Not publishable as-is. 1 of 5 publication_gate checks fail. The renderer displays the gate rather than suppressing it. Legal review and sub-brief approval are informational and are not part of this test.
Cyprus
CYschema crypto-v2.0.0trajectory: not yet assessedregulatedoverlaps: FIM, WPM
Last updated · 7 categories · 23 sourced
findings · 25 sources in the cumulative register
7Categoriesbaseline.
23Findings.claims[]
12Tier-1 sourcesrun_metadata.t1_source_count
Confidence mix(sums to 7 rendered categories; click to filter)
No categories moved this cycle.
Jurisdiction lead brief
Lead Signal
Cyprus's Markets in Crypto-Assets Regulation transitional backstop has closed. The Article 143(3) national grandfathering arrangement, which had allowed crypto-asset service providers operating under pre-MiCA Cypriot law to continue pending MiCA authorisation, expired on 1 July 2026 -- and this cycle's research corrects an earlier framing that treated that date as still ahead of us. CySEC set 27 February 2026 as the cut-off for MiCA authorisation applications from providers relying on the transitional relief, required wind-down plans from any provider that had not applied by that date, and followed through with a post-deadline AML circular issued 9 July 2026. Together these confirm that Cyprus has moved from a live transitional window into a concluded, actively enforced post-deadline compliance state: any entity now providing crypto-asset services to EU clients without a MiCA licence is in breach of EU law and must have ceased those services or be executing an approved wind-down. This is a material shift in framing rather than a new legal event -- the underlying deadline was always 1 July 2026 -- but it changes how the Cypriot licensing landscape should be read going into the second half of 2026: the question is no longer when the grace period ends but who has actually exited or wound down since it did. CySEC's own authorisation activity in the run-up to and since the deadline -- including MiCA CASP licences granted to Revolut and eToro, which now offer regulated crypto services across the EEA under Cypriot authorisation -- illustrates the licensing side of that transition working as intended, though the specific volume of firms that wound down rather than converting has not yet been independently confirmed and is worth watching for in subsequent research passes.
Other Developments
MiCA's token taxonomy continues to apply in Cyprus without any national carve-out: e-money tokens pegged to a single official currency, asset-referenced tokens pegged to other assets or baskets, and other crypto-assets remain three legally distinct categories, with e-money token holders retaining a direct, full-face-value redemption right against the issuer, and non-fungible crypto-assets treated as potentially falling outside the standard fungible-token categories. Consumer-protection rules under MiCA Article 66 and the custody-segregation and white-paper-liability provisions remain in force and unchanged. However, this cycle also surfaced a correction to the evidentiary basis behind Cyprus's amber consumer-protection rating: a previously cited ESMA finding of high cross-border complaint volume and supervisory shortcomings turns out to be a March 2022 MiFID II passporting peer review covering conduct years before MiCA existed, not a crypto-specific or current assessment. It is being retained only as dated, cross-domain context on CySEC's general supervisory capacity, and a fresh MiCA-era supervisory assessment of CySEC is still needed before that rating can be considered well-evidenced. On the stablecoin side, the Central Bank of Cyprus's exact allocation of Title IV credit-institution issuer-authorisation responsibility remains marked to be confirmed on ESMA's own competent-authorities list, and the Central Bank has set itself a 30 September 2026 target to bring EMI/PI supervisory practice into line with MiCA's Title VI market-abuse guidelines -- a prospective milestone rather than settled practice. On-chain activity -- staking, DeFi lending and borrowing, mining, and validator operation -- remains without any dedicated licensing regime at either EU or Cypriot level; the joint EBA/ESMA Article 142 report describes these as market trends without proposing binding rules, and mining and validator treatment specifically remains an unresearched gap rather than a confirmed regulatory silence. Cyprus's tax treatment of crypto-assets remains the thinnest area of this record: no primary-source confirmation exists that the 2002 general capital gains law extends to crypto disposals, and no Inland Revenue Department or Tax Department circular addressing crypto income tax or VAT treatment could be located.
