NIS2 Country Guide

NIS2 Cyprus: Security of Networks & Information Systems Laws 89(I)/2020 & 60(I)/2025

Cyprus implemented NIS2 through the Security of Networks and Information Systems Laws of 2020 and 2025 (89(I)/2020 as amended by 60(I)/2025). This page sets out the figures the Law actually contains: a six-hour early warning - the tightest incident deadline in the EU - administrative fines to EUR 10,000,000 or 2% with a EUR 10,000 per day continuing-breach penalty, and criminal offences carrying up to three years' imprisonment.

Cyprus Law 60(I)/2025, in force 2025 Early warning: 6 hours Regulator: DSA Last updated: 13 August 2026

Introduction: NIS2 Directive & the Cypriot context

Cyprus already had a cybersecurity framework under the Security of Networks and Information Systems Law 89(I)/2020, with the Digital Security Authority (DSA) as the central body for NIS supervision. NIS2 required Cyprus to expand this regime to many more sectors and entities and to strengthen risk management, governance and incident reporting.

With the 2025 amendment law, Cyprus now operates a full NIS2-aligned framework across a broad range of sectors. Two features of it are unusual enough to change how you plan. The early warning is due in six hours, not the twenty-four the Directive sets as a baseline and that every other member state we have reviewed adopted. And Cyprus runs administrative fines and criminal offences side by side - failing to implement security measures is itself an offence carrying up to three years' imprisonment.

Source: the figures on this page come from the consolidated English text of the Laws published by the Digital Security Authority itself, incorporating Law 60(I)/2025. Where this page cites an Article number, it is an Article of the consolidated Law.
Quick link: New to NIS2? Start with our general guides “What is NIS2?” and “NIS vs NIS2”.

NIS2 implementation in Cyprus

Cyprus has implemented NIS2 through the Security of Networks and Information Systems (Amendment) Law of 2025, No. 60(I)/2025, which amends the Security of Networks and Information Systems Law of 2020, No. 89(I)/2020. Together, these are often referred to as the Cypriot NIS/NIS2 Laws.

The 2025 amendment aligns Cypriot law with NIS2, expands the number of entities in scope, and updates requirements related to risk management, incident notification, supervision and sanctions.

Status

NIS2 is fully implemented in Cyprus through Law 60(I)/2025, which updates and consolidates the 2020 NIS Law.

Legal structure

The Security of Networks and Information Systems Laws of 2020 and 2025 form a single framework that defines scope, obligations, authorities and penalties for NIS2 entities.

Supervisory approach

The Digital Security Authority is the competent authority and runs the national CSIRT. In practice the powers are exercised by the Commissioner for Communications, who heads the Authority and signs its decisions - see authorities.

Who is in scope

Cyprus follows the NIS2 model of essential and important entities. Obligations are largely aligned with NIS2 Annex I security measures, but implemented through the amended national law and related guidance from the DSA.

Who is in scope?

  • Entities operating in NIS2 Annex I sectors (energy, transport, health, drinking water, digital infrastructure, public administration, etc.).
  • Entities operating in NIS2 Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, research, etc.).
  • Medium-sized and larger organisations that meet NIS2 staff or turnover thresholds.
  • Certain providers covered regardless of size, including DNS service providers, TLD registries, trust service providers, and some digital infrastructure and cloud services.

Core obligations

  • Implement risk-management measures covering technical and organisational security for relevant systems.
  • Adopt policies and procedures for incident prevention, detection, response and recovery.
  • Report significant incidents and certain cyber threats to the DSA / CSIRT-CY within NIS2 timeframes.
  • Manage supply-chain risks, including security requirements in contracts with key ICT and service providers.
  • Ensure management bodies approve cybersecurity policies, oversee implementation and receive regular training.

Standards & frameworks

The Cypriot NIS2 Laws do not mandate a single standard, but aligning with ISO/IEC 27001, NIST CSF or a similar ISMS framework is an effective way to structure and demonstrate compliance with national requirements.

