What is a Cyprus CySEC license?
CySEC是塞浦路斯证券交易委员会。希望在欧盟框架下提供投资服务的企业,通常需先确定MiFID II下的投资服务、附属服务、金融工具、客户类别及订单执行模式,再申请相应CIF授权。
获批后的跨境经营仍涉及通知程序、目标成员国规则和营销边界,不应把“欧盟通行证”理解为自动覆盖所有产品、客户和国家。若同时评估英国、澳洲或瑞士,应分别核对British FCA license、Australian AFSL licenseand瑞士FINMA监管路径。
Suitable for those who want to establish a European compliance entity and interface with international banks、Medium to large teams for liquidity and institutional clients。
The application path can be designed based on the investment service portfolio,Adaptation Brokerage、matchmaking、Asset management consultant and other models。
in payment channel、Partner brokers、High degree of identification during due diligence of technology suppliers and institutional customers。
Available with the United States、U.K.、Asian licenses form regional compliance structure,Support multi-market operations。
Application conditions and substantive business requirements
CySEC会评估申请人的股权与控制、管理层适当性、governance、capital、business plan、合规与风险管理、AML/CFT、customer assets、complaint、IT、外包和业务连续性安排。申请材料必须与拟开展的实际业务一致。
Number of personnel、Division of responsibilities、居住和外包安排并非一套适用于所有CIF的固定模板,应按获批服务、scale、复杂性和利益冲突逐项设计。Available fromCySEC投资公司专题进入申请、instruction、通告和受监管实体资料。
UBO identification needs to be completed、Fund source description and negative information investigation,Avoid triggering additional inquiries during the approval stage。
board governance、Compliance/AML、Risk and internal audit functions need segregation of duties,avoid role conflict。
Need to reflect local management capabilities and operational capabilities,Rather than just registering a shell company。
Transaction monitoring、Log retention、Rights management and business continuity planning are the focus of technical due diligence。
Application process and cycle management
Based on target customers、product、Counterparties and cross-border routes,Determine investment service scope and compliance structure。
Complete Cyprus entity establishment、equity penetration、Matching of directors and key positions。
Prepare business plan、financial forecast、AML/KYC、risk policy、Complaints and Outsourcing Management Documents。
After submitting the application to CySEC, it enters the inquiry and response stage.,Focus on consistency and enforceability。
Complete bank/payment docking、staff training、System joint debugging and internal control implementation。
Perform regular declarations in accordance with regulatory requirements、audit、Training and internal control review,Reduce law enforcement risk。
CySEC license application fee structure
CySEC投资公司申请费和年度费由Directive DI87-03及其现行修订按投资服务、附属服务和后续变更计算;CySEC当前费用页面未支持把25,000欧元“加急费”作为统一项目展示。
初始资本应按欧盟《Directive (EU) 2019/2034》第9条及实际获批活动判断:涉及MiFID II附件一A部第(3)项自营交易或第(6)项承销/坚定承诺配售的投资公司为750,000欧元;仅从事第(1)、(2)、(4)、(5)、(7)项且不得持有客户资金或证券的公司为75,000欧元;不属于上述及特定第(9)项情形的其他投资公司通常为150,000欧元。

