CPMI and IOSCO target cyber resilience and third-party risks at FMIs
Global standard setters CPMI and IOSCO have published a cyber resilience toolkit alongside a discussion paper examining financial market infrastructures’ operational dependencies on third-party service providers. Stakeholders are invited to submit comments by December 1, 2026.
Operational tools for core infrastructure
The BIS Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) released two consultative documents addressing financial market infrastructures (FMIs).
The cyber resilience toolkit provides practical, non-binding tools to help FMIs implement operational resilience components under the CPMI-IOSCO Principles for Financial Market Infrastructures (PFMI).
In parallel, the joint discussion paper explores the vulnerabilities arising from FMIs’ growing dependence on third-party vendors for critical operations.
Stakeholders have until December 1, 2026, to provide feedback to the CPMI and IOSCO Secretariats.
Beyond the 2016 baseline
The publication builds on the 2016 CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures.
While the earlier guidance established overarching expectations, market infrastructures have increasingly integrated external technology vendors and cloud architectures into critical clearing and settlement functions.
The new toolkit provides modular implementation methods, whereas the discussion paper maps potential transmission channels of operational disruption across interconnected entities.
Voluntary tools face hard systemic limits
Voluntary guidance helps FMIs structure their cyber defenses but cannot resolve deep systemic exposure.
Concentration among a few dominant third-party service providers creates single points of failure across global markets.
Without binding regulatory mandates, operational resilience will remain incomplete.