CMA Cybersecurity Guidelines
CMA CSG
What it is
The Capital Market Authority’s cybersecurity guidelines for financial market institutions — how they govern, manage and test their cybersecurity.
What it covers
- 01Governance
- 02Risk management, review and audit
- 03Operational controls
- 04Third-party security
How we help
- Gap assessment against the guidelines
- Governance and policy set
- Risk and audit review
- Remediation roadmap
In depth
The guidelines ask each institution to run cybersecurity as a governed program: a board-approved strategy and policies, regular risk reviews and audits, sound controls in daily operations, and security terms with every supplier and cloud provider.
We map where you stand against each area, close the gaps that matter most first, and prepare the evidence the CMA expects to see.
Related services
Other frameworks we work with
Ready to meet CMA CSG?
Tell us where you stand. We will show you the shortest path to what your regulator expects.
Built around the regulators you answer to
Ready to talk about your compliance?
Tell us where you stand. We will show you the shortest path to what your regulator expects.
