CySEC · CIF · AIFM · ASP · CASP
Insurance for CySEC-Regulated Firms in Cyprus
DigiCare Insurance is a licensed Cyprus insurance agency, ICCS licence 2451, regulated under Law 35(I)/2002. We place professional indemnity, directors' and officers', crime and cyber cover for the firms CySEC licenses.
No published rate card in Cyprus. Every programme is individually underwritten.
A CIF cannot swap capital for insurance. An AIFM can. A UCITS management company cannot. A CASP expressly can.

10+
Insurers compared
15+
Years in Cyprus
2451
ICCS licence
The Cyprus insurers we place







DigiCare Insurance arranges financial-lines cover for CySEC-regulated firms, and it is individually quoted because no Cyprus insurer publishes a rate card. The statutory anchors are fixed: a Cyprus Investment Firm holds €75,000, €150,000 or €750,000 of initial capital, and an alternative investment fund manager must cover professional liability with insurance at 0.7% of assets per claim, or 0.01% in extra own funds.
Get a quote for your licence classThe basics
What a CySEC-regulated firm actually buys
A CySEC-regulated firm buys a programme, not a policy. DigiCare Insurance places the five covers a licensed Cyprus firm normally holds together: professional indemnity, directors' and officers' liability, crime and fidelity, cyber and technology errors and omissions, and regulatory investigation and defence costs. What is actually required of you turns on your licence class, and we set that out below.
I get the same opening line most weeks. Someone tells me they need professional indemnity insurance, because that is the term the whole market uses. Then we go through the licence and it turns out three of the other four covers are doing the real work.
The five parts of a regulated-firm programme:
Professional indemnity insurance, also called professional liability or errors and omissions cover
Directors' and officers' liability, which reaches the individuals CySEC can name in a decision
Crime and fidelity, for internal fraud, employee dishonesty and social engineering
Cyber and technology errors and omissions, for outages, data loss and failed transaction processing
Regulatory investigation and defence costs, the claim a Cyprus firm is most likely to make
For a licensed financial firm these are usually written as one combined financial-institutions form rather than five separate purchases. That matters at claim time. One form, one limit, one set of definitions is what stops a claim falling into the gap between two policies.

The generic cover on its own is on our professional indemnity insurance in Cyprus page. This page is about what a CySEC licence adds to it.
It sits inside the wider picture of business insurance for Cyprus companies, alongside the property and employers' covers every Cyprus company holds.
One thing to clear up first. If you are an investor checking whether a firm is regulated, this page will not answer that. Search the firm in the CySEC public register at cysec.gov.cy, which lists every entity CySEC authorises and the services each one is licensed for. This page is written for the licensed firm buying cover.
Scope
Which firms CySEC regulates, and which it does not
CySEC authorises Cyprus Investment Firms, alternative investment fund managers, UCITS management companies, administrative service providers and crypto-asset service providers. It does not authorise electronic money institutions or payment institutions. Those answer to the Central Bank of Cyprus, and it is there, not at CySEC, that professional indemnity cover is a hard licensing condition.
Cyprus Investment Firm (CIF)
What it does · Investment services under MiFID II
Who supervises · CySEC
Alternative investment fund manager (AIFM)
What it does · Manages alternative investment funds
Who supervises · CySEC
UCITS management company
What it does · Manages UCITS funds
Who supervises · CySEC
Administrative service provider (ASP)
What it does · Corporate and fiduciary services
Who supervises · CySEC
Crypto-asset service provider (CASP)
What it does · Crypto-asset services under MiCA
Who supervises · CySEC
Electronic money institution and payment institution
What it does · E-money and payment services
Who supervises · Central Bank of Cyprus
Under PSD2 Article 5(2) and (3), a firm providing payment-initiation or account-information services must hold professional indemnity insurance or a comparable guarantee. The amount comes from an EBA criteria-based formula rather than a fixed euro figure, and the Central Bank of Cyprus supervises it. If someone has told you CySEC will check that policy, they have the wrong regulator.
The split runs through crypto too. Under MiCA, crypto-asset service providers and asset-referenced-token issuers sit with CySEC, while e-money-token issuers sit with the Central Bank of Cyprus. So "CySEC regulates crypto in Cyprus" is only two thirds right, and which third you land in decides who reads your policy.

