facilitating access to the Eurosystem TIPS service, with wide SCT Inst adoption around 9 January 2025. Mandatory VoP and universal SCT Inst availability at standard-transfer pricing reshape A2A competitiveness against cards for Cyprus PSPs across both bank and non-bank populations.

Outlook

The W4 standing position is established, with the IFR layer Confirmed on two Tier-1 anchors and the instant-payments layer held at High. No scheme-rule change is signalled near term; the structural watch is the competitive shift from cards toward instant A2A as VoP and SCT Inst pricing mature.

W4Scheme & Network ComplianceConfirmed
Card-scheme economics are governed by the EU Interchange Fee Regulation (EU 2015/751) implemented domestically by Cyprus Law N.77(I)/2018, with the CBC, the Commission for the Protection of Competition and the Consumer Protection Service as joint competent authorities. Caps are 0.2% (debit) and 0.3% (credit). Visa, Mastercard, Diners and China UnionPay schemes run through JCC, the domestic acquirer/processor. PCI DSS and 3-D Secure apply at the acquiring layer. SEPA SCT Inst rails operate under the EU Instant Payments Regulation with mandatory Verification of Payee.
all · compliance · analyst · board
Evidence 4 claims ›

W5HighPayment Corridor Dynamics

see this theme across all jurisdictions →3 claims

As a euro-area member, Cyprus's principal corridors are euro-denominated SEPA flows (SCT, SCT Inst, SDD) settled in T2-CY, with non-euro cross-border flows reliant on correspondent networks. The Cyprus SEPA Direct Debit system (CY-SDD) has operated since 2014, settling in T2-CY; TIPS access provides pan-European instant reach across the 36-country SEPA zone. The CBC operates TARGET-CY and stands ready to support local credit institutions accessing TIPS.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Payment Corridor Dynamics

As a euro-area member, Cyprus's principal corridors are euro-denominated SEPA flows — SCT, SCT Inst and SDD — settled in T2-CY, with CY-SDD having operated since 2014. TIPS access provides pan-European instant reach across the 36-country SEPA zone. Non-euro cross-border flows, by contrast, rely on correspondent networks. The structural corridor-risk axis for Cyprus operators is the contrast between euro-corridor strength via SEPA and TIPS and the dependence on correspondent banking for non-euro flows.

Outlook

The W5 trajectory is stable, held at High, with the SEPA and CY-SDD anchors on a Tier-1 CBC page and cross-border correspondent reliance on lower-tier sourcing. The euro-corridor position is settled; the live risk lies in the non-euro correspondent dimension, treated more fully under W12.

W5Payment Corridor DynamicsHigh
As a euro-area member, Cyprus's principal corridors are euro-denominated SEPA flows (SCT, SCT Inst, SDD) settled in T2-CY, with non-euro cross-border flows reliant on correspondent networks. The Cyprus SEPA Direct Debit system (CY-SDD) has operated since 2014, settling in T2-CY; TIPS access provides pan-European instant reach across the 36-country SEPA zone. The CBC operates TARGET-CY and stands ready to support local credit institutions accessing TIPS.
all · compliance · analyst · board
Evidence 3 claims ›

W6ConfirmedIndustry Structure & Commercial

see this theme across all jurisdictions →4 claims

The Cyprus payments market is bank-led at the acquiring layer, dominated by JCC Payment Systems Ltd — a bank-owned consortium (Bank of Cyprus holds a controlling/circa-75% interest; other shareholders include Hellenic Bank, Alpha Bank Cyprus, National Bank of Greece (Cyprus) and AstroBank) acting as the primary card processor. As of 2026 the CBC supervises around 26 EMIs and 11 PIs. Card payments accounted for ~74.5% of cashless transactions in H1 2025, above the euro-area average, and fintechs are emerging as a competitive challenge to incumbent banks.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Industry Structure & Commercial

The Cyprus payments market is bank-led at the acquiring layer, dominated by JCC Payment Systems Ltd, a bank-owned consortium in which Bank of Cyprus holds a controlling interest alongside shareholders including Hellenic Bank, Alpha Bank Cyprus, National Bank of Greece (Cyprus) and AstroBank. JCC is the primary card processor and acquirer for Visa, Mastercard and Diners. The exact controlling percentage varies across sources — one cites approximately 75%, an older source cites a historic 45% pre-resolution — so the controlling-interest characterisation is held at High rather than Confirmed and the specific figure is reported, not asserted. This concentration of domestic card acquiring in a single bank-consortium entity defines the competitive structure and the entry challenge for cross-border acquirers.

