FSCA: Notification template for material IT and cyber incidents

FSCA: Notification template for material IT and cyber incidents logo

Summary:
The Financial Sector Conduct Authority (FSCA) and the Prudential Authority (PA) have published the Determination of the Notification Template for Reporting of Material IT and Cyber Incidents. 


Article:
The FSCA and PA, in terms of paragraph 15.1 of Joint Standard 1 of 2023 – IT Governance and Risk Management Requirements for Financial Institutions and paragraph 9.1 of Joint Standard 2 of 2024 – Cybersecurity and Cyber Resilience Requirements, hereby determine the form, manner and period for the notification of material information technology and cyber incidents, as set out in the Schedule. 

Financial institutions in South Africa must report material IT and cyber incidents using the official Reporting of Material IT and Cyber Incident Template outlined in Joint Notice 2 of 2026.

Reporting Timelines & Process

  • Initial Notification: Submit within 24 hours of classifying the incident as material (not from when it is first detected).
  • Follow-up Update: Provide a detailed status update within 14 calendar days of the initial notification.
  • Final Investigation Report: Deliver a complete report based on timelines agreed upon with the relevant regulator.

Submission Channels

  • Prudential Authority (PA): Banks, insurers, and market infrastructures submit via the Umoja Portal.
  • FSCA: Financial Services Providers (FSPs), collective investment scheme managers, retirement/pension funds, and administrators submit via email to ITandCybernotification@fsca.co.za or the dedicated FSCA portal.

The Determination became effective on 1 September 2026.

Access Annexure A - Reporting of Material IT and Cyber Incident Template at https://www.resbank.co.za/content/dam/sarb/publications/prudential-authority/pa-public-awareness/communication/2026/joint-communication-5-of-2026/Annexure%20A%20-%20Reporting%20of%20Material%20IT%20and%20Cyber%20Incident%20Template.xlsx 

Click here to download Joint Notice 2 of 2026:

https://www.resbank.co.za/content/dam/sarb/publications/prudential-authority/pa-public-awareness/communication/2026/joint-communication-5-of-2026/FSCA-PA%20Joint%20Communication%205%20of%202026%20-%20Determination%20of%20the%20Notification%20Template_310826.pdf 

 

Relevance to Auditors, Independent Reviewers & Accountants:

  • Auditors, Independent Reviewers and Accountants should be aware of the latest publications and guidance issued by regulators, such as the FIC – to enable their assessment of accountable institutions’ compliance with FICA.
  • As a TCSP (which is an accountable institution), the firm also needs to comply with FICA, and the resulting Beneficial Ownership requirements.
  • When advising clients or performing this function on their behalf, practitioners should be aware of the finer details and specific guidance on Material IT and Cyber Incidents.

Relevance to Your clients:

  • Relevant companies and CCs (accountable institutions) should be aware of the latest publications and guidance issued by regulators, such as the FSCA, FIC, etc – specifically for Material IT and Cyber Incidents.

There are not comments for this article at the moment, check back later.
You must be logged in to add a comment, log in now.

Explore Smarty