One more scoping point worth having. An administrative service provider is CySEC-licensed, and the ASP statute sets no insurance requirement at all. Many administrative service providers are also ICPAC member firms or Cyprus Bar firms, though, and those bodies do set their own minimums. Where a minimum bites on an ASP it comes from the professional body, not from CySEC.
22 crypto-asset service providers have CySEC as their competent authority as at July 2026, which puts Cyprus fourth in the EU and EEA.
One naming detail before we move on, because it decides who the policy actually insures. A forex brand's public name is often an approved trade name rather than the registered name of the licensed entity behind it. We come back to what that does to a policy schedule further down, under who the policy has to name.
Where to check a firm's status
The requirement
Does CySEC require professional indemnity insurance?
No. CySEC does not require a Cyprus Investment Firm to hold professional indemnity insurance, and insurance is not a substitute for capital. Under Law 165(I)/2021 a CIF's initial capital is €75,000, €150,000 or €750,000, depending on the services its licence covers. What the same law does say is that a CIF shall consider holding professional indemnity insurance as an effective tool in the management of risks.
CIF initial capital, Law 165(I)/2021 section 9
| Services licensed for | Initial capital |
|---|---|
| Dealing on own account; underwriting or placing on a firm commitment basis | €750,000 |
| Reception and transmission of orders, execution, portfolio management, investment advice, placing without a firm commitment, where the firm is not permitted to hold client money or securities belonging to its clients | €75,000 |
| All other Cyprus Investment Firms | €150,000 |
| Operating an organised trading facility where the firm deals on own account or is permitted to do so | €750,000 |
Read the second row twice. The tier turns on the client-money qualifier, not on the size of the firm.
Can insurance stand in for capital? It depends entirely on the licence
Cyprus Investment Firm (CIF)
Insurance instead of capital? · No. Insurance is not a capital substitute at any tier
Authority · Law 165(I)/2021 s.9
Alternative investment fund manager (AIFM)
Insurance instead of capital? · Yes. Additional own funds or insurance, your choice
Authority · AIFMD Art. 9(7)
UCITS management company
Insurance instead of capital? · No. The additional own funds are capital, full stop
Authority · Directive 2009/65/EC Art. 7(1)(a)
Administrative service provider (ASP)
Insurance instead of capital? · No. The ASP law sets no insurance requirement at all
Authority · Law 196(I)/2012
Crypto-asset service provider (CASP)
Insurance instead of capital? · Yes. Expressly, as part of the prudential safeguards
Authority · MiCA Art. 67(4)
Electronic money institution and payment institution
Insurance instead of capital? · Yes. Or a comparable guarantee, but the supervisor is the Central Bank of Cyprus
Authority · PSD2 Art. 5(2) and (3)
Read it once and it stays read. A CIF cannot swap capital for insurance. An AIFM can. A UCITS management company cannot. A CASP expressly can.
Plenty of Cyprus advisory pages still print an older line: that a firm holding no client money can meet the prudential requirement with a smaller amount of capital plus a professional indemnity policy. Check the statute. Law 165(I)/2021 contains exactly three euro figures, €75,000, €150,000 and €750,000, and no fourth number anywhere in it. Section 10 says its capital levels replace those of the Capital Adequacy of Investment Firms Law, and the old law is where the capital-or-insurance option lived. The option went with it.
What Law 165(I)/2021 does say about insurance, in its own words:
Section 23(4), the duty to consider
CIFs "shall consider holding professional indemnity insurance as an effective tool in the management of risks".
Section 29(2), the supervisory review
CySEC "shall duly take into account whether CIFs hold a professional indemnity insurance" when it carries out its supervisory review and evaluation.
So it is not legally required, and your regulator is required to look at whether you have it. In a supervisory review that is a better reason to hold cover than a mandate nobody can actually point to.
An alternative investment fund manager gets a genuine choice. AIFMD Article 9(7) lets it cover professional-liability risk with additional own funds or with professional indemnity insurance. Take the insurance route and the cover has to be at least 0.7% of assets under management for an individual claim and 0.9% in aggregate per year, under Articles 15(3) and 15(4) of Delegated Regulation (EU) 231/2013. Take the capital route and it is 0.01% of assets under management, under Article 14(2). Any excess on the policy has to be funded with additional own funds of its own, the policy must come from a third-party entity, and it must be reviewed at least once a year.