Cross-Monitor Connections
Two threads in this cycle sit outside crypto's own analytical lane. The Travel Rule obligations under Regulation (EU) 2023/1113 -- requiring originator CASPs to hold counterparty information on self-hosted-address transfers and to assess address ownership above EUR 1,000 -- together with CySEC's 9 July 2026 post-deadline AML circular, fall within the AML/CFT surface that crypto now subscribes to rather than independently analyses; that material is being routed to financial-integrity for original treatment. Separately, the payments-adjacent dimension of Cyprus's stablecoin regime -- e-money token redemption rights and the Central Bank's Title IV/VI compliance timeline running to 30 September 2026 -- is relevant to how payment instruments are framed and is being flagged to world-payments for tracking on that basis. Neither connection changes crypto's own module ratings this cycle, but both mean that a fuller picture of Cyprus's AML posture and stablecoin-as-payment-instrument treatment will depend on synthesis across monitors rather than this record alone.
Outlook
The near-term watch list for Cyprus centres on confirmation rather than new rulemaking. Whether the Central Bank of Cyprus actually brings EMI/PI supervisory practice into compliance with the Title VI market-abuse guidelines by its self-set 30 September 2026 target is the clearest dated marker on the horizon, and its outcome will speak to whether Cyprus's stablecoin_regime amber rating should move. A parallel and less time-bound item is whether the Central Bank clarifies its own share of Title IV credit-institution competent-authority responsibility, which ESMA's list still marks as unresolved. On consumer protection, the priority is sourcing a genuinely current, MiCA-era supervisory assessment of CySEC to replace the stale 2022 MiFID II peer-review evidence now downgraded in this record. And on tax, the absence of any crypto-specific guidance from the Cyprus Inland Revenue Department or Tax Department remains an open structural gap that primary-source research should target directly rather than continuing to infer from general accession-era summaries. None of these items currently point toward a change in Cyprus's overall regulated status, but each represents a live thread that could shift an individual module's rating in either direction as fresh primary-source material becomes available.
7 of 7 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Cyprus operates under Regulation (EU) 2023/1114 (MiCA) as its primary crypto framework. ESMA's list of competent authorities designates CySEC as the Title V authorisation authority for CASPs, with the Central Bank of Cyprus (CBC) sharing Title IV responsibilities and non-credit-institution CASPs falling to CySEC. A national grandfathering period under MiCA Art.143(3) allows pre-MiCA VASP registrants to continue operating until authorised or refused, or until the EU-wide 1 July 2026 backstop, whichever is sooner. CySEC has since granted a wave of MiCA CASP authorisations (Revolut, eToro, Taurus-adjacent MiFID licensing) confirming the regime is operative.
Standing sub-brief524 words · last cycle 2026-09-11
Crypto Licensing
Cyprus's crypto-licensing landscape is anchored in the Markets in Crypto-Assets Regulation (MiCA), and CySEC operates as Cyprus's Title V competent authority for authorising crypto-asset service providers, with Title IV issuer authorisation and Title V notification for credit institutions and electronic-money institutions falling to the Central Bank of Cyprus. This designation is drawn directly from ESMA's own Article 93 competent-authorities list and is not in question.
The most significant development in this cycle concerns the Article 143(3) national transitional regime -- the mechanism that had allowed crypto-asset service providers operating under pre-MiCA Cypriot law to keep serving clients while their MiCA authorisation applications were pending. That transitional window has now concluded. ESMA's own statement on the end of transitional periods under MiCA confirms the EU-wide backstop expired on 1 July 2026, and Cyprus-specific reporting adds operational detail: CySEC set 27 February 2026 as the deadline for providers relying on the transitional relief to submit a MiCA authorisation application, required a formal wind-down plan from any provider that had not applied by that date, and issued a post-deadline AML circular on 9 July 2026 addressing the compliance state of providers moving through or past the transition. Read together, these facts establish that Cyprus's transitional period is a closed chapter rather than a live one: any entity providing crypto-asset services to EU clients without a MiCA licence after 1 July 2026 is now in breach of EU law and must either have ceased those services or be actively executing an approved wind-down plan.
This closure sits alongside continued licensing activity on the other side of the ledger. CySEC has granted MiCA CASP authorisations to major platforms including Revolut and eToro, each of which is now positioned to offer regulated crypto services across the EEA on the strength of its Cypriot authorisation -- a concrete illustration of MiCA's passporting design operating as intended and of Cyprus's role as an EEA-wide licensing gateway for at least some large platforms. One caution from this cycle's review process is worth flagging explicitly: Taurus, a crypto custodian previously associated with Cyprus in some reporting, holds a MiFID II licence rather than a MiCA CASP authorisation, and should not be read as evidence of MiCA-operative licensing activity. The distinction matters because MiFID II and MiCA authorisations carry different scopes, obligations, and supervisory consequences, and conflating the two would overstate the breadth of CySEC's MiCA-licensed population.