What the Law actually requires is set out below - see the list, and what you must submit. It is not a matter of "may be required": Article 2A(4) obliges the Authority to require the information, and it includes your IP ranges.

The list, and what you must submit

Cyprus works from a list rather than a public register. Article 2A(3) requires the Authority to establish a list of essential entities, important entities and entities providing domain name registration services, and to review and where appropriate update it at least every two years.

What you must provide

  • The name of the entity.
  • The address and up-to-date contact details, including email addresses, IP ranges and telephone numbers.
  • Where applicable, the relevant sector and subsector in Annex I or Annex II.

Refusing costs you EUR 5,000

Article 20 lets the Authority demand information by reasoned request, within the timeframe and level of detail it specifies. Failing to comply attracts an administrative fine of up to EUR 5,000 - and, separately, failing to provide requested information within 15 days is a criminal offence.

If you are not established in Cyprus

DNS providers, TLD registries, domain registration services, cloud, data centre, CDN, managed service and managed security service providers, online marketplaces, search engines and social platforms not established in the Republic or another member state must appoint a representative, who the Authority and the national CSIRT may address instead of the entity itself.

Management body duties & training

Article 35A puts three distinct duties on the management body itself, and the third one reaches your staff.

  • Approve the cybersecurity risk-management measures the entity takes to comply with Article 35.
  • Oversee their implementation - and members may be held liable for the entity's infringements of Article 35.
  • Follow training, and offer similar training to employees on a regular basis, so that both can identify risks and assess cybersecurity risk-management practices and their impact on the services the entity provides.
Public bodies are not carved out of the governance duty, but Article 35A(2) preserves the separate liability rules that apply to public institutions, public servants and elected or appointed officials. The duty applies; the liability consequences are governed elsewhere.

Authorities, CSIRT & the Commissioner

Cyprus is centralised, and the Digital Security Authority is correctly named everywhere as the competent authority. But there is a second name in the Law that almost no guide mentions, and it is the one that signs decisions.

The Commissioner for Communications runs the Authority. The consolidated Law refers to the Commissioner more than sixty times, against two references to the Digital Security Authority by name, and defines the Commissioner as the Commissioner for Communications appointed under Article 5(1) of the Law on the Regulation of Electronic Communications and Postal Services. A Deputy Commissioner for Communications advises and assists. When a decision is issued against you - for example after the right to be heard under Article 21 - it is the Commissioner who issues and notifies it.
Role Authority Notes
National competent authority & Single Point of Contact Digital Security Authority (DSA) Responsible for NIS2 implementation, supervision, strategy and coordination; also acts as the Single Point of Contact towards the EU and other Member States.
National CSIRT CSIRT-CY (within the DSA) Receives incident notifications, shares threat information and supports technical response for NIS2 entities.
Office exercising the Authority's powers Commissioner for Communications (with a Deputy Commissioner) Defined in the Law by reference to Article 5(1) of the Law on the Regulation of Electronic Communications and Postal Services. Issues and notifies the Authority's decisions.
Data protection interface Commissioner for Personal Data Protection Article 44A: where an infringement may entail a personal data breach, the Authority must inform the GDPR supervisory authority without undue delay - and where that authority is in another member state, must inform the Cypriot Commissioner for Personal Data Protection.

Reporting: the six-hour warning

This is the provision that makes Cyprus different from every other transposition on this site. Article 35B(4)(a) gives you six hours, not twenty-four, to send the initial warning. Plans written to the Directive's baseline are wrong here by a factor of four.