A crypto-asset service provider gets the clearest version of the same choice. MiCA Article 67(1) sets prudential safeguards at the higher of two things: the Annex IV permanent minimum for your class of services, €50,000 for Class 1, €125,000 for Class 2 and €150,000 for Class 3, or one quarter of the previous year's fixed overheads. Article 67(4) then lets you meet that with own funds, with an insurance policy covering the Union territories where you provide the services, or with a combination. Insurance does not remove the floor. It changes how you fund it.
Search whether professional indemnity is mandatory for regulated firms and the market's answer comes back as "often yes". In Cyprus that is wrong for every CySEC licence class. Knowing which of your obligations is real is the difference between a policy that satisfies a filing and one that just costs money.
We go through the same ground for a single licence class in CySEC and CIF insurance requirements explained.
Where the legal statements on this page come from
- CySEC, register of Cypriot investment firms and the IFR/IFD implementation guide
- Directive 2011/61/EU (AIFMD), Article 9
- Commission Delegated Regulation (EU) 231/2013, Articles 12, 14 and 15
- Directive 2009/65/EC (UCITS), Article 7
- Regulation (EU) 2023/1114 (MiCA), Article 67 and Annex IV
- Companies Law, Cap. 113, section 197
- ESMA registers and data, including the interim MiCA register
- Central Bank of Cyprus, licensing and supervision
A common mix-up
The Investor Compensation Fund is not your insurance
The Investor Compensation Fund pays a retail client of a failed Cyprus Investment Firm up to €20,000. It is not insurance for the firm, and it does not cover the firm's liability for negligence. It pays out only once the firm can no longer meet its obligations to its clients.
The Fund runs under Law 144(I)/2007, CySEC administers it, and member firms pay for it by levy. Membership comes with the licence rather than from the insurance market, so it is a condition you satisfy, not a cover you buy.
What the Investor Compensation Fund does
- Pays a retail client of a failed firm up to €20,000
- Steps in only once the firm cannot meet its obligations
- Funded by a levy on member firms, administered by CySEC
- Covers the client's loss of money or financial instruments
What your own programme does
- Pays a claim brought against your firm while it is trading
- Responds from the day a claim or an investigation starts
- Funded by a premium you agree with an insurer
- Covers your legal defence and regulatory investigation costs
The €20,000 ceiling is per covered client. It is not per firm, not per claim, and it applies to non-professional clients only, so professional clients and eligible counterparties sit outside the scheme. Nothing in it responds to a negligence claim brought against you while you are still trading, and that claim is what your own programme is for.
I get this one from applicants more than from licensed firms. Someone reads that a CIF must join the Investor Compensation Fund, sees the word compensation, and files it under insurance. It runs the other way. The Fund exists so a retail client is not left empty-handed when a firm fails, and the levy that pays for it is a cost on your side of the balance sheet rather than a cover on it.
Clients ask about the two together because both involve money arriving after something went wrong. They point in opposite directions. The Fund protects the investor from your failure. Your programme protects you from the investor's claim.
Cover and exclusions
What the programme covers, and what it does not
Five covers, one form. Here is what each part answers, and where the wording stops.
Professional indemnity
This is the base grant: a claim that your firm's work was negligent. The best-drafted list of what that means for a fund manager sits in Article 12(2) of the AIFMD delegated regulation, and it maps almost one to one onto what a policy has to respond to.
Loss of documents evidencing title to fund assets
Misrepresentations or misleading statements to the fund or its investors
Acts, errors and omissions breaching legal and regulatory obligations, the duty of skill and care, fiduciary duties, confidentiality, the fund rules or your terms of appointment
Failure to maintain procedures preventing dishonest, fraudulent or malicious acts
Improperly carried out valuation of assets or calculation of unit prices
Business disruption, system failures and failed transaction processing
Read the fifth line again. Getting the net asset value wrong is a named professional-liability risk in the delegated regulation, and it is the claim fund managers actually make. Most policy summaries you will read never mention it.
