
The Committee on Payments and Market Infrastructures (CPMI) at the Bank for International Settlements and the International Organization of Securities Commissions (IOSCO) published two documents on September 8, 2026, aimed at strengthening cyber resilience and risk management in financial market infrastructures (FMI). The first document — "Cyber Resilience Toolkit: Practical Considerations for Financial Market Infrastructures" — is a compendium of practical recommendations. The second — a discussion paper titled "Financial Market Infrastructures' Reliance on Third-Party Service Providers: Challenges and Risks" — examines the growing dependence of FMIs on third parties.
The toolkit contains voluntary, non-binding recommendations that help FMIs strengthen their cyber defense systems and embed operational resilience components in accordance with the CPMI-IOSCO Principles for Financial Market Infrastructures (PFMI). The document covers several broad topics related to cyber resilience and is intended to complement the 2016 CPMI-IOSCO Guidance on Cyber Resilience. The practical considerations set out in the toolkit allow financial institutions to adapt their processes to modern cyber threats without creating new regulatory obligations.
The discussion paper, in turn, identifies and examines several key challenges arising from the outsourcing of certain functions to third-party service providers, particularly when critical services are involved. It emphasizes that increased reliance on external providers can create additional operational and cyber risks, as well as concentration risks. CPMI and IOSCO have formulated a series of questions for stakeholders in order to gather feedback on the identified risks and possible directions for further work. This will enable organizations to better understand the scope of the problem and, where necessary, develop more detailed standards.
The publication of these two documents reflects the commitment of international standard-setting bodies to ensuring the resilience of financial infrastructure in a rapidly evolving threat landscape. Financial market infrastructures play a systemically important role in the global economy, and their ability to withstand cyberattacks and manage third-party dependencies directly affects the stability of the entire financial system. CPMI and IOSCO invite market participants, regulators, and other interested parties to submit comments and proposals so that the feedback received can be used to continue improving cyber resilience standards and practices. The feedback is expected to contribute to a deeper understanding of risks and the development of balanced approaches to mitigating them.