Stage Deadline What it must contain
Warning 6 hours from becoming aware, and without undue delay Where applicable, whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have cross-border impact.
Incident notification 72 hours Updates the warning; an initial assessment of severity and impact; and, where available, indicators of compromise.
Intermediate report On the Authority's request Relevant status updates.
Final report One month after the incident notification A detailed description including severity and impact; the type of threat or root cause; applied and ongoing mitigation measures; and any cross-border impact.
Progress reports Every 15 days where the incident is still ongoing Running from the incident notification until the final report - which is then due within 15 days of restoration of the affected network or information system.
Trust service providers 24 hours for the notification, by derogation For significant incidents affecting the provision of their trust services.
The Authority owes you a reply, and the CSIRT owes you help. Article 35B(5): within 24 hours of your early warning, and without undue delay, the Authority provides a response including initial feedback and - on request - guidance or operational advice on mitigation measures. The national CSIRT provides additional technical support if you ask, or if the Authority considers it necessary.

An incident is significant where it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity, and/or where it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.

NIS2 timeline & key dates (Cyprus)

12 August 2020 — Security of Networks and Information Systems Law 89(I)/2020 is promulgated in the Official Gazette (No. 4770) under Article 52 of the Constitution.
2022–2024 — NIS2 adopted at EU level; Cyprus prepares amendments to align Law 89(I)/2020 with the new Directive.
2025 — Security of Networks and Information Systems (Amendment) Law 60(I)/2025 takes effect, formally transposing NIS2.
Ongoing — The Authority establishes and maintains the list of essential entities, important entities and domain name registration services, reviewing it at least every two years (Article 2A(3)).
Rolling, per incident — 6 hours to warn, 72 hours to notify, one month to the final report, and progress reports every 15 days while an incident runs.

Sector-specific notes for Cyprus

  • Energy: electricity and gas operators, and related infrastructure, are treated as essential entities with strict resilience and incident-reporting obligations.
  • Transport: air, maritime and port services are especially important given Cyprus’s role as a shipping and logistics hub.
  • Financial services: selected financial institutions are in scope alongside EU financial-sector cyber rules; supervision involves both the DSA and financial regulators.
  • Healthcare: hospitals, clinics and critical e-health services must implement robust cybersecurity and incident-management measures.
  • Public administration: core government bodies and certain public entities fall in scope as part of the national cyber-resilience strategy.
  • Digital infrastructure & ICT providers: data centres, cloud providers, major electronic communications operators and managed service providers are a central focus of the Cypriot NIS2 regime.
  • Trust service providers: the only group with a different reporting clock - 24 hours for the incident notification, by derogation from the 72-hour rule.
  • TLD registries and domain name registration services: subject to their own regime, including a duty to answer lawful and duly substantiated data-access requests within 72 hours, and to publish their disclosure policies.

Administrative fines

Article 43 sets four separate administrative maximums, and the one most likely to apply to an ordinary breach is not the headline figure.

Provision Applies to Maximum
Article 43(1) Any act or omission in breach of the Law EUR 200,000, according to the seriousness of the infringement - and where the infringement is repeated, EUR 10,000 for each day it continues
Article 43(2) Breach of EU decisions or regulations EUR 300,400; on repetition, up to EUR 200,000
Article 43(4) Essential entities infringing Article 35 or 35B EUR 10,000,000 or 2% of total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher
Article 43(5) Important entities infringing Article 35 or 35B EUR 7,000,000 or 1.4%, whichever is higher
Article 20(1)(c) Failure to comply with the Authority's request for information EUR 5,000
The EUR 10,000 per day is the provision to plan around. The turnover-based ceilings attach only to Articles 35 and 35B - the security measures and the reporting duty. Everything else in the Law sits under the EUR 200,000 general maximum, with a daily penalty for continuing breaches that has no stated cap.

Criminal offences & imprisonment

Cyprus does not choose between an administrative regime and a criminal one. It runs both, and the criminal route reaches the core NIS2 duties - not merely obstruction of the regulator.