Research cites the CBC supervising 26 EMIs and 11 PIs as of 2026, though a challenger-identified May-2026 source citing an official CBC statement gives 29 EMIs and 10 PIs; the count is carried at Assessed pending reconciliation to the official figure. Card payments accounted for approximately 74.5% of cashless transactions in H1 2025, above the euro-area average, and the digital payments market is projected to grow from $2.76bn in 2025 to $6.70bn in 2030, with fintechs emerging as competition to incumbent banks.

Outlook

The W6 trajectory is established. The acquiring-concentration spine is durable; the supervised-population count must be reconciled to the CBC official statement before publication. The card-share and growth trajectory frame an intensifying competitive landscape for new entrants.

W6Industry Structure & CommercialConfirmed
The Cyprus payments market is bank-led at the acquiring layer, dominated by JCC Payment Systems Ltd — a bank-owned consortium (Bank of Cyprus holds a controlling/circa-75% interest; other shareholders include Hellenic Bank, Alpha Bank Cyprus, National Bank of Greece (Cyprus) and AstroBank) acting as the primary card processor. As of 2026 the CBC supervises around 26 EMIs and 11 PIs. Card payments accounted for ~74.5% of cashless transactions in H1 2025, above the euro-area average, and fintechs are emerging as a competitive challenge to incumbent banks.
all · compliance · analyst · board
Evidence 4 claims ›

W7HighLegal & Litigation

see this theme across all jurisdictions →3 claims

Enforcement in the payments-adjacent space is driven by CySEC (CIFs, CASPs, funds) and CBC (credit institutions, PIs, EMIs), plus the National Sanctions Implementation Unit (NSIU). In its 2025 review CySEC reported imposing €2.3 million in fines and ~600 inspections, with thematic inspections in retail FX/CFD and crypto-asset sectors producing administrative fines for sanctions-screening and prudential-reporting deficiencies. The Criminalisation of the Violation of Restrictive Measures Law (2025) empowers the NSIU to impose fines up to €5 million or 10% of annual turnover. CySEC lacks restitution powers; consumer redress runs through the Financial Ombudsman and the District Courts.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Legal & Litigation

In its 2025 review CySEC reported imposing approximately EUR 2.3 million in fines and around 600 inspections across CIFs, asset managers, funds, issuers and market infrastructures, approving 47 new licences including 8 CASPs. Thematic inspections in retail FX/CFD and crypto produced administrative fines for sanctions-screening and prudential-reporting deficiencies. CySEC lacks restitution powers; redress runs via the Financial Ombudsman and District Courts.

Separately, the Criminalisation of the Violation of Restrictive Measures Law (2025) empowers the National Sanctions Implementation Unit to impose fines. Research cites up to EUR 5 million or 10% of annual turnover with trading suspensions for reporting failures, but a divergent 2025 source reports legal-entity fines of up to 5% of global turnover or EUR 40 million (whichever higher), with individual imprisonment exposure and entry into force around 1 August 2025 implementing EU Directive 2024/1226. The penalty ceiling and entry-into-force date are carried at Assessed pending reconciliation.

Outlook

The W7 trajectory is stable, held at High on the enforcement figures (confirmed by challenger review) but with the sanctions-penalty ceiling contested. The compliance-risk signal is clear — intensifying sanctions-screening enforcement with no regulator restitution power — but the exact penalty exposure requires reconciliation to official sources.

