Standardised IT and cyber incident reporting takes effect
SARB Press

Standardised IT and cyber incident reporting takes effect

South Africa's Prudential Authority and Financial Sector Conduct Authority have determined the mandatory template and electronic submission channels for material IT and cyber incident notifications, effective 1 September 2026.

Dual channels for incident filing

The determination by FSCA Commissioner Unathi Kamlana and PA CEO Fundi Tshazibana enforces reporting obligations under Joint Standard 1 of 2023 and Joint Standard 2 of 2024.

Reporting routes are divided by institution type.

Banks, foreign bank branches, mutual banks, and insurers must file the reporting template electronically through the PA's Umoja Portal under dedicated notification fields.

Non-banking financial entities—including collective investment scheme managers, market infrastructures, discretionary and administrative financial service providers, pension funds, OTC derivative providers, and credit rating agencies—must submit through the FSCA Joint Standards Submission Portal.

Thresholds for operational disruption

Under the notice, a material incident is defined as any operational disruption to business activities or functions that carries a severe and widespread impact on an institution's services, its customers, or the broader financial system.

The notification timeline is governed by the specifications set out on the template's cover page.

The harmonised reporting regime establishes enforceable regulatory channels across both authorities pursuant to the Financial Sector Regulation Act of 2017.

Standardisation with portal friction

Standardised reporting replaces ad-hoc crisis disclosures with structured incident data.

Splitting submissions across two separate portals, however, introduces avoidable friction for diversified groups.

Real-time cross-agency coordination will decide whether the framework improves cyber resilience.

Report an error