Conduct Maximum penalty
Failing to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the systems used for operations (Art 44(3)) 3 years' imprisonment or a fine up to EUR 15,000, or both
Failing to notify the Authority, without undue delay, of an incident with severe impact on the continuity of essential services (Art 44(1)) 2 years' imprisonment or a fine up to EUR 10,000, or both
Failing to provide information requested by the Authority within 15 days (Art 44(5)) 3 years' imprisonment or a fine up to EUR 3,400
Violating EU decisions or regulations on the security of networks and information systems (Art 44(7)) 3 years' imprisonment or a fine up to EUR 15,000, or both
Failing to provide information required under EU regulations within 15 days (Art 44(6)) 6 months' imprisonment or a fine up to EUR 3,400, or both
Obstructing or preventing an Authority employee from performing their duties (Art 20(3)) 6 months' imprisonment or a fine up to EUR 8,000, or both
Failing, without reasonable cause, to comply with Article 21 (Art 22) 1 year's imprisonment or a fine up to EUR 5,000, or both
Read the first row again. In Cyprus, not having adequate security measures is not only a regulatory failure attracting a fine - it is an offence for which a court can impose a custodial sentence. Of the transpositions reviewed on this site, only Ireland's proposed regime goes further.

Enforcement & the GDPR overlap

You are heard first

Article 21 requires that, before the Authority adopts a decision affecting a person, that person is given the opportunity to be heard. The Commissioner then issues and notifies the final decision as soon as possible. Failing to comply with Article 21 is itself an offence.

Investigations

Article 23 lets the Authority investigate the activities and operations of any essential or important entity on its own initiative. A person may be represented by a lawyer and may summon witnesses, and may refuse to answer where the answer would self-incriminate or breach lawyer-client privilege.

No double punishment

Article 44A: where the data-protection supervisory authority has imposed a fine under Article 58(2)(i) GDPR for the same conduct, the Authority shall not impose an administrative fine under Article 43A - though it may still apply the non-monetary enforcement measures under Articles 36A and 36B.

How Cyprus differs from the Directive

  • Six hours, not twenty-four. The early warning under Article 35B(4)(a) is the tightest incident deadline of any transposition on this site. An incident-response plan written to the Directive's baseline misses it by a factor of four.
  • Progress reports every 15 days while an incident continues, and a final report due 15 days after restoration - a cadence the Directive does not require.
  • Criminal liability for the core duty. Failing to implement security measures is an offence carrying up to three years' imprisonment, alongside the administrative regime.
  • A daily penalty with no stated ceiling. EUR 10,000 for each day a repeated infringement continues, under Article 43(1).
  • The powers sit with a named office. The Commissioner for Communications heads the Authority and issues its decisions - a fact almost no guide to Cypriot NIS2 mentions.
  • The regulator owes you a response in 24 hours, plus CSIRT technical support on request.
What we deliberately do not state. We print no count of entities in scope and no registration deadline. The Law works from a list the Authority compiles and reviews at least every two years rather than from a single national cut-off date, and we will not invent one.

Greek terms you will meet

Cyprus legislates in Greek and the Authority publishes in both languages. These are the terms you will see on official correspondence and in the Greek text of the Law.

Greek English
Αρχή Ψηφιακής ΑσφάλειαςDigital Security Authority
Επίτροπος ΕπικοινωνιώνCommissioner for Communications
Ασφάλεια Δικτύων και Συστημάτων ΠληροφοριώνSecurity of Networks and Information Systems - the name of the Law
ΚυβερνοασφάλειαCybersecurity
Βασικές οντότητες / Σημαντικές οντότητεςEssential entities / important entities
Διοικητικό πρόστιμοAdministrative fine
Επίσημη Εφημερίδα της ΔημοκρατίαςOfficial Gazette of the Republic

