Logo

Curaçao is introducing mandatory cybersecurity standards

Valge

I-Gaming Industry Representative Gofaizen & Sherle
Joined
Nov 12, 2025
Location
Rotterdam
The CGA just published a 62-page cybersecurity framework for public consultation — open until 18 June 2026. For the first time, meeting recognised international security standards will be a mandatory condition of holding a CGA licence, for both operators and their B2B suppliers.

The baseline is CIS Controls Implementation Group 1 — covering access controls, vulnerability management, data backup, audit logging, incident response, staff training, and anti-malware. The CGA also expects most operators to progress to the more demanding IG2 level within 24 to 36 months.

The part most relevant to players: operators must notify the regulator within 24 hours of any cybersecurity incident affecting player funds, personal data, or gaming integrity. That's a direct player protection measure and a significant departure from the previous situation where operators could essentially handle breaches however they chose.

B2B providers — platforms, aggregators, sports data suppliers — are also covered as independent licence holders with their own compliance obligations. That's important because a lot of player data exposure historically came through third-party systems rather than operators directly.

The CGA has rejected around 38% of direct licence applications so far. Whether the cybersecurity framework gets meaningfully enforced is the real question — but the direction of travel is clearly toward something closer to what MGA or UKGC demand.
 
Small update about Curaçao reforms. The CGA published a new procedure this week covering every scenario where a Curaçao licence ends: voluntary surrender, revocation, non-renewal, or closure of individual brands.

Before an operator can formally exit, they must settle all outstanding player balances, stop accepting new registrations and bets, clear any debts owed to the CGA and the Curaçao government, and submit a final closure report to the regulator. The CGA licence seal must also be removed from all active properties.

The six-week window for operators whose renewal is denied is the most practically relevant part. From the moment a non-renewal decision lands, the operator must immediately stop taking new customers and bets, but has six weeks to process remaining player funds and complete the paperwork. Pre-paid licence fees are non-refundable regardless of when the decision comes.

One thing worth noting, the CGA has also made clear that operators get removed from the public register automatically after 71 days of non-payment of fees. Combined with the new exit procedure, the message is fairly clear that the post-LOK CGA is trying to eliminate the scenario where defunct or non-compliant operators just keep running without consequence.

Whether this is enforceable in practice against operators that choose to ignore the procedure is still an open question. Curaçao's enforcement track record against genuinely bad actors has historically been limited. But having a formal procedure is at least a precondition for enforcement being possible at all.

You do not have permission to view link Log in or register now.
 

Users who are viewing this thread

Accredited Casinos

Read about our rating system and how it's done.

Actions
Back
Top