Official verification:欧盟投资公司审慎指令第9条初始资本、CySEC Investment Firms FeesandCySEC Directive DI87-03英文版。最终金额须按申请时有效修订和服务组合计算。
Regulatory focus and common causes of failure
申请延迟或被质疑通常来自业务计划、资本来源、governance、personnel、customer assets、marketing、外包或系统安排之间不一致,而非单纯缺少某一张表格。获批后仍须持续满足资本与审慎要求、AML/CFT、客户保护、财务与监管报告、audit、重大变更和跨境经营管理。
塞浦路斯投资服务申请准备
- Define investment services、金融工具、订单执行方式、客户类别和目标市场。
- 准备股权与资金来源、董事及关键人员、business plan、财务预测和控制职能资料。
- 核对客户资产、complaint、conflict of interest、Report、IT security、外包和业务连续性。
- 加密资产服务应另按MiCA及CySEC MiCAR框架判断,不能由传统CIF授权自动覆盖。
Official verification:CySEC投资公司资料、CySEC MiCAR加密资产实体资料。许可范围以CySEC正式决定和公开登记为准。
The policy text is complete but systematic、Processes and people cannot be executed,Most likely to trigger repeated inquiries。
Compliance officer、AMLCO、The person in charge of risk control lacks actual participation,There is a high risk of law enforcement。
Over-reliance on third parties but lack of SLA、Audit rights and emergency plans,High regulatory attention。
Promotional language、Customer source does not match service scope,May trigger additional regulatory issues。
Frequently Asked Questions about Cyprus CySEC Licenses(FAQ)
CySEC依据塞浦路斯实施的MiFID II框架授权CIF提供获批的投资服务。向其他欧洲经济区国家提供服务通常还须履行跨境通知,并遵守目标市场的客户、营销和产品规则;并非获批后即可不经程序覆盖所有国家和业务。
“STP”与“MM”是市场常用经营模式描述,不是取代MiFID II服务项目的法定牌照类别。欧盟《Directive (EU) 2019/2034》第9条按服务与是否持有客户资金或证券规定75,000、150,000或750,000欧元初始资本,应以拟申请活动逐项判断。
传统CIF授权不会自动覆盖加密资产服务。2026年的新申请应按欧盟MiCA和CySEC MiCAR加密资产实体资料判断CASP授权、capital、治理及持续义务;历史国家CASP注册不能作为新申请口径。
申请人应证明在塞浦路斯具备与业务相称的实际管理、personnel、系统和控制能力。office space、数据和系统部署、外包及记录保存安排应按业务模式说明,不能把“所有核心系统必须在本地”或“虚拟地址绝对无效”当作脱离个案的统一规则。
董事会构成、执行与非执行董事、居住安排、Compliance、risk、AML和内审职能应符合公司治理、appropriateness、独立性和利益冲突要求。页面不再采用“固定4名董事、多数居民、所有岗位必须全职本地”的统一模板,具体配置应按申请范围与CySEC反馈确定。
初始资本按欧盟《Directive (EU) 2019/2034》第9条分为75,000、150,000或750,000欧元档位,并取决于获批服务及客户资产权限。besides,还应预算CySEC申请与年费、personnel、site、system、outsourcing、audit、法律和持续报告成本。
CySEC公开费用资料没有为所有CIF申请提供统一10至14个月时限,也未支持把25,000欧元作为普遍“Fast Track”费用。时间由申请范围、integrity、人员与资本准备以及问询决定;应按当前申请程序和书面沟通安排。
通常包括公司与股权控制资料、Source of funds、董事和关键人员适当性、业务计划与财务预测、Proof of capital、governance、AML/CFT、customer assets、complaint、conflict of interest、outsourcing、IT安全和业务连续性文件。以当前CySEC表格与申请范围为准。
企业税务与CIF授权是不同事项,且税率、exemption、预扣和资本利得处理取决于年度、Nature of income、税务居民身份和交易事实。页面不再沿用12.5%及“股息和证券收益一律免税”的概括;should be塞浦路斯税务部门现行资料和专业税务意见为准。
持牌后需持续满足适用的自有资金和审慎要求、客户保护、AML/CFT、governance、财务与监管报告、audit、complaint、外包和重大变更义务。违反后的措施取决于法例、严重程度和程序,不宜用统一“数十万欧元以上”概括。
是否必须加入投资者补偿基金、哪些客户和服务可获保障、赔偿上限及客户资金隔离要求,应按CIF获批服务、客户类别和CySEC现行ICF规则判断。持有客户资金或资产的权限和保障安排必须在申请中单独核对。
常见问题包括业务计划与申请范围不一致、资金来源或资本不足、人员适当性与实际投入不匹配、控制职能流于形式,以及未及时或完整回应问询。差距评估可帮助识别缺口,但不能承诺提高成功率或保证获批。