A crypto-asset service provider's policy is not a plain professional indemnity form. MiCA Article 67(6) already requires it to cover loss of documents, misrepresentations, breaches of legal and regulatory obligations, breach of the duty to act honestly, fairly and professionally, breach of confidentiality, failure to maintain conflict-of-interest procedures, business disruption and system failures, gross negligence in safeguarding clients' crypto-assets and funds, and transfer-service liability under Article 75(8). Article 67(5) then sets conditions on the wording: at least a one-year initial term, at least 90 days' cancellation notice, an authorised insurer, and a policy provided by a third-party entity. That last one rules out captives and intra-group self-insurance, and it is why an off-the-shelf policy does not satisfy Article 67.
Directors' and officers' liability
CySEC can reach past the company to the people running it, so this cover is about individuals as much as the entity. Three sections of the policy do three different jobs.
| Section of the policy | What it answers |
|---|---|
| Side A | The individual director or officer, where no company indemnity is available |
| Side B | Reimbursement to the company where it has indemnified an individual. Narrower in Cyprus, for the reason below |
| Side C, entity cover | Claims brought against the company itself |
Cap. 113 section 197 makes an advance indemnity of a director for breach of duty void, and it contains no insurance carve-out. Cyprus company law blocks the company from indemnifying a director in advance. It does not block the company from buying insurance. That is exactly why Side A carries the weight here and Side B is narrower than the UK or US version of the same policy.
The exposure is real rather than theoretical. CySEC can fine the individuals running a licensed firm, ban them from management functions in any CIF, and it must publish the decision naming them. Administrative fines run to millions of euro. Non-executive directors ask about this before they join a board, and they are right to.
Whistleblowing is the newer exposure. Law 6(I)/2022, as amended by Law 13(I)/2024, puts every CySEC-regulated firm in scope regardless of headcount, because the 50-employee threshold does not apply to financial-services and anti-money-laundering entities. Article 39 liability is criminal for the individual: up to three years, a fine up to €30,000, or both. Directors' and officers' cover buys the defence costs. It never pays the fine.
Crime and fidelity
Internal fraud, employee dishonesty, social engineering and third-party crime. Relevance is highest for administrative service providers, who hold client money, take nominee directorships and operate bank accounts for clients. If your staff can move someone else's money, this cover earns its premium.
Cyber and technology errors and omissions
DORA has applied to Cyprus financial entities since 17 January 2025, CySEC issued Circular C700 in April 2025, and the Central Bank of Cyprus is also a competent authority. Now the part nobody says out loud: DORA mandates no insurance. Cyber cover is your commercial answer to the exposure DORA describes, not a compliance purchase. On network security, DORA is the more specific law for financial entities, so the NIS2 duties it covers are disapplied. NIS2 duties it does not cover can still bite.
Regulatory investigation and defence costs
This is the claim a Cyprus firm is most likely to make. Not a client lawsuit: a CySEC investigation, with the firm instructing one set of lawyers and two directors instructing their own. The spend starts the week the letter arrives, long before anyone decides whether there is a penalty at the end of it.
Check one clause before you sign. Do defence costs sit inside the limit of indemnity, or on top of it? Inside is the market default and the commonest nasty surprise, because a long investigation can eat the limit before a single claim is paid. It is negotiable. A Cyprus regulator has accepted defence costs outside the limit for another regulated profession, so it is a term you can argue rather than a law of nature.

Territorial limits are worth ten minutes of your time. A Cyprus Investment Firm passporting services across the EEA needs the policy's territory to match the passport, not the office. A crypto-asset service provider's Article 67(4) policy has to cover the Union territories where the services are actually provided.
Run-off is the extension that decides whether the programme was worth buying. Professional indemnity and directors' and officers' cover are written on a claims-made basis with a retroactive date, so the policy in force when the claim arrives responds, not the one in force when the work was done. A firm in voluntary renunciation still needs cover, and so do the directors who left two years ago. Never let the retroactive date reset when you change insurer.
Covered
- Legal defence and regulatory investigation costs, including external advisers
- Client claims for negligent advice, execution and administration
- Valuation and unit-pricing errors for fund managers
- Loss of documents evidencing title, and breach of confidentiality
- Individual directors, officers and named compliance appointments
Not covered
- Regulatory fines and penalties, in every case
- Bodily injury and property damage, which belong on public and employers' liability
- Deliberate fraud, dishonesty and illegal personal gain, typically once finally adjudicated
- Insured-versus-insured claims, commonly with a liquidator carve-back
- Employment practices claims, which are an extension rather than part of the base form
One hard constraint, and it holds in every language we write this page in. The policy responds to defence and investigation costs. It does not pay a CySEC, MiCA or GDPR fine. Whether an administrative fine is insurable at all is unsettled in Cyprus, and criminal fines are not insurable as a matter of public policy. Where you read about individual penalties under MiCA, those are MiCA's, not a CySEC power.