W7Legal & LitigationHigh
Enforcement in the payments-adjacent space is driven by CySEC (CIFs, CASPs, funds) and CBC (credit institutions, PIs, EMIs), plus the National Sanctions Implementation Unit (NSIU). In its 2025 review CySEC reported imposing €2.3 million in fines and ~600 inspections, with thematic inspections in retail FX/CFD and crypto-asset sectors producing administrative fines for sanctions-screening and prudential-reporting deficiencies. The Criminalisation of the Violation of Restrictive Measures Law (2025) empowers the NSIU to impose fines up to €5 million or 10% of annual turnover. CySEC lacks restitution powers; consumer redress runs through the Financial Ombudsman and the District Courts.
all · compliance · analyst · board
Evidence 3 claims ›

W8HighMerchant Acquiring & Risk

see this theme across all jurisdictions →3 claims

Domestic merchant acquiring is dominated by JCC Payment Systems, the primary card processor and acquirer for Visa, Mastercard, Diners and China UnionPay, providing the JCC Gateway (online card capture and 3-D Secure), JCCsmart (public-sector/biller acceptance), POS terminals, fraud controls, tokenisation, rolling reserves and chargeback handling. Cross-border PSPs (Adyen, Stripe, Mollie, Worldline) compete for EU-footprint merchants. High-risk merchant onboarding is constrained by bank AML/KYC policies, with specialist high-risk providers and PayFac models filling the gap.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Merchant Acquiring & Risk

Domestic merchant acquiring is dominated by JCC, the primary acquirer for Visa, Mastercard, Diners and China UnionPay, providing JCC Gateway with online capture and 3-D Secure, JCCsmart, POS terminals, tokenisation, rolling reserves and chargeback handling, with 47-currency processing and PCI DSS / 3-D Secure compliance. High-risk merchant categories — online casinos, pharma, dating — are typically refused by the domestic bank-PSP acquirer; cross-border PSPs including Adyen, Stripe, Mollie and Worldline compete for EU-footprint merchants. The refusal of high-risk MCCs by the domestic acquirer creates a structural gap filled by specialist and PayFac providers — a recurring, under-indexed merchant-acquiring dynamic.

Outlook

The W8 trajectory is stable, held at High on three corroborating sources. The domestic-versus-cross-border split is durable; the analytical watch is the persistence of the high-risk MCC gap and the role of specialist PSPs in filling it.

W8Merchant Acquiring & RiskHigh
Domestic merchant acquiring is dominated by JCC Payment Systems, the primary card processor and acquirer for Visa, Mastercard, Diners and China UnionPay, providing the JCC Gateway (online card capture and 3-D Secure), JCCsmart (public-sector/biller acceptance), POS terminals, fraud controls, tokenisation, rolling reserves and chargeback handling. Cross-border PSPs (Adyen, Stripe, Mollie, Worldline) compete for EU-footprint merchants. High-risk merchant onboarding is constrained by bank AML/KYC policies, with specialist high-risk providers and PayFac models filling the gap.
all · compliance · analyst · board
Evidence 3 claims ›

W9HighProduct Innovation & Market Development

see this theme across all jurisdictions →4 claims

Cyprus runs dual innovation infrastructure: the CBC Innovation Hub (non-binding guidance for payments/banking fintech and the EMT/stablecoin boundary) and the CySEC Innovation Hub (active since 2018) plus a full CySEC Regulatory Sandbox launched in 2024 for supervised live testing (typically up to six months) of fintech/crypto models. Open-banking cash-flow analysis operates under PSD2; SCT Inst, request-to-pay and mobile wallets (Apple Pay, Google Wallet) are live. The CBC targets readiness for a possible first digital euro issuance in 2029, subject to EU legislation in 2026. The 2025 national eID scheme strengthened remote onboarding.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Product Innovation & Market Development

Cyprus runs dual innovation infrastructure: the CBC Innovation Hub covering payments and banking fintech and the EMT/stablecoin boundary, and the CySEC Innovation Hub operating since 2018 alongside a full CySEC Regulatory Sandbox launched in 2024 for supervised live testing, typically up to six months. Open-banking cash-flow analysis operates under PSD2; SCT Inst, request-to-pay and mobile wallets (Apple Pay, Google Wallet) are live. The CBC targets readiness for a possible first digital-euro issuance in 2029, subject to EU legislation in 2026. Sandbox and innovation-hub access, together with digital-euro readiness, signal regulatory openness and act as a market-development draw for fintech domiciliation across both bank and non-bank operators.