Outlook
The crypto-licensing picture in Cyprus is now best read as settled-and-enforced rather than transitional. The open question going forward is less about the rules themselves -- which are fully in force -- and more about compliance outcomes: how many providers that relied on the Article 143(3) transitional window actually completed wind-down versus converted to full MiCA authorisation, and whether CySEC's 9 July 2026 AML circular signals a broader supervisory posture toward post-deadline non-compliance. Continued monitoring of CySEC's authorisation register and enforcement actions over the coming quarters should clarify both points. No change to the green traffic-light rating is indicated by this cycle's findings, but the shift from transition pending to transition concluded and enforced is itself the substantive development worth carrying forward into subsequent cycles.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and findings (4)
T1 · ESMAESMA — CySEC is the designated competent authority for authorisation of crypto-asset service providers under Title V of MiCA in Cyprus, while CBC handles Title IV (ARTs/EMTs) and credit institutions/EMIs under Title V notification.retrieved M5bindingin force
T1 · ESMAESMA — Crypto-asset service providers that provided services in Cyprus in accordance with pre-30 December 2024 national law may continue to do so under Article 143(3) transitional measures until granted or refused MiCA authorisation, or until 1 July 2026, whichever is sooner.retrieved M4bindingin force
T1 · ESMAESMA — The EU-wide MiCA transitional period expires on 1 July 2026; after this date any entity providing crypto-asset services to EU clients without a MiCA licence is in breach of EU law and must cease such services.retrieved M5bindingin force
T4 · CoinDeskCoinDesk — CySEC has granted MiCA CASP authorisations to major crypto platforms (e.g., Revolut, eToro), enabling regulated crypto services across the EEA, evidencing an operative licensing regime in Cyprus.retrieved M3non-binding
Cyprus follows MiCA's tripartite crypto-asset taxonomy (asset-referenced tokens, e-money tokens, and other crypto-assets including utility tokens and NFTs), applied uniformly under CySEC/CBC supervision. A CY-specific Joint ESAs consumer factsheet confirms EMT redemption rights and NFT non-fungibility treatment as applied in the Cypriot market context.
Standing sub-brief308 words · last cycle 2026-09-11
Token Classification
MiCA's tripartite taxonomy for crypto-assets applies to Cyprus as a matter of directly binding EU law, with no Cyprus-specific carve-out identified in this cycle's research. The regulation distinguishes e-money tokens (EMTs), which are stabilised against a single official currency, from asset-referenced tokens (ARTs), which are stabilised against other assets or a basket of assets, and separately from crypto-assets that fall into neither category. This classification structure is imported wholesale from the EU regulation and confirmed for Cyprus specifically through the Joint ESAs' updated consumer factsheet for Cyprus.
A concrete consumer-facing consequence of the EMT classification is the redemption right: holders of e-money tokens have the right to redeem their tokens at full face value, in the currency to which the token is pegged, directly from the issuer. This is confirmed both at the general MiCA level and specifically for Cypriot consumers through the same Joint ESAs factsheet, and it functions as one of the clearest investor-protection guarantees built into the EMT category.
Non-fungible crypto-assets receive distinct treatment under this taxonomy. Where the relative value of a unique, non-fungible crypto-asset cannot be identified by comparison to an existing market or to equivalent fungible assets, it may fall outside MiCA's standard fungible-token categories altogether. This carve-out matters for Cyprus's growing NFT-adjacent market activity, since it means such assets are not automatically captured by the EMT/ART/other-crypto-asset framework that governs fungible tokens.
