FSCA and PA Determine Notification Template for Material IT and Cyber Incidents

Posted 29 September 2026 Written by Acts Online

Brought to you by SA Accounting Academy: The Financial Sector Conduct Authority (FSCA) and the Prudential Authority (PA) have published the official notification template and reporting procedures for material IT and cyber incidents affecting financial institutions.

In terms of paragraph 15.1 of Joint Standard 1 of 2023 (IT Governance and Risk Management Requirements for Financial Institutions) and paragraph 9.1 of Joint Standard 2 of 2024 (Cybersecurity and Cyber Resilience Requirements), the FSCA and the PA have issued Joint Notice 2 of 2026 along with FSCA-PA Joint Communication 5 of 2026. These authorities have formally determined the prescribed form, manner, and period for reporting material information technology and cyber incidents.

The determination takes effect on 1 September 2026, from which date all regulated financial institutions must utilise the standard reporting spreadsheet provided in Annexure A.

Key Regulatory Requirements

  • Prescribed form: Notifications must be submitted using the official Annexure A — Reporting of Material IT and Cyber Incident Template.
  • Statutory mandate: Submissions are required under both Joint Standard 1 of 2023 (IT governance) and Joint Standard 2 of 2024 (cyber resilience).
  • Effective date: Mandatory compliance commences on 1 September 2026.
  • Scope: Applies to all financial institutions licensed or regulated under the regulatory oversight of the FSCA and the PA.

Click here to download Joint Notice 2 of 2026 — Determination of the Notification Template.

Click here to download Annexure A — Reporting of Material IT and Cyber Incident Template (XLSX).

Click here to read FSCA-PA Joint Communication 5 of 2026.

What this means for you, your business, or your clients

  • For yourself: Compliance officers and internal auditors must familiarise themselves with the required data fields in Annexure A to ensure incident classifications align with regulatory reporting thresholds before 1 September 2026.
  • For your business: Regulated institutions and professional advisory practices must integrate the standardized incident response reporting template into their existing IT disaster recovery and operational risk governance workflows.
  • For your clients: Financial institution clients face non-compliance sanctions under Joint Standards 1 of 2023 and 2 of 2024 if material outages, breaches, or cyber attacks are not reported using the prescribed format by the statutory deadline.

Originally published at https://accountingacademy.co.za/news/read/fsca-notification-template-for-material-it-and-cyber-incidents


The views expressed herein are those of the author and do not necessarily reflect those of Acts Online. Acts Online accepts no responsibility for the accuracy, completeness or fairness of the article, nor does the information contained herein constitute advice, legal or otherwise.