Outlook

The W9 trajectory is established, held at High. The thematic, regulatory product-access view here is distinct from discrete commercial launches carried under W13. The forward marker is the digital-euro readiness target of 2029, conditional on EU legislation during 2026.

W9Product Innovation & Market DevelopmentHigh
Cyprus runs dual innovation infrastructure: the CBC Innovation Hub (non-binding guidance for payments/banking fintech and the EMT/stablecoin boundary) and the CySEC Innovation Hub (active since 2018) plus a full CySEC Regulatory Sandbox launched in 2024 for supervised live testing (typically up to six months) of fintech/crypto models. Open-banking cash-flow analysis operates under PSD2; SCT Inst, request-to-pay and mobile wallets (Apple Pay, Google Wallet) are live. The CBC targets readiness for a possible first digital euro issuance in 2029, subject to EU legislation in 2026. The 2025 national eID scheme strengthened remote onboarding.
all · compliance · analyst · board
Evidence 4 claims ›

W10HighConsumer Protection & APP Fraud

see this theme across all jurisdictions →3 claims

Consumer protection rests on PSD2-derived conduct rules, transparency/disclosure obligations, and EBA consumer-protection guidance adopted by the CBC. The Office of the Cyprus Financial Commissioner (Financial Ombudsman), established under Law 84(I)/2010, handles consumer complaints against banks, PIs/EMIs and other financial institutions up to €250,000 (€20 fee; decisions binding only if accepted by both parties). For instant-payment fraud, the EU Instant Payments Regulation's mandatory Verification of Payee (payee name/IBAN matching) is the principal APP/misdirection-fraud control; Cyprus does not have a UK-style mandatory APP-fraud reimbursement scheme.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Consumer Protection & APP Fraud

Consumer protection rests on PSD2-derived conduct rules and EBA consumer-protection guidance adopted by the CBC. The Financial Ombudsman, under Law 84(I)/2010, handles complaints against banks, PIs/EMIs and other financial institutions up to EUR 250,000, with a EUR 20 fee and decisions binding only if accepted by both parties. For instant-payment fraud, the EU Instant Payments Regulation's mandatory Verification of Payee is the principal APP and misdirection control. Critically, Cyprus has no UK-style mandatory APP-fraud reimbursement scheme — a material differentiator in consumer-protection liability exposure for PSPs relative to the UK PSR model.

Outlook

The W10 trajectory is stable, held at High, with the redress mechanics on two Tier-1 Financial Ombudsman pages. The absence of a mandatory APP-reimbursement scheme is recorded as not applicable in the current regime and remains the key liability-exposure distinction for Cyprus PSPs.

W10Consumer Protection & APP FraudHigh
Consumer protection rests on PSD2-derived conduct rules, transparency/disclosure obligations, and EBA consumer-protection guidance adopted by the CBC. The Office of the Cyprus Financial Commissioner (Financial Ombudsman), established under Law 84(I)/2010, handles consumer complaints against banks, PIs/EMIs and other financial institutions up to €250,000 (€20 fee; decisions binding only if accepted by both parties). For instant-payment fraud, the EU Instant Payments Regulation's mandatory Verification of Payee (payee name/IBAN matching) is the principal APP/misdirection-fraud control; Cyprus does not have a UK-style mandatory APP-fraud reimbursement scheme.
all · compliance · analyst · board
Evidence 3 claims ›

W11AssessedAML/CFT & Financial Crime (Sentinel.gi-fed)

Sentinelsee this theme across all jurisdictions →7 claims

[Sentinel-fed] Cyprus AML/CFT for the payments context is governed by the AML/CFT Law of 2007 and Sanctions Law of 2016, with sector supervisors CBC (credit institutions, PIs, EMIs), CySEC (CIFs, CASPs, funds), ICPAC and the Cyprus Bar Association; MOKAS is the FIU. CASPs are obliged entities registered with CySEC and subject to Travel Rule (Reg (EU) 2023/1113) obligations and CDD from €1,000. Sentinel.gi position carried; no original WPM illicit-finance analysis performed.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