Outlook
Because this taxonomy is directly imported from binding EU law rather than shaped by Cypriot discretion, no jurisdiction-specific developments are expected here absent a change at the EU level. The item worth continued attention is how NFT-adjacent products marketed in or from Cyprus are treated in practice as the market matures -- particularly where issuers attempt to structure fungible-token-like products with NFT wrappers to avoid MiCA's classification thresholds. No change to the green traffic-light rating is indicated.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and findings (3)
T1 · Joint ESAs (ESMA/EBA/EIOPA)Joint ESAs (ESMA/EBA/EIOPA) — If a consumer holds an e-money token (EMT), they have the right to get their money back from the issuer at its full face value, in the currency to which the token is pegged.retrieved M5bindingin force
T2 · EUR-LexEUR-Lex — MiCA distinguishes e-money tokens (stabilised against a single official currency) from asset-referenced tokens (stabilised against other assets or a basket of assets) and from crypto-assets that are neither ART nor EMT.retrieved M4bindingin force
T1 · Joint ESAs (ESMA/EBA/EIOPA)Joint ESAs (ESMA/EBA/EIOPA) — Crypto-assets that are unique and non-fungible, such that their relative value cannot be easily identified by comparison to an existing market or equivalent assets, are treated distinctly and may fall outside standard MiCA fungible-token categories.retrieved M3bindingin force
MiCA as applied in Cyprus does not create a bespoke licensing category for staking, DeFi lending, DEX operation, mining, or node/validator operation; these remain either unregulated or captured only incidentally where a CASP bundles them as an ancillary service under its Title V authorisation (e.g., Revolut's Cyprus-licensed entity marketing zero-fee staking). EBA/ESMA joint MiCAR Article 142 analysis flags DeFi, lending/borrowing and staking business models as emerging-risk areas without dedicated rules.
Standing sub-brief353 words · last cycle 2026-09-11
On-Chain Activity Regime
Cyprus has no dedicated licensing or registration regime -- at either the national or EU level -- for on-chain activities such as staking, DeFi lending and borrowing, mining, or validator/node operation. Treatment of these activities remains incidental to CASP authorisation under MiCA rather than governed by any purpose-built framework. This is not a Cyprus-specific gap; it reflects the current state of EU crypto regulation more broadly, in which MiCA's licensing architecture was built around service-provider categories rather than around the underlying on-chain activities themselves.
Market practice offers an illustrative data point rather than a regulatory one: Revolut's CySEC-authorised MiCA entity offers zero-fee staking with advertised rewards, structured as an activity ancillary to its licensed crypto services rather than as a separately licensed line of business. This is consistent with the absence of a dedicated staking licensing category and should be read as evidence of how existing CASP authorisation is being stretched to cover staking services, not as evidence that staking itself has become a licensed activity in its own right.
At the EU policy level, the joint EBA/ESMA report under MiCAR Article 142 examines DeFi adoption and lending, borrowing, and staking business models as emerging crypto-market trends, but does so analytically and without proposing binding rules -- consistent with an unregulated-gap status for DeFi activity across the EU, including Cyprus. Separately, whether mining, node-operation, or validator activity in Cyprus is addressed by MiCA or by any CySEC guidance was not resolved in this research pass; this should be read as an unresearched gap rather than as confirmation that no such rules exist.
Outlook
This module's amber rating reflects a genuine absence of dedicated rules rather than any ambiguity in what does exist. The key forward-looking marker is the EBA/ESMA Article 142 report, which -- while non-binding today -- is the most likely vehicle through which any future EU-wide proposal on DeFi, staking, or lending regulation would first surface. Confirming whether mining and validator activity in Cyprus is addressed by any guidance not yet located remains a priority for the next research pass, given the current evidentiary basis here is thin.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and findings (3)
T4 · CoinDeskCoinDesk — Revolut's Cyprus CySEC-authorised MiCA entity offers zero-fee staking with advertised rewards as part of its licensed crypto services, treating staking as an ancillary service rather than a separately licensed activity.retrieved M3non-binding
T1 · EBAEBA — EBA and ESMA's joint MiCAR Article 142 report analyses DeFi adoption, lending, borrowing and staking business models as EU crypto-market trends without issuing binding policy recommendations, indicating an unregulated-gap status for DeFi activity across the EU including Cyprus.retrieved M3non-binding
T1 · ESMAESMA — No CY-specific mining, node-operation, or validator licensing regime was identified in this research pass; mining/validation activity in Cyprus is not addressed by MiCA or CySEC guidance located to date.retrieved M2non-bindingour coverage gap, expected to resolve on a re-run
The Central Bank of Cyprus (CBC) is designated alongside CySEC for MiCA Title IV (ART/EMT issuance) responsibilities, with CySEC handling non-credit-institution authorisation and CBC handling credit institutions/EMIs. CBC has separately indicated (via the ESMA market-abuse guidelines compliance table) that it intends to comply with Title VI market-abuse guidelines for EMIs/PIs only by 30 September 2026, citing no current express intention of regulated entities to begin related activities — this compliance date is prospective/not-yet-effective and should be read as a CAUTION-flagged, pre-live position rather than a settled in-force requirement.