The standalone version for financial firms outside a CySEC licence is on our professional indemnity insurance for financial services page.
Directors' and officers' liability insurance has its own page, with the Cyprus company-law detail set out in full.
So does cyber insurance, if that is the part of the programme you are missing.
Get the five covers priced as one programmeThe insured persons
Who the policy has to name
Cyprus has no register of approved persons, so an insurer cannot key the insured-persons definition to a regulatory approval the way a UK wording does. Under Law 87(I)/2017 a CIF notifies CySEC of every member of its board and of any change (section 9(15)), and CySEC may refuse a person on repute, knowledge, skills, experience or time (section 9(14)). That is notification plus a refusal power, not pre-approval.
Which means a wording drafted for London arrives pointing at a regime Cyprus does not have. The insured persons have to be written against the roles Cyprus actually recognises instead.
Executive and non-executive directors
Recognised as · Board of directors
How it arises · Notified to CySEC under section 9(15); at least two persons must effectively direct the business (section 9(16))
The insurance point · The core insured persons. Non-executives usually want confirmation that Side A responds independently
Anti-money-laundering compliance officer (AMLCO)
Recognised as · A named CySEC appointment
How it arises · Directive R.A.D. 44/2019, article 69 of Law 188(I)/2007, duties under DI144-2007-08
The insurance point · Personally exposed on anti-money-laundering supervision, and routinely missing from a UK-drafted definition
Regulatory compliance officer
Recognised as · A named CySEC appointment
How it arises · CySEC Guidelines GD-IF-01 and Circular C025
The insurance point · Same exposure, same omission. Name the appointment, not just the job title
Internal audit and risk management
Recognised as · Control functions, not approved appointments
How it arises · GD-IF-01 and Circular C025, paragraph 21.3
The insurance point · Frequently outsourced. Check whether an outsourced function holder is an insured person at all
Data protection officer
Recognised as · Not a CySEC role
How it arises · GDPR Article 37 and Law 125(I)/2018, notified to the Commissioner for Personal Data Protection
The insurance point · Insurable, but under a different regime. A wording that names the data protection officer and omits the AMLCO copied the wrong template
There is no such thing as a CySEC-approved person, and Cyprus has no equivalent of a senior managers regime. If your wording leans on either phrase, it was written for another market and the definition needs redrafting before you bind.
Two questions settle most of this at renewal. Does the definition of insured person name the anti-money-laundering compliance officer and the regulatory compliance officer as appointments, and does it reach a function holder you have outsourced? Cyprus firms outsource internal audit and risk management routinely. The outsourced holder often falls outside the definition, which leaves the person carrying the regulatory duty with no cover for carrying it. Send us the wording and we will mark up both points.
Now the trade-name point from earlier, and its consequence. An approved trade name is a marketing name; the insured has to be the company CySEC licensed. Put the trading brand in the insured field and the policy answers for an entity that holds no licence, which is the commonest mis-naming we see on Cyprus financial-lines cover. It surfaces at the worst possible moment, when a claim is notified and the insurer checks the schedule against the register. Copy the entity name straight off the licence, then add the trade name as a declared trading style if the insurer will carry it.
The AMLCO is the first name I look for on any Cyprus wording that crosses my desk. It is a named CySEC appointment carrying personal exposure on anti-money-laundering supervision, and a definition imported from London almost never mentions it. Nobody notices until an investigation letter names the individual and the insurer asks whether that person is an insured at all.
Pricing
How much does insurance for a CySEC-regulated firm cost?
Insurance for a CySEC-regulated firm is individually underwritten, and no Cyprus insurer publishes a rate card for it. That is not us dodging the question. There is a sourced reason no rate card exists, and it explains the whole segment.
The Insurance Association of Cyprus reports one undifferentiated liability class: €73,224,972 of €614,182,887 in non-life premium in 2024, about 11.9%. Solvency II's finest published unit is "general liability insurance". The Insurance Companies Control Service publishes no class-level breakdown at all. With no published Cyprus financial-lines data in existence, every policy in this segment is priced on its own file.