AML/CFT & Financial Crime

This surface is sourced from the Sentinel feed (sentinel://cy/aml-cft/framework); the World Payments Monitor carries the framework as provenance and does not conduct original illicit-finance analysis. Per the Sentinel feed, Cyprus AML/CFT for payments is governed by the AML/CFT Law of 2007 and the Sanctions Law of 2016, with sector supervisors CBC (credit institutions, PIs, EMIs), CySEC (CIFs, CASPs, funds), ICPAC and the Cyprus Bar Association; MOKAS is the FIU. CASPs are obliged entities registered with CySEC, subject to the EBA Travel Rule (Reg (EU) 2023/1113) and CDD for occasional transactions of EUR 1,000 and above. Firm-wide sanctions risk assessment is treated as a non-negotiable compliance element. The bank-versus-CASP supervisory split and Travel Rule CDD thresholds frame the AML compliance perimeter for Cyprus payments and crypto operators.

Outlook

The W11 standing position rests at Assessed: the surface is entirely Sentinel-fed on lower-tier carriers, with no primary MOKAS/CBC/CySEC AML-circular anchors retrieved. Original AML and sanctions-evasion analysis — including CASP Travel Rule application, MOKAS reporting and the bank-versus-CASP supervision gap — is routed to the Financial Integrity Monitor via cross-monitor flag pending primary-source confirmation.

W11AML/CFT & Financial Crime (Sentinel.gi-fed)Assessed
[Sentinel-fed] Cyprus AML/CFT for the payments context is governed by the AML/CFT Law of 2007 and Sanctions Law of 2016, with sector supervisors CBC (credit institutions, PIs, EMIs), CySEC (CIFs, CASPs, funds), ICPAC and the Cyprus Bar Association; MOKAS is the FIU. CASPs are obliged entities registered with CySEC and subject to Travel Rule (Reg (EU) 2023/1113) obligations and CDD from €1,000. Sentinel.gi position carried; no original WPM illicit-finance analysis performed.
all · compliance · analyst · board
Evidence 7 claims ›

W13AssessedCommercial Intelligence (M&A, Investment & Product)

see this theme across all jurisdictions →3 claims

Trailing-12-month commercial activity is shaped by MiCA-driven crypto re-domiciliation into Cyprus and bank consolidation. Revolut secured a CySEC MiCA CASP licence (October 2025), making Cyprus its EEA crypto hub. Bank of Cyprus (CET1 ~21%) signalled openness to smaller, strategically targeted fintech/insurance acquisitions under its 2026-2028 plan. 2025 saw a significant rise in tech/fintech/financial-services M&A. Earlier CASP registrations included Revolut and eToro; Binance exited the market.

No periodic updates yet · baseline brief is current.

Read the full sub-brief

Commercial Intelligence (M&A, Investment & Product)

Three discrete commercial events anchor this module. First, a completed product release: Revolut formally received a MiCA CASP licence from CySEC in October 2025, allowing regulated crypto services across all 30 EEA countries and making its Cyprus base the centre of its EEA crypto operations — a flagship fintech selecting Cyprus as its EEA MiCA crypto hub and a material market-access signal validating the jurisdiction's CASP regime. The deal value is not publicly disclosed.

Second, a rumoured M&A signal: Bank of Cyprus, with CET1 of approximately 21%, said in March 2026 that it remains open to smaller, strategically targeted acquisitions in fintech and insurance under its 2026-2028 plan, identifying fintech companies as a greater competitive challenge than traditional banks. This is a stated appetite rather than an announced or closed deal, with no target named and the value not publicly disclosed.

Third, a sector-level trend: during 2025 Cyprus saw a significant increase in M&A activity emphasising technology, fintech and financial services, alongside a new 8% flat tax on crypto-asset disposal gains effective 1 January 2026. Values across the sector trend are not publicly disclosed.

Outlook

The W13 trajectory is escalating, held at Assessed. The Major Product Launches and Major M&A trackers both advance on these events. Granular funding-round data is thin in this baseline — private-company and emerging-fintech financing signals are under-indexed relative to deal-announcement and launch signals — and should be deepened in subsequent cycles.

