10 August 2026
Cybersecurity has evolved from a predominantly technical issue into a matter of corporate governance and regulatory compliance. The implementation of the NIS2 Directive (Directive (EU) 2022/2555) in Cyprus significantly expands the number of organisations subject to mandatory cybersecurity requirements and introduces enhanced obligations relating to risk management, incident reporting, governance and regulatory supervision.
In Cyprus, NIS2 was implemented principally through Law 60(I)/2025, which amended the Security of Networks and Information Systems Law of 2020 (Law 89(I)/2020). The amended legislation entered into force in 2025 and substantially revised the existing cybersecurity regulatory framework.
For businesses operating in Cyprus, one of the first questions is therefore no longer simply whether their IT systems are adequately protected, but whether the organisation itself falls within the scope of the NIS2 regulatory regime.
Which organisations fall within NIS2 in Cyprus?The scope of the Cyprus legislation is considerably broader than under the previous NIS framework.
As a general rule, the legislation applies to public or private entities which:
(a) carry out activities falling within one of the sectors listed in Annex I or Annex II of the Law; and
(b) qualify as at least a medium-sized enterprise, or exceed the thresholds applicable to medium-sized enterprises under the relevant EU rules.
Accordingly, determining whether a company is subject to NIS2 requires more than simply examining its principal business description. Its actual activities, the services it provides, its corporate structure, number of employees, turnover and balance-sheet figures may all be relevant.
Furthermore, certain categories of entities may fall within the legislation regardless of their size, while the Digital Security Authority may identify additional entities as essential or important where the statutory criteria are satisfied.
Annex I – Sectors of High CriticalityAnnex I covers sectors regarded as particularly important for the functioning of society and the economy. These include:
Energy;
Transport;
Banking;
Financial market infrastructures;
Health;
Drinking water;
Waste water;
Digital infrastructure;
ICT service management (business-to-business);
Public administration; and
Space.
The category of digital infrastructure is particularly significant. Depending on their precise activities, the legislation may capture providers of cloud computing services, data centre services, content delivery networks, DNS services and certain electronic communications services.
Similarly, the inclusion of managed service providers and managed security service providers means that businesses providing outsourced IT or cybersecurity services should carefully examine whether their activities bring them within the scope of the Law.
Annex II – Other Critical SectorsThe scope of NIS2 extends beyond traditional critical infrastructure. Annex II includes:
Postal and courier services;
Waste management;
Manufacture, production and distribution of chemicals;
Production, processing and distribution of food;
Certain manufacturing activities;
Providers of online marketplaces;
Online search engines;
Social networking service platforms; and
Research organisations.
The manufacturing category includes, amongst others, certain manufacturers of medical devices, computer, electronic and optical products, electrical equipment, machinery, motor vehicles and other transport equipment.
This expanded sectoral coverage means that companies which would not traditionally regard themselves as operators of “critical infrastructure” may nevertheless now be subject to cybersecurity regulation.
Does company size matter?Yes, but size should not be considered in isolation.
The general starting point is the EU definition of a medium-sized enterprise. In broad terms, organisations employing 50 or more persons and meeting the applicable financial criteria may potentially fall within the scope of NIS2 where their activities are covered by Annex I or Annex II.
However, the analysis can become more complex in the context of corporate groups, partner enterprises and linked enterprises. Employee numbers and financial information may therefore need to be assessed beyond the individual Cyprus company.
Importantly, the Law also contains circumstances in which an entity can fall within its scope irrespective of its size. This may arise, for example, in relation to particular categories of digital infrastructure or where the entity is specifically identified because of the critical nature of its services, its systemic importance or the potential impact that disruption of its services could have.
Consequently, a company should not assume that it falls outside NIS2 merely because it has fewer than 50 employees.
Essential and Important EntitiesEntities within the scope of the legislation are classified as either “essential entities” or “important entities.”
As a general rule, larger organisations operating in the high-criticality sectors of Annex I will constitute essential entities. Certain entities, including specific providers of digital infrastructure and electronic communications services, may also be classified as essential under the particular criteria contained in the Law.
Other entities within Annex I or Annex II which fall within the scope of the legislation but do not qualify as essential entities will generally constitute important entities.
The distinction is significant because it affects, amongst other matters, the manner in which regulatory supervision and enforcement may be exercised.
In Cyprus, the Digital Security Authority (“DSA”) is the competent national authority responsible for cybersecurity supervision and enforcement.
The DSA is required to maintain a list of essential and important entities and to review and update that list regularly and at least every two years. Significantly, under the Cyprus legislation, the relevant list approved by the Council of Ministers is classified and is not published in the Official Gazette.
An organisation should therefore not conclude that NIS2 does not apply simply because its name does not appear on a publicly accessible list.
