If your firm operates a Cyprus branch — authorised in another EU Member State, passported into Cyprus — the May 8, 2026 deadline under CySEC Circular C772 has now passed. What remains is either a completed Form RBSF-CBR Version 3 carrying a NO ERROR feedback file in your TRS Outgoing directory, or an open enforcement risk under section 37(5) of the CySEC Law. There is no middle ground, and CySEC issued no reminders.
What Is a Cyprus Branch (CBR) and Why Is It Different from a CIF?
A Cyprus Investment Firm (CIF) holds its own CySEC authorisation. It is licensed directly by CySEC under the Investment Services and Activities and Regulated Markets Law — Cyprus's transposition of MiFID II — and CySEC is its home-country regulator.
A Cyprus Branch (CBR) is a different entity. CySEC Circular C772, Introduction defines the addressees precisely: EU investment firms "authorised by the National Conduct Authority of a Member State other than Cyprus and which are operating in Cyprus." The branch holds its investment firm authorisation from its home-country NCA — the FCA, BaFin, AMF, or equivalent — not from CySEC. CySEC is the host-country supervisor.
That distinction matters because it shapes the branch's regulatory obligations. On conduct-of-business and prudential matters, the branch remains primarily answerable to its home NCA. But Cyprus remains the host jurisdiction, and CySEC retains host-country supervisory powers — including the power to collect statistical and risk data from every regulated entity operating within its territory.
The RBS-F Framework: What CySEC Collects and Why
The Risk-Based Supervision Framework (RBS-F) is CySEC's structured programme for gathering quantitative data from regulated entities to support supervisory risk assessment. For Cyprus Branches, the data vehicle is Form RBSF-CBR.
CySEC Circular C772, Section 1.1 describes the form's purpose: "the collection of various statistical information." CySEC uses that information "for the purposes of conducting statistical analyses, risk management and other purposes." The RBS-F is therefore an intelligence-gathering exercise, not a licensing or notification obligation. CySEC is building a risk picture of the branch population operating in Cyprus.
The form is issued on an annual basis. Section 1.1 confirms that Version 3 of Form RBSF-CBR is the current version — a Version 2 exists. Section 2 states that no additional information is requested in Version 3 relative to Version 2, meaning the data scope is unchanged from the prior cycle. The compliance burden for a branch that submitted correctly in the previous cycle is structurally identical in this one.
The form spans eleven data sections — Sections A through K — each with embedded validation tests. Section 3.6 requires that all validation tests across Sections A, B, C, D, E, F, G, H, I, J, K and the Validation Tests Worksheet show TRUE (Green Color) before submission. The Instructions Worksheet within the form provides field-level guidance. Section 3.5 directs branches there rather than to the circular itself.
Who Must Submit
The obligation is tightly scoped. CySEC Circular C772, Section 1.2 requires submission by "all Cyprus Branches that were operational as of 31st December 2025." The converse is also stated: EU investment firm branches established in Cyprus that were not operational as at that date are not required to submit the form.
This is a narrower scope than the equivalent CASP obligation under C771, where CySEC required submission from all registered CASPs regardless of whether they were operational. For CBRs, non-operational status as at 31 December 2025 provides a genuine exemption.
Compliance officers should verify operational status carefully. A branch that conducted any regulated activity — even minimal — during 2025 would ordinarily be treated as operational as at year-end. The circular provides no further definition of "operational"; branches in any doubt should take a conservative position and submit.
The Reporting Period and Data Format
CySEC Circular C772, Section 3.1 fixes the reporting parameters: the form covers the period 01/01/2025 to 31/12/2025, using 31/12/2025 as the reference date. All data in the eleven sections must reflect the full calendar year and be measured to that single year-end reference point.
Two formatting rules apply:
→ Section 3.3: data must be reported in Euro, rounded to the nearest unit. Any figures held in a foreign currency must be converted to Euro before entry. Conversion methodology and rounding approach should be documented internally.
→ Section 3.2: the form is available only in English. There is no multilingual version.
Deadline and Submission Mechanics
CySEC Circular C772, Section 1.3 sets the submission deadline as Friday, May 8, 2026. Submission is made electronically via CySEC's Transaction Reporting System (TRS).
Uploading the file to TRS does not constitute successful submission. Section 1.4 places on each branch the obligation to confirm it has received a feedback file in the Outgoing directory — an official confirmation dispatched by TRS after processing.
Section 1.5 specifies two possible outcomes from that feedback file:
→ A NO ERROR indication: the submission is successful.
→ An error description: the submission has failed. The branch must review the form, correct all identified errors, and re-submit before the May 8 deadline.
Section 1.5 states the rule plainly: "The Form is regarded as being successfully submitted to CySEC, only when a NO ERROR indication feedback file is received, within the deadlines set in point 1.3 above." The feedback file is dispatched only during CySEC regular hours. A file uploaded close to the deadline may not receive TRS confirmation until after regular hours, effectively missing the deadline. Branches should submit with sufficient lead time for TRS to process the file and return the confirmation within business hours.
File Naming, Format, and Technical Requirements
CySEC Circular C772, Section 4 sets out the technical requirements. Importantly, the circular states that "no digital signature is required for the successful submission of the Form." Branches should not apply a digital signature; the form is validated by the TRS process alone.