W13Commercial Intelligence (M&A, Investment & Product)Assessed
Trailing-12-month commercial activity is shaped by MiCA-driven crypto re-domiciliation into Cyprus and bank consolidation. Revolut secured a CySEC MiCA CASP licence (October 2025), making Cyprus its EEA crypto hub. Bank of Cyprus (CET1 ~21%) signalled openness to smaller, strategically targeted fintech/insurance acquisitions under its 2026-2028 plan. 2025 saw a significant rise in tech/fintech/financial-services M&A. Earlier CASP registrations included Revolut and eToro; Binance exited the market.
all · compliance · analyst · board
Evidence 3 claims ›

Key judgments

5 judgments
W1aConfirmed
Cyprus operates a fully EU-harmonised, multi-pillar payments regime (PSD2/EMD2 PI/EMI, MiCA, DORA, IFR, Instant Payments) under a bifurcated CBC/CySEC supervisory architecture, with the CBC tightening EMI/PSP governance via 2025/2026 directives.
Impact: HIGH
5 supporting claims
Evidence 5 claims ›
W2High
Cyprus is becoming an EEA MiCA crypto hub: Revolut's October 2025 CASP licence centres its EEA crypto operations there, but the EMT-issuance restriction to credit institutions/EMIs and the 1 July 2026 transitional cliff-edge constrain stablecoin ambitions.
Impact: ELEVATED
3 supporting claims
Evidence 3 claims ›
W8High
Domestic card acquiring is structurally concentrated in the bank-owned JCC consortium, leaving high-risk MCCs and cross-border merchants reliant on specialist/PayFac and EU-footprint PSPs — an under-indexed merchant-acquiring dynamic.
Impact: MONITORED
2 supporting claims
Evidence 2 claims ›
W7High
Two challenger-identified quantitative discrepancies (supervised PI/EMI count 26/11 vs official 29/10; sanctions-law penalty EUR 5m/10% vs EUR 40m/5%-of-global-turnover) leave those figures at Assessed and require reconciliation to official sources before publication.
Impact: MONITORED
2 supporting claims
Evidence 2 claims ›
W12High
Euro-corridor settlement strength via T2-CY/TIPS coexists with de-risking-driven fragility in non-euro correspondent access — the principal structural settlement-access constraint for smaller Cyprus institutions and PIs/EMIs.
Impact: ELEVATED
2 supporting claims
Evidence 2 claims ›

What changed this cycle

5 changes this cycle
jurisdiction JID-CYNew
Full 13-module CY baseline established across W1a-W13.
First baseline run for jurisdiction CY; all module standing positions written.
Confidence: High
Detail ›
domain W2New
MiCA competent-authority split + EMT issuance restriction + 1 July 2026 transitional cliff established.
Baseline W2 standing position with forward MiCA deadline.
Confidence: Confirmed
Detail ›
tracker WT9New
Revolut MiCA CASP licence (Oct 2025) recorded as major product/market-access launch for CY.
Discrete W13 commercial event advancing the Major Product Launches tracker.
Confidence: High
Detail ›
horizon wpm-reg-1New
MiCA hard enforcement deadline 1 July 2026 logged for CY CASPs.
Forward regulatory change with date + uncertainty band established at baseline.
Confidence: High
Detail ›
domain W1bNew
CBC 2025/2026 governance & suitability directives establish board-accountable EMI/PSP governance.
Baseline W1b conduct/governance standing position with tightening trajectory.
Confidence: High
Detail ›

Risk posture

1 tracked
JID-CYStable-With-Tightening-Conduct
EU-harmonised PI/EMI/MiCA/DORA framework with intensifying CBC governance directives and sanctions-criminalisation; MiCA-driven crypto re-domiciliation inflow (Revolut). Bank-led acquiring concentration in JCC.
Risk level: Moderate
Confidence: High
Detail ›
World Payments jurisdiction data · Cyprus (CY) · schema world-payments-v1 · baseline wpm-2026-06-27. Data-driven from the published jurisdiction contract — all values shown are read directly from the pipeline output (server-rendered).

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.