Rule
Digital Asset Business (Cyber Risk) Rules 2022
DraftView on BMA's website Source document
Summary
This is a draft set of rules made by the Bermuda Monetary Authority under the Digital Asset Business Act 2018, setting out cyber risk return and governance requirements for digital asset business licensees. The document is still in draft form (it contains placeholder text for the BR number, execution date and operative date), so it has not yet taken legal effect.
- Cyber risk return: Class F licence holders must file a written cyber risk return with the Authority annually; Class M and Class T licence holders must file it on the date specified in their licence.
- Form of return: The return must be in the form directed by the Authority, to be published on the Authority's website (www.bma.bm).
- Declaration requirement: Each cyber risk return must be accompanied by a signed declaration from the chief information security officer and a senior executive or director confirming the return is accurate in all material respects.
- Chief information security officer: The Rules define this role as the senior executive responsible for overseeing and implementing the licensed undertaking's cyber security programme and enforcing its cyber security policies, implying licensees must have such a designated officer.
Because the Rules remain in draft, the actual operative date and the specific filing date for Class M and Class T licensees are not yet fixed in this text and will depend on each licence and the final made version of the Rules.
Key obligations
- Class F digital asset business licence holders must annually file a written cyber risk return with the BMA.
- Class M and Class T digital asset business licence holders must file the cyber risk return on the date specified in their licence.
- The cyber risk return must be submitted in the form directed by the Authority as published on its website.
- Each cyber risk return must be accompanied by a declaration signed by the chief information security officer and a senior executive or director, attesting to its accuracy in all material respects.
- Licensed undertakings must have a designated chief information security officer responsible for the cyber security programme and policies.
Applies to
digital asset business licensees, Class F licence holders, Class M licence holders, Class T licence holders
Deadlines
- annually: Class F licence holders must file the cyber risk return annually.
- date specified in their licence: Class M and Class T licence holders must file the cyber risk return on the date specified in their licence.
Related documents
- This document is made under Digital Asset Business Act 2018
Topics
Version history
2026-07-07