The file must be named according to this convention:
Username_yyyymmdd_RBSF-CBR
The three components are:
→ Username: the TRS credentials username issued to the branch by the authorisation department, entered in capital letters.
→ yyyymmdd: the end date of the reporting period. For the 2025 cycle, this is 20251231.
→ RBSF-CBR: the form coding, inserted exactly as it appears, unchanged.
The form must be in Excel 2007 format or later. Excel adds the .xlsx extension automatically on saving. Section 4 is explicit: "This extension should not be inserted manually, under any circumstances." A manually typed extension may result in a corrupted or unrecognised file.
A correctly named submission file for the 2025 cycle would therefore follow the pattern: [TRS_USERNAME]_20251231_RBSF-CBR.xlsx, where the .xlsx is added by Excel, not the preparer.
Branches that have not previously received TRS credentials should refer to the TRS information section of the CySEC website before attempting to submit.
Enforcement: Section 37(5) Penalties and the No-Reminder Policy
CySEC Circular C772, Section 1.6 addresses enforcement in direct terms. Failure to comply "may bear the administrative penalties of section 37(5) of the CySEC Law." CySEC did not specify in C772 the precise penalty amounts applicable in a given case; the determination under section 37(5) is made on the facts of each case.
What C772 does state procedurally is significant: "CySEC will not send any reminders to those Branches, which fail to comply promptly and duly." There is no grace-period notification, no follow-up email, and no cure window attached to a reminder. May 8, 2026 was the operative deadline, and responsibility for meeting it rested entirely with the branch.
A branch that missed the May 8 deadline — or whose TRS submission generated an error file that was not corrected and re-submitted in time — should assess its position under section 37(5) and consider whether voluntary disclosure or engagement with CySEC is appropriate.
Practical Compliance Checklist for Branch Compliance Officers
The 2025 cycle deadline has passed, but the following checklist applies to any branch reviewing its C772 compliance position and preparing for future RBS-F cycles.
→ Confirm operational status: was the branch operational as at 31 December 2025? If not, the reporting obligation does not apply.
→ Obtain the correct form: download Version 3 of Form RBSF-CBR from the CySEC website. Do not use Version 2.
→ Complete the 11 sections: populate Sections A through K using the Instructions Worksheet embedded in the form. Use Euro, rounded to the nearest unit. Reference date: 31/12/2025. Reporting period: 01/01/2025 to 31/12/2025.
→ Run all validation tests: before submitting, verify that all validation tests in Sections A–K and the Validation Tests Worksheet show TRUE (Green Color).
→ Name the file correctly: [TRS_USERNAME]_20251231_RBSF-CBR.xlsx (the .xlsx extension is added by Excel, not typed).
→ Submit via TRS: no digital signature is required. Upload the file through the Transaction Reporting System.
→ Confirm the feedback file: check the TRS Outgoing directory for a NO ERROR feedback file. If an error file is received, correct and re-submit before the deadline. A submission without a NO ERROR confirmation is not a successful submission.
→ Raise queries before the query window closes: queries on form completion must be submitted in writing to riskstatistics.cifs@cysec.gov.cy before the closing date specified in the relevant annual circular (April 30, 2026 for the 2025 cycle). Technical queries on TRS go to information.technology@cysec.gov.cy. All emails must include the branch's full name and TRS coding in the subject line.
FAQ
Q: Our firm is authorised in Germany and passported into Cyprus. Do we fall within the scope of C772?
Yes. CySEC Circular C772, Introduction addresses "EU Investment Firms Branches established in Cyprus, which are authorised by the National Conduct Authority of a Member State other than Cyprus and which are operating in Cyprus." A German-authorised firm with a Cyprus branch passported under MiFID II is precisely the entity to which C772 is addressed, provided the branch was operational as at 31 December 2025.
Q: The circular says no digital signature is required. Is that correct — the equivalent CASP form required one?
Yes. CySEC Circular C772, Section 4 states explicitly that "no digital signature is required for the successful submission of the Form." Branch compliance officers should not apply a digital signature; the submission is validated by TRS processing alone.
Q: What counts as a successful submission under C772?
Submission is successful only when TRS returns a feedback file containing a NO ERROR indication to the branch's Outgoing directory, during CySEC regular hours, before the May 8, 2026 deadline. CySEC Circular C772, Section 1.5 states: "The Form is regarded as being successfully submitted to CySEC, only when a NO ERROR indication feedback file is received." Uploading the file without receiving this confirmation does not constitute successful submission.
Q: What is the penalty exposure for missing the deadline?
CySEC Circular C772, Section 1.6 states that failure to comply "may bear the administrative penalties of section 37(5) of the CySEC Law." CySEC does not quantify the penalty in the circular; the determination is made on the facts. The same provision confirms CySEC will send no reminders to non-compliant branches. Exposure is therefore live from the moment the deadline passed without a NO ERROR confirmation on file.
Every answer carries its citation. Primary sources, not summaries. For Cyprus Branches reviewing their C772 compliance position or preparing for future RBS-F cycles, omnilaw.ai provides direct access to CySEC circulars and Cyprus regulatory source text so your analysis is grounded in the original document, not a paraphrase of it.



