Global standard-setters publish FMI cyber resilience toolkit
BIS CPMI and IOSCO published a voluntary cyber resilience toolkit for financial market infrastructures and a discussion paper on FMIs’ reliance on third-party providers. Responses due 1 December.
The BIS Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) published a cyber resilience toolkit for financial market infrastructures (FMIs) and a discussion paper on FMIs’ reliance on third-party service providers. Stakeholders are invited to submit comments by 1 December.
The toolkit provides voluntary, non-binding practical considerations to help FMIs strengthen cyber resilience frameworks and to support implementation of the operational resilience elements of the CPMI‑IOSCO Principles for Financial Market Infrastructures (PFMI). It covers governance, detection and response, recovery planning and testing, and information sharing aimed at protecting core market infrastructure from cyber incidents. The toolkit is designed to complement the 2016 CPMI‑IOSCO Guidance on cyber resilience for FMIs.
The discussion paper examines risks and operational challenges when FMIs use external providers, with particular focus on the delivery of critical services. It poses questions to market participants, service providers and supervisors about identified risks and asks whether further engagement or policy development by CPMI and IOSCO is needed.
Both documents are addressed to operators of FMIs-including payment systems, central counterparties and central securities depositories-as well as supervisors, third‑party vendors and market participants that rely on these infrastructures. The toolkit is framed as a set of tools FMIs can adapt to local legal and operational circumstances.
Comments on the toolkit and the discussion paper must be submitted by 1 December. CPMI and IOSCO will review responses and then decide on any further work or formal guidance.
The publications build on the PFMI framework and earlier international guidance on cyber resilience, which set expectations for how FMIs manage operational and technology risks.








