NIS2 Cyprus: Security of Networks & Information Systems Laws 89(I)/2020 & 60(I)/2025
Cyprus implemented NIS2 through the Security of Networks and Information Systems Laws of 2020 and 2025 (89(I)/2020 as amended by 60(I)/2025). This page sets out the figures the Law actually contains: a six-hour early warning - the tightest incident deadline in the EU - administrative fines to EUR 10,000,000 or 2% with a EUR 10,000 per day continuing-breach penalty, and criminal offences carrying up to three years' imprisonment.
Introduction: NIS2 Directive & the Cypriot context
Cyprus already had a cybersecurity framework under the Security of Networks and Information Systems Law 89(I)/2020, with the Digital Security Authority (DSA) as the central body for NIS supervision. NIS2 required Cyprus to expand this regime to many more sectors and entities and to strengthen risk management, governance and incident reporting.
With the 2025 amendment law, Cyprus now operates a full NIS2-aligned framework across a broad range of sectors. Two features of it are unusual enough to change how you plan. The early warning is due in six hours, not the twenty-four the Directive sets as a baseline and that every other member state we have reviewed adopted. And Cyprus runs administrative fines and criminal offences side by side - failing to implement security measures is itself an offence carrying up to three years' imprisonment.
NIS2 implementation in Cyprus
Cyprus has implemented NIS2 through the Security of Networks and Information Systems (Amendment) Law of 2025, No. 60(I)/2025, which amends the Security of Networks and Information Systems Law of 2020, No. 89(I)/2020. Together, these are often referred to as the Cypriot NIS/NIS2 Laws.
The 2025 amendment aligns Cypriot law with NIS2, expands the number of entities in scope, and updates requirements related to risk management, incident notification, supervision and sanctions.
Status
NIS2 is fully implemented in Cyprus through Law 60(I)/2025, which updates and consolidates the 2020 NIS Law.
Legal structure
The Security of Networks and Information Systems Laws of 2020 and 2025 form a single framework that defines scope, obligations, authorities and penalties for NIS2 entities.
Supervisory approach
The Digital Security Authority is the competent authority and runs the national CSIRT. In practice the powers are exercised by the Commissioner for Communications, who heads the Authority and signs its decisions - see authorities.
Who is in scope
Cyprus follows the NIS2 model of essential and important entities. Obligations are largely aligned with NIS2 Annex I security measures, but implemented through the amended national law and related guidance from the DSA.
Who is in scope?
- Entities operating in NIS2 Annex I sectors (energy, transport, health, drinking water, digital infrastructure, public administration, etc.).
- Entities operating in NIS2 Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, research, etc.).
- Medium-sized and larger organisations that meet NIS2 staff or turnover thresholds.
- Certain providers covered regardless of size, including DNS service providers, TLD registries, trust service providers, and some digital infrastructure and cloud services.
Core obligations
- Implement risk-management measures covering technical and organisational security for relevant systems.
- Adopt policies and procedures for incident prevention, detection, response and recovery.
- Report significant incidents and certain cyber threats to the DSA / CSIRT-CY within NIS2 timeframes.
- Manage supply-chain risks, including security requirements in contracts with key ICT and service providers.
- Ensure management bodies approve cybersecurity policies, oversee implementation and receive regular training.
Standards & frameworks
The Cypriot NIS2 Laws do not mandate a single standard, but aligning with ISO/IEC 27001, NIST CSF or a similar ISMS framework is an effective way to structure and demonstrate compliance with national requirements.
The list, and what you must submit
Cyprus works from a list rather than a public register. Article 2A(3) requires the Authority to establish a list of essential entities, important entities and entities providing domain name registration services, and to review and where appropriate update it at least every two years.
What you must provide
- The name of the entity.
- The address and up-to-date contact details, including email addresses, IP ranges and telephone numbers.
- Where applicable, the relevant sector and subsector in Annex I or Annex II.
Refusing costs you EUR 5,000
Article 20 lets the Authority demand information by reasoned request, within the timeframe and level of detail it specifies. Failing to comply attracts an administrative fine of up to EUR 5,000 - and, separately, failing to provide requested information within 15 days is a criminal offence.