Standing sub-brief334 words · last cycle 2026-09-11
Stablecoin Regime
Cyprus's stablecoin oversight is split between two authorities under MiCA's Title IV framework. CySEC and the Central Bank of Cyprus share Title IV competent-authority functions, with CySEC handling non-credit-institution issuers; the credit-institution side of that allocation is marked to be confirmed on ESMA's own list of competent authorities notified under MiCA, meaning the precise division of responsibility for bank-affiliated issuers has not yet been definitively confirmed by a Cypriot primary source.
On the supervisory-timeline side, the Central Bank of Cyprus has stated an intention to bring its supervisory practice for electronic-money institutions and payment institutions into compliance with ESMA's Title VI guidelines on market abuse by 30 September 2026. Notably, the Central Bank has also indicated there is no current express intention among its regulated entities to begin the kinds of activities those guidelines address, which suggests this compliance target is a readiness measure rather than a response to imminent market activity. Because this milestone has not yet arrived as of this cycle's research date, it should be read as a prospective, not-yet-effective commitment rather than settled supervisory practice.
On the consumer-facing side of stablecoin regulation, e-money token holders in Cyprus retain the MiCA-wide right to redeem their tokens at full face value from the issuer, in the currency to which the token is pegged -- a right that applies uniformly as MiCA is applied domestically and that mirrors the redemption guarantee described in the token-classification module.
Outlook
Two dated markers define this module's near-term trajectory: the Central Bank's 30 September 2026 compliance target for Title VI market-abuse supervision, and the still-unresolved question of exactly how Title IV credit-institution competent-authority responsibility is allocated between CySEC and the Central Bank. Confirmation on either point -- particularly a Central Bank statement resolving the to-be-confirmed allocation -- would likely be sufficient to move this module's rating from amber toward green. Until then, the amber rating reflects genuine, acknowledged gaps in implementation detail rather than any deficiency in the underlying redemption-rights framework, which is fully settled.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and findings (3)
T1 · ESMAESMA — For MiCA Title IV, CySEC and CBC share competent-authority functions in Cyprus (further allocation details marked TBC in the ESMA notification list), with CySEC handling Title III for non-credit institutions and CBC for credit institutions.retrieved M4bindingin force
T1 · ESMAESMA — The Central Bank of Cyprus, as competent authority for Title VI of MiCA on market abuse for EMIs and PIs, intends to comply with the relevant ESMA guidelines by 30 September 2026, citing no current express intention of regulated entities to begin related activities.retrieved M3bindingenacted not yet effective
T1 · Joint ESAs (ESMA/EBA/EIOPA)Joint ESAs (ESMA/EBA/EIOPA) — Holders of e-money tokens in Cyprus have the right to redeem at full face value from the issuer, in the currency to which the token is pegged, under MiCA as applied domestically.retrieved M5bindingin force
MiCA-derived consumer-protection duties (marketing fairness, custody segregation, complaint handling, risk disclosure) apply to CY-licensed CASPs. However, an ESMA peer review specifically targeting CySEC found Cyprus had the highest level of outgoing cross-border activity and complaint volume among six reviewed NCAs, with supervisory shortcomings in monitoring aggressive marketing of speculative products — prompting the first-ever Article 16 ESMA recommendations issued to a national competent authority.
Standing sub-brief368 words · last cycle 2026-09-11
Consumer Protection
Cyprus's consumer-protection framework for crypto-assets rests on binding, in-force MiCA provisions. Article 66 requires crypto-asset service providers to give clients information that is fair, clear, and not misleading, including ensuring that marketing communications are clearly identified as such. Providers must also keep client crypto-assets and funds segregated from their own assets and are prohibited from using client assets on their own account. Issuers of asset-referenced tokens carry a further set of obligations: they must publish a crypto-asset white paper and their marketing communications on their website, and they are liable for damages arising from incorrect information in that white paper. None of these provisions is new or contested in this cycle; they represent settled, binding EU law as applied in Cyprus.