Four reference points we can publish, each scoped honestly:
€1,500 to €8,000
A year for directors' and officers' cover at a €1,000,000 limit on a small Cyprus private company (Nexora Cyprus, April 2026). That is a small private company, not a licensed firm. CySEC-licensed firms sit at limits of €5 million to €15 million and above.
From €180
A year, the floor of our own professional indemnity ladder for a low-risk Cyprus professional. A CySEC-licensed firm is never that price. We publish it so you can see the distance.
€500 to €25,000
The range professional indemnity premiums run across the wider Cyprus market, from a sole practitioner up to a larger company.
€4,000 to €10,000
A year in CySEC application and annual fees, against Cyprus operating substance of €150,000 to €200,000 a year. A financial-lines programme is a small line in that stack.
Nine things we rate:
| Rating factor | What it changes |
|---|---|
| Licence class and the exact services licensed | The starting point. A CASP and an advice-only CIF are different risks with different statutory floors |
| Limit of indemnity | The largest single lever. Your class, your clients' contracts and your assets set it |
| Deductible | Normally lowers the premium, with one exception set out below |
| Turnover or assets under management | The exposure base. An AIFM's limits are a percentage of assets, so this drives both sides |
| Territorial limits and passporting | An EEA passport prices higher than a Cyprus-only permission |
| Jurisdiction and choice of law | Where a claim can be brought matters as much as where you trade |
| Number of licensed professionals | More people giving advice means more chances to give it wrongly |
| Retail versus professional client base | Retail clients complain more often, and the Investor Compensation Fund sits behind them |
| Claims and regulatory history | Prior claims, prior investigations and prior CySEC correspondence |

One factor works backwards for an alternative investment fund manager. Any excess on the policy has to be funded with additional own funds, so a high deductible does not cheapen an AIFM's programme the way it cheapens an ordinary firm's. It just moves the cost from a premium into your capital.
Where the cost figures come from
The question behind the question is usually whether you are about to be quoted a number that wrecks the budget. Fair enough, so here is the shape of the answer. Send the licence class, the services on it, the limit your counterparties ask for and your assets under management or turnover, and you get a figure for your own firm rather than a range for somebody else's. Firms that arrive with those four things on one page get quoted in days rather than weeks.
Here is the honest way to think about the price. A regulatory investigation consumes six figures of legal spend long before anyone decides whether there is a penalty. That spend is the part the policy pays, and it is the part firms underestimate.
Get a quote
Request a quote for your CySEC-regulated firm
Send us your licence class, the services it covers and your assets under management or turnover. We come back with a comparison across the insurers we place for regulated Cyprus firms, and the wording checked against the article that applies to you.
The form asks six things: your firm's name, your licence class, your CySEC licence number if you hold one, the covers you want, your assets under management or turnover band, and how to reach you. If you are pre-authorisation, pick "applying for a licence" and skip the number.
You get a written comparison back, usually within two working days. Where a MiCA or CIF application deadline is driving the timetable, put the date in the message and we will work to it.
Tell us your licence class
Six fields, no phone call needed. We reply with the programme priced across the insurers we place for regulated firms.
DigiCare Insurance is a licensed Cyprus insurance agency in Paphos. We place cover for regulated firms in Limassol, Nicosia and across Cyprus, in English, Greek and Russian.
This programme sits inside business insurance in Cyprus; professional indemnity insurance for financial services and directors' and officers' liability insurance are usually written on the same schedule.
Costas Matheou — Licensed insurance agent, DigiCare Insurance, Paphos, Cyprus
Last reviewed: 27 July 2026
ICCS licence 2451, regulated under Law 35(I)/2002
We review this page whenever CySEC, the Central Bank of Cyprus or an EU instrument changes what a licensed Cyprus firm has to hold, and at least twice a year in any case.
FAQ
Frequently asked questions
Your licence class decides what you need. Let's settle it.
A CIF cannot swap capital for insurance. An AIFM can. A UCITS management company cannot. A CASP expressly can. Tell us which one you are and we will price the programme against the article that actually applies to you.
Licensed Cyprus insurance agency, ICCS licence 2451 | 5.0 on Google