If you are not established in Cyprus
DNS providers, TLD registries, domain registration services, cloud, data centre, CDN, managed service and managed security service providers, online marketplaces, search engines and social platforms not established in the Republic or another member state must appoint a representative, who the Authority and the national CSIRT may address instead of the entity itself.
Management body duties & training
Article 35A puts three distinct duties on the management body itself, and the third one reaches your staff.
- Approve the cybersecurity risk-management measures the entity takes to comply with Article 35.
- Oversee their implementation - and members may be held liable for the entity's infringements of Article 35.
- Follow training, and offer similar training to employees on a regular basis, so that both can identify risks and assess cybersecurity risk-management practices and their impact on the services the entity provides.
Reporting: the six-hour warning
This is the provision that makes Cyprus different from every other transposition on this site. Article 35B(4)(a) gives you six hours, not twenty-four, to send the initial warning. Plans written to the Directive's baseline are wrong here by a factor of four.
| Stage | Deadline | What it must contain |
|---|---|---|
| Warning | 6 hours from becoming aware, and without undue delay | Where applicable, whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have cross-border impact. |
| Incident notification | 72 hours | Updates the warning; an initial assessment of severity and impact; and, where available, indicators of compromise. |
| Intermediate report | On the Authority's request | Relevant status updates. |
| Final report | One month after the incident notification | A detailed description including severity and impact; the type of threat or root cause; applied and ongoing mitigation measures; and any cross-border impact. |
| Progress reports | Every 15 days where the incident is still ongoing | Running from the incident notification until the final report - which is then due within 15 days of restoration of the affected network or information system. |
| Trust service providers | 24 hours for the notification, by derogation | For significant incidents affecting the provision of their trust services. |
An incident is significant where it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity, and/or where it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.
NIS2 timeline & key dates (Cyprus)
Sector-specific notes for Cyprus
- Energy: electricity and gas operators, and related infrastructure, are treated as essential entities with strict resilience and incident-reporting obligations.
- Transport: air, maritime and port services are especially important given Cyprus’s role as a shipping and logistics hub.
- Financial services: selected financial institutions are in scope alongside EU financial-sector cyber rules; supervision involves both the DSA and financial regulators.
- Healthcare: hospitals, clinics and critical e-health services must implement robust cybersecurity and incident-management measures.
- Public administration: core government bodies and certain public entities fall in scope as part of the national cyber-resilience strategy.
- Digital infrastructure & ICT providers: data centres, cloud providers, major electronic communications operators and managed service providers are a central focus of the Cypriot NIS2 regime.
- Trust service providers: the only group with a different reporting clock - 24 hours for the incident notification, by derogation from the 72-hour rule.
- TLD registries and domain name registration services: subject to their own regime, including a duty to answer lawful and duly substantiated data-access requests within 72 hours, and to publish their disclosure policies.
Administrative fines
Article 43 sets four separate administrative maximums, and the one most likely to apply to an ordinary breach is not the headline figure.
| Provision | Applies to | Maximum |
|---|---|---|
| Article 43(1) | Any act or omission in breach of the Law | EUR 200,000, according to the seriousness of the infringement - and where the infringement is repeated, EUR 10,000 for each day it continues |
| Article 43(2) | Breach of EU decisions or regulations | EUR 300,400; on repetition, up to EUR 200,000 |
| Article 43(4) | Essential entities infringing Article 35 or 35B | EUR 10,000,000 or 2% of total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher |
| Article 43(5) | Important entities infringing Article 35 or 35B | EUR 7,000,000 or 1.4%, whichever is higher |
| Article 20(1)(c) | Failure to comply with the Authority's request for information | EUR 5,000 |
Criminal offences & imprisonment
Cyprus does not choose between an administrative regime and a criminal one. It runs both, and the criminal route reaches the core NIS2 duties - not merely obstruction of the regulator.