The more consequential development this cycle is a correction to the evidentiary basis underlying Cyprus's amber consumer-protection rating. A previously cited ESMA finding -- that CySEC had the highest outgoing cross-border activity and complaint volume among six reviewed national competent authorities, alongside noted supervisory shortcomings -- has been re-examined and found to originate from a March 2022 ESMA peer review of cross-border MiFID II passporting activity, covering supervisory conduct between August 2018 and August 2020. That review predates MiCA entirely and concerns securities-market passporting supervision, not crypto-asset or MiCA-specific supervision. Treating it as current, crypto-specific evidence would have overstated what is actually known about CySEC's present-day MiCA-era supervisory performance. It is retained in this record only as dated, cross-domain context on CySEC's general supervisory capacity -- useful background, but not a substitute for a genuine assessment of how CySEC is currently supervising crypto-asset service providers under MiCA.
Outlook
The substantive consumer-protection rules in force in Cyprus are not in question and require no further monitoring at this time beyond routine confirmation of continued application. What does require attention is sourcing a current, MiCA-era supervisory assessment of CySEC -- whether through a future ESMA peer review specific to crypto-asset supervision, enforcement statistics, or CySEC's own reporting -- to properly ground this module's amber rating going forward. Until such a source is located, the rating should be understood as resting on the strength of the binding rules themselves rather than on any confirmed assessment of supervisory execution.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and findings (4)
T1 · ESMAESMA — Article 66 of MiCA provides that crypto-asset service providers shall provide their clients with information that is fair, clear and not misleading, including in marketing communications, which shall be identified as such.retrieved M4bindingin force
T1 · ESMAESMA — ESMA found that out of six jurisdictions reviewed, Cyprus had the highest level of outgoing cross-border activity and by far the highest number of complaints relating to firms' cross-border activities, with CySEC's supervisory activities proving insufficient to address risks from aggressive marketing of speculative products.retrieved M4non-binding
T2 · EUR-LexEUR-Lex — MiCA requires crypto-asset service providers to keep clients' crypto-assets and funds separate from other assets and not use them on their own account.retrieved M5bindingin force
T2 · EUR-LexEUR-Lex — Issuers of asset-referenced tokens must publish a crypto-asset white paper and any marketing communication on their website and are liable for damages for incorrect information in the white paper.retrieved M4bindingin force
No CY-specific Inland Revenue Department circular or CySEC/Ministry of Finance guidance on the taxation of crypto-asset gains, income, or VAT treatment was located in this research pass. Cyprus's general capital gains tax law (adopted 2002) is historically scoped to disposals of Cyprus immovable property and shares in companies holding such property; whether or how it extends to crypto-asset disposals has not been confirmed by a primary tax-authority source in this pass. This module is emitted amber pending primary-source escalation.
Standing sub-brief312 words · last cycle 2026-09-11
Tax Treatment
Cyprus's tax treatment of crypto-assets remains the least developed area of this jurisdictional record, reflecting a structural gap rather than a settled policy position. Cyprus's general capital gains tax law, dating to 2002, has a historical scope covering disposals of Cyprus immovable property and shares in companies holding such property; no primary tax-authority source located in this research confirms that this law's scope has been extended, by ruling, circular, or amendment, to cover crypto-asset disposals. Absent such confirmation, the applicability of capital gains tax to crypto transactions in Cyprus should be treated as unresolved rather than assumed either way.
Similarly, no circular from the Cyprus Inland Revenue Department addressing the income-tax treatment of cryptocurrency-related income was located, and no circular from the Cyprus Tax Department addressing the VAT treatment of crypto-asset exchange transactions was located. In both cases, this reflects a genuine research gap -- an absence of located primary guidance -- rather than an affirmatively confirmed finding that no such guidance exists or that no tax liability arises. It remains possible that relevant guidance exists but was not surfaced in this research pass, and this distinction is treated deliberately in this record rather than collapsed into a false negative.