How to prepare for NIS2 in Cyprus

  1. Determine if you are in scope: map your services and size against NIS2 Annex I & II sectors and review DSA guidance for your industry.
  2. Understand your legal obligations: review the consolidated text of the Security of Networks and Information Systems Laws (89(I)/2020 and 60(I)/2025).
  3. Perform a gap assessment: compare your current cybersecurity posture with NIS2-aligned requirements (governance, technical controls, processes, documentation).
  4. Prepare for registration / designation: gather information on critical services, systems, dependencies and NIS contact persons.
  5. Rebuild your incident plan around six hours: the warning is due within six hours of becoming aware, not twenty-four. That is an out-of-hours escalation path, a named decision-maker who can authorise a filing at 3am, and a pre-drafted warning template - not a process that starts with a meeting.
  6. Diarise the 15-day cadence: while an incident runs you owe a progress report every fifteen days, and the final report falls due fifteen days after the affected system is restored.
  7. Review supply-chain risk: update contracts with critical suppliers to include security, audit and incident-notification requirements.
  8. Align with a recognised framework: build or refine an ISMS aligned with ISO 27001 or similar to structure your NIS2 compliance journey.
  9. Train the board, then the staff: Article 35A requires management body members to follow training and to offer similar training to employees on a regular basis. Both halves are the entity's obligation, and members may be held liable for the entity's Article 35 infringements.

Official links & resources

FAQ: NIS2 in Cyprus

Has Cyprus fully transposed NIS2?
Yes. The NIS2 Directive is implemented through the Security of Networks and Information Systems Laws of 2020 and 2025 (89(I)/2020 and 60(I)/2025), which together form the core NIS2 framework in Cyprus.
Which law should we look at for NIS2?
You should refer to the consolidated Security of Networks and Information Systems Laws as published by the Digital Security Authority, which incorporate both the 2020 and 2025 texts.
Who is the NIS2 competent authority in Cyprus?
The Digital Security Authority (Αρχή Ψηφιακής Ασφάλειας) is the competent authority, Single Point of Contact and home of the national CSIRT. In the Law itself the powers are exercised by the Commissioner for Communications, who heads the Authority and issues its decisions.
Do we have to register with the DSA?
The Authority compiles a list of essential entities, important entities and domain name registration services, and reviews it at least every two years (Article 2A(3)). To build it, the Authority requires entities to submit their name, address and up-to-date contact details - including IP ranges and telephone numbers - and the relevant Annex I or II sector and subsector. Failing to comply with an information request carries an administrative fine of up to EUR 5,000, and failing to provide information within 15 days is a criminal offence.
Is a specific certification like ISO 27001 mandatory?
No particular certification is mandated by name, but frameworks such as ISO/IEC 27001 are strongly recommended as a way to structure and evidence your NIS2 compliance efforts.
How quickly must we report an incident?
Six hours for the initial warning - not the twenty-four hours the Directive sets as a baseline, and the tightest deadline of any transposition we have reviewed. Then 72 hours for the incident notification, an intermediate report if the Authority asks, and a final report one month after the notification. If the incident is still running, progress reports every 15 days, with the final report due within 15 days of restoration. Trust service providers notify within 24 hours by derogation.
Can anyone go to prison for a NIS2 breach in Cyprus?
Yes. Cyprus runs criminal offences alongside administrative fines. Failing to take appropriate and proportionate security measures carries up to three years' imprisonment or a fine up to EUR 15,000, or both; failing to notify an incident with severe impact on continuity carries up to two years or EUR 10,000, or both.
What is the maximum administrative fine?
EUR 10,000,000 or 2% of total worldwide annual turnover for essential entities, and EUR 7,000,000 or 1.4% for important entities, whichever is higher - but only for infringements of Articles 35 and 35B. Everything else falls under the general maximum of EUR 200,000, with EUR 10,000 for each day a repeated infringement continues.
Information provided for general guidance and verified against the consolidated English text of the Security of Networks and Information Systems Laws 89(I)/2020 and 60(I)/2025 as published by the Digital Security Authority; always consult the official Cypriot legislation, DSA publications and legal counsel for definitive NIS2 compliance requirements.