| Conduct | Maximum penalty |
|---|---|
| Failing to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the systems used for operations (Art 44(3)) | 3 years' imprisonment or a fine up to EUR 15,000, or both |
| Failing to notify the Authority, without undue delay, of an incident with severe impact on the continuity of essential services (Art 44(1)) | 2 years' imprisonment or a fine up to EUR 10,000, or both |
| Failing to provide information requested by the Authority within 15 days (Art 44(5)) | 3 years' imprisonment or a fine up to EUR 3,400 |
| Violating EU decisions or regulations on the security of networks and information systems (Art 44(7)) | 3 years' imprisonment or a fine up to EUR 15,000, or both |
| Failing to provide information required under EU regulations within 15 days (Art 44(6)) | 6 months' imprisonment or a fine up to EUR 3,400, or both |
| Obstructing or preventing an Authority employee from performing their duties (Art 20(3)) | 6 months' imprisonment or a fine up to EUR 8,000, or both |
| Failing, without reasonable cause, to comply with Article 21 (Art 22) | 1 year's imprisonment or a fine up to EUR 5,000, or both |
Enforcement & the GDPR overlap
You are heard first
Article 21 requires that, before the Authority adopts a decision affecting a person, that person is given the opportunity to be heard. The Commissioner then issues and notifies the final decision as soon as possible. Failing to comply with Article 21 is itself an offence.
Investigations
Article 23 lets the Authority investigate the activities and operations of any essential or important entity on its own initiative. A person may be represented by a lawyer and may summon witnesses, and may refuse to answer where the answer would self-incriminate or breach lawyer-client privilege.
No double punishment
Article 44A: where the data-protection supervisory authority has imposed a fine under Article 58(2)(i) GDPR for the same conduct, the Authority shall not impose an administrative fine under Article 43A - though it may still apply the non-monetary enforcement measures under Articles 36A and 36B.
How Cyprus differs from the Directive
- Six hours, not twenty-four. The early warning under Article 35B(4)(a) is the tightest incident deadline of any transposition on this site. An incident-response plan written to the Directive's baseline misses it by a factor of four.
- Progress reports every 15 days while an incident continues, and a final report due 15 days after restoration - a cadence the Directive does not require.
- Criminal liability for the core duty. Failing to implement security measures is an offence carrying up to three years' imprisonment, alongside the administrative regime.
- A daily penalty with no stated ceiling. EUR 10,000 for each day a repeated infringement continues, under Article 43(1).
- The powers sit with a named office. The Commissioner for Communications heads the Authority and issues its decisions - a fact almost no guide to Cypriot NIS2 mentions.
- The regulator owes you a response in 24 hours, plus CSIRT technical support on request.
Greek terms you will meet
Cyprus legislates in Greek and the Authority publishes in both languages. These are the terms you will see on official correspondence and in the Greek text of the Law.
| Greek | English |
|---|---|
| Αρχή Ψηφιακής Ασφάλειας | Digital Security Authority |
| Επίτροπος Επικοινωνιών | Commissioner for Communications |
| Ασφάλεια Δικτύων και Συστημάτων Πληροφοριών | Security of Networks and Information Systems - the name of the Law |
| Κυβερνοασφάλεια | Cybersecurity |
| Βασικές οντότητες / Σημαντικές οντότητες | Essential entities / important entities |
| Διοικητικό πρόστιμο | Administrative fine |
| Επίσημη Εφημερίδα της Δημοκρατίας | Official Gazette of the Republic |
How to prepare for NIS2 in Cyprus
- Determine if you are in scope: map your services and size against NIS2 Annex I & II sectors and review DSA guidance for your industry.
- Understand your legal obligations: review the consolidated text of the Security of Networks and Information Systems Laws (89(I)/2020 and 60(I)/2025).
- Perform a gap assessment: compare your current cybersecurity posture with NIS2-aligned requirements (governance, technical controls, processes, documentation).
- Prepare for registration / designation: gather information on critical services, systems, dependencies and NIS contact persons.
- Rebuild your incident plan around six hours: the warning is due within six hours of becoming aware, not twenty-four. That is an out-of-hours escalation path, a named decision-maker who can authorise a filing at 3am, and a pre-drafted warning template - not a process that starts with a meeting.
- Diarise the 15-day cadence: while an incident runs you owe a progress report every fifteen days, and the final report falls due fifteen days after the affected system is restored.
- Review supply-chain risk: update contracts with critical suppliers to include security, audit and incident-notification requirements.
- Align with a recognised framework: build or refine an ISMS aligned with ISO 27001 or similar to structure your NIS2 compliance journey.
- Train the board, then the staff: Article 35A requires management body members to follow training and to offer similar training to employees on a regular basis. Both halves are the entity's obligation, and members may be held liable for the entity's Article 35 infringements.
