CATEGORIES
- (5) Negotiating Tax Debt and Payment Arrangements with SARS
- (2)Account / Profile
- (574)Accounting
- (4)Accounting & Financial Reporting
- (2)Accounting and Finance
- (29)Audit
- (164)Auditing and Assurance
- (1)Business
- (1)Business Management
- (3)Business Rescue
- (118)CIPC
- (7)Compliance
- (19)Ethics and Professionalism
- (47)Financial Reporting
- (1)Government Funding Applications
- (4)Guides
- (1)IFRS
- (1)Independent Reviews
- (1)Individuals Tax
- (41)Law
- (49)Legal and Compliance
- (2)Management
- (60)Miscellaneous
- (29)Money Laundering
- (1)Personal & Professional Development
- (2)Practice Management
- (2)Professional Ethics
- (3)Public Sector
- (145)Regulatory Compliance and Legislation
- (41)SARS Issues
- (32)Sustainability Reporting
- (45)Tax
- (1)Tax Update
- (11)Technology
- (1)Wills, Estates & Trusts
- Show All
FSCA: Notification template for material IT and cyber incidents
- 29 September 2026
- Miscellaneous
- South African Accounting Academy
Summary:
The Financial Sector Conduct Authority (FSCA) and the Prudential Authority (PA) have published the Determination of the Notification Template for Reporting of Material IT and Cyber Incidents.
Article:
The FSCA and PA, in terms of paragraph 15.1 of Joint Standard 1 of 2023 – IT Governance and Risk Management Requirements for Financial Institutions and paragraph 9.1 of Joint Standard 2 of 2024 – Cybersecurity and Cyber Resilience Requirements, hereby determine the form, manner and period for the notification of material information technology and cyber incidents, as set out in the Schedule.
Financial institutions in South Africa must report material IT and cyber incidents using the official Reporting of Material IT and Cyber Incident Template outlined in Joint Notice 2 of 2026.
Reporting Timelines & Process
- Initial Notification: Submit within 24 hours of classifying the incident as material (not from when it is first detected).
- Follow-up Update: Provide a detailed status update within 14 calendar days of the initial notification.
- Final Investigation Report: Deliver a complete report based on timelines agreed upon with the relevant regulator.
Submission Channels
- Prudential Authority (PA): Banks, insurers, and market infrastructures submit via the Umoja Portal.
- FSCA: Financial Services Providers (FSPs), collective investment scheme managers, retirement/pension funds, and administrators submit via email to ITandCybernotification@fsca.co.za or the dedicated FSCA portal.
The Determination became effective on 1 September 2026.
Access Annexure A - Reporting of Material IT and Cyber Incident Template at https://www.resbank.co.za/content/dam/sarb/publications/prudential-authority/pa-public-awareness/communication/2026/joint-communication-5-of-2026/Annexure%20A%20-%20Reporting%20of%20Material%20IT%20and%20Cyber%20Incident%20Template.xlsx
Click here to download Joint Notice 2 of 2026:
Relevance to Auditors, Independent Reviewers & Accountants:
- Auditors, Independent Reviewers and Accountants should be aware of the latest publications and guidance issued by regulators, such as the FIC – to enable their assessment of accountable institutions’ compliance with FICA.
- As a TCSP (which is an accountable institution), the firm also needs to comply with FICA, and the resulting Beneficial Ownership requirements.
- When advising clients or performing this function on their behalf, practitioners should be aware of the finer details and specific guidance on Material IT and Cyber Incidents.
Relevance to Your clients:
- Relevant companies and CCs (accountable institutions) should be aware of the latest publications and guidance issued by regulators, such as the FSCA, FIC, etc – specifically for Material IT and Cyber Incidents.