Indeed, the Cyprus legislation expressly provides that entities falling within its scope which have not been included in the list are required to inform the DSA for the purposes of their assessment.
What are the principal obligations?For organisations falling within NIS2, compliance involves considerably more than installing cybersecurity software.
The legislation requires essential and important entities to implement appropriate and proportionate technical, operational and organisational measures to manage risks posed to the security of their network and information systems.
These measures must address, amongst other matters:
Risk analysis and information-system security policies.
Organisations should establish an appropriate framework for identifying, assessing and managing cybersecurity risks.
Incident handling.
Businesses must have procedures allowing cybersecurity incidents to be identified, managed, contained and appropriately escalated.
Business continuity and crisis management.
This includes backup management, disaster recovery and procedures designed to maintain or restore operations following a serious cyber incident.
Supply-chain security.
NIS2 expressly extends cybersecurity considerations to relationships with suppliers and service providers. Organisations may therefore need to reassess contractual arrangements, cybersecurity requirements and due-diligence procedures applicable to critical suppliers.
Security in the acquisition, development and maintenance of network and information systems.
Cybersecurity should be integrated throughout the lifecycle of systems, including appropriate vulnerability handling and disclosure procedures.
Assessment of cybersecurity measures.
Policies alone are insufficient. Organisations should have procedures for evaluating whether their cybersecurity controls are operating effectively.
Cyber hygiene and cybersecurity training.
Personnel awareness and training form an express part of the compliance framework.
Cryptography and encryption.
Human resources security, access-control policies and asset management.
Multi-factor authentication and secure communications, where appropriate.
The precise measures required will depend upon the organisation's exposure to risk, its size, the nature of its activities and the potential consequences of a cybersecurity incident.
Management responsibility under NIS2One of the most important changes introduced by NIS2 is the emphasis placed on management accountability.
Cybersecurity compliance cannot simply be delegated to an IT department or an external cybersecurity provider.
Under the Cyprus legislation, the senior management of essential and important entities is required to approve the cybersecurity risk-management measures adopted by the organisation and supervise their implementation.
Management may also be held accountable in connection with an entity's failure to comply with its cybersecurity risk-management obligations.
This makes NIS2 relevant not only to CISOs and IT departments, but also to boards of directors, senior executives, compliance officers and legal departments.
Companies should therefore consider establishing a documented governance structure showing how cybersecurity risks are reported to management, how compliance measures are approved and how their implementation is monitored.
Cyber incident reportingNIS2 also introduces a structured reporting regime for significant cybersecurity incidents.
Entities must have internal mechanisms capable of rapidly determining whether an incident may trigger a regulatory notification obligation. The European NIS2 framework provides for an early warning within 24 hours of becoming aware of a significant incident, followed by an incident notification within 72 hours, with further reporting requirements potentially applying thereafter.
This makes preparation essential. A company discovering a serious ransomware attack, system compromise or other major cybersecurity incident cannot realistically begin designing its reporting and escalation process after the incident has occurred.
Incident-response policies should therefore clearly identify responsibility for:
determining whether an incident is potentially reportable;
escalating the incident internally;
involving senior management and legal advisers;
preserving relevant evidence;
communicating with the competent authorities; and
managing potential parallel obligations under other legislation, including the GDPR where personal data is affected.
The DSA has extensive supervisory and enforcement powers under the Cyprus legislation, including powers to request information and evidence of compliance.
Failure to comply can expose organisations to substantial administrative penalties.
For violations of the cybersecurity risk-management and incident-reporting obligations, the statutory maximum framework provides for fines for essential entities of at least €10 million or 2% of total worldwide annual turnover, whichever is higher.
For important entities, the corresponding maximum is at least €7 million or 1.4% of total worldwide annual turnover, whichever is higher.
The financial consequences are therefore potentially substantial. However, regulatory exposure should not be viewed solely in terms of administrative fines. A serious cyber incident can also result in contractual claims, data-protection exposure, business interruption, reputational damage and disputes with customers, suppliers and insurers.
What should Cyprus companies do now?The first step should be a properly documented NIS2 applicability assessment.
This assessment should examine, amongst other matters:
the precise activities and services carried out by the company;
whether those activities fall within Annex I or Annex II;
the company's number of employees;
annual turnover and balance-sheet total;
whether the company forms part of a wider group or has linked or partner enterprises;
whether any of the exceptions bringing smaller entities within the legislation apply;
whether the company is likely to constitute an essential or important entity; and
whether notification or engagement with the Digital Security Authority is required.
Where the company falls within scope, a legal and technical gap assessment should then identify the measures already in place and the additional steps required to achieve compliance.
Particular attention should be given to governance, cybersecurity policies, incident-response procedures, supplier agreements, outsourcing arrangements, business-continuity plans, access controls, staff training and the documentation