Outlook
Tax treatment is flagged across this monitor's broader coverage as a structurally under-indexed area, and Cyprus's experience here is consistent with that pattern rather than an outlier. The clear next step is targeted primary-source escalation directly to the Cyprus Tax Department and Ministry of Finance, seeking any existing circulars, rulings, or informal guidance on the capital gains, income tax, and VAT treatment of crypto-asset transactions. Until that escalation produces a result, this module's amber rating and thin evidentiary base should be read as reflecting an active research gap rather than a settled regulatory position, and any downstream conclusions about crypto tax exposure in Cyprus should be treated as provisional.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and findings (3)
T3 · EUR-LexEUR-Lex — Cyprus adopted legislation simplifying and harmonising its income tax, capital gains tax, and stamp duty laws with the EU acquis in July 2002; this general capital gains tax law has not been confirmed by a primary tax-authority source as covering crypto-asset disposals.retrieved M2non-bindingour coverage gap, expected to resolve on a re-run
T3 · EUR-LexEUR-Lex — No Cyprus-specific Inland Revenue Department circular on cryptocurrency income taxation was identified in this research pass.retrieved M2non-bindingour coverage gap, expected to resolve on a re-run
T3 · EUR-LexEUR-Lex — No Cyprus-specific VAT guidance on crypto-asset exchange transactions was identified in this research pass.retrieved M2non-bindingour coverage gap, expected to resolve on a re-run
Cyprus-based CASPs are subject to EU Regulation 2023/1113 (the crypto Travel Rule), which extends FATF-style originator/beneficiary information requirements to crypto-asset transfers and treats EMTs as crypto-assets for this purpose. MiCA authorisation obtained via CySEC additionally passports Cypriot CASPs to operate across all EEA states without additional national cross-border restriction.
Standing sub-brief257 words · last cycle 2026-09-11
Cross-Border Transfer
Cyprus's cross-border crypto-asset transfer rules are governed directly by Regulation (EU) 2023/1113, the EU's crypto Travel Rule, which applies as binding law without Cypriot modification. Under this regulation, the crypto-asset service provider of the originator in a transfer to a self-hosted address must obtain and hold originator and beneficiary information and ensure that the transfer can be individually identified. For transfers exceeding EUR 1,000 to a self-hosted address specifically, the originator's crypto-asset service provider must take adequate measures to assess whether that address is owned or controlled by the originator -- an additional verification step layered onto the general information-holding requirement.
Separately from information-accompanying-transfer obligations, MiCA's passporting mechanism governs cross-border service provision itself: a MiCA licence granted by CySEC allows a Cyprus-based crypto-asset service provider to offer regulated crypto services across all EEA countries without needing additional national authorisation in each destination market. This is the same mechanism underpinning the EEA-wide expansion of CySEC-licensed platforms such as Revolut and eToro described under crypto-licensing, and it represents one of the more concretely operative and market-tested elements of Cyprus's crypto framework.
Outlook
Both the Travel Rule information requirements and MiCA's passporting mechanism are fully in force and unchanged this cycle; no near-term developments are expected absent a change at the EU regulatory level. The Travel Rule dimension of this module overlaps substantively with AML/CFT supervision and is being tracked jointly with financial-integrity going forward, meaning future updates to this module's Travel Rule content may increasingly originate from that monitor's independent analysis rather than from crypto-native research alone.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and findings (3)
T1 · EUR-Lex / European Parliament and CouncilEUR-Lex / European Parliament and Council — In the case of a transfer of crypto-assets made to a self-hosted address, the crypto-asset service provider of the originator shall obtain and hold originator/beneficiary information and ensure the transfer can be individually identified.retrieved M5bindingin force
T1 · EUR-Lex / European Parliament and CouncilEUR-Lex / European Parliament and Council — For a transfer of crypto-assets exceeding EUR 1,000 to a self-hosted address, the crypto-asset service provider of the originator must take adequate measures to assess whether that address is owned or controlled by the originator.retrieved M4bindingin force
T4 · CoinDeskCoinDesk — A MiCA licence granted by CySEC allows a Cyprus-based CASP to provide regulated crypto services across all EEA countries without additional national cross-border authorisation.retrieved M4bindingin force
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
Blocking. 1 failing check(s).
schema_valid
FAIL
min_quoted_text_present
waived — floor 0%
egress_verified
pass
every_practical_object_has_source_id
n/a — no subject in this jurisdiction
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
68.42
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Cyprus
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: module cards load OPEN; standing positions render in full; sub-briefs and jurisdiction briefs load as a clamped teaser with an explicit “read full” control carrying the true word count; earlier updates stay collapsed behind a counted summary. No text is hidden without disclosing how much of it there is.
Sentinel-fed modules receive no special rendering treatment. sentinel_feed is an attribution chip only: it does not suppress content, does not generate an absence reason code, and does not exclude the module from any count, filter, search index or export on this page.
Family taxonomy is renderer-level presentation config, not a JID field. Colour is always duplicated in text and is never the sole carrier of meaning.