Rule

Virtual Currency (Cybersecurity) Rules 2018

Bermuda Monetary Authority (BMA) · Bermuda

Status not confirmed

Current version last checked: 2026-07-07

Summary

These Rules, made by the Bermuda Monetary Authority under the Virtual Currency Business Act 2018, impose cybersecurity governance and reporting requirements on licensed undertakings conducting virtual currency business. They require an annual cybersecurity report prepared by a designated Chief Information Security Officer and an independent audit of the licensee's cyber security controls.

  • Annual report: Every licensed undertaking must annually file a written report with the Authority, prepared by its Chief Information Security Officer, assessing system availability, functionality and integrity, identified cyber risk from its virtual currency business, and the cyber security program plus remediation proposals.
  • Audit functions required: The cyber security program must include, at minimum, quarterly penetration testing and vulnerability assessments, and audit trail systems that reconstruct financial transactions, protect data and hardware integrity, log system events, and maintain audit trail records.
  • Independent audit: Every licensed undertaking must engage a qualified independent party to audit its systems and provide the Authority with a written opinion that its cyber security program is suitably designed and operating effectively to meet the Rules.
  • Chief Information Security Officer: Licensed undertakings must appoint a senior executive as Chief Information Security Officer to oversee and implement the cyber security program and enforce cyber security policies.

Key obligations

  • Every licensed undertaking must annually file with the Authority a written cybersecurity report prepared by its Chief Information Security Officer covering system integrity, cyber risk, and program adequacy.
  • Every licensed undertaking must conduct penetration testing and vulnerability assessments of its electronic systems at least quarterly.
  • Every licensed undertaking must maintain audit trail systems that track transactions, protect data and hardware integrity, log system events, and retain audit trail records.
  • Every licensed undertaking must engage a qualified independent party to audit its cyber security controls and provide the Authority a written opinion on the program's design and operating effectiveness.
  • Every licensed undertaking must appoint a Chief Information Security Officer to oversee and implement its cyber security program.

Applies to

licensed undertakings conducting virtual currency business

Deadlines

  • annually: Licensed undertakings must file the written cybersecurity report with the Authority annually.
  • at least on a quarterly basis: Penetration testing and vulnerability assessment of electronic systems must be conducted at least quarterly.

Related documents

Topics

Version history

2026-07-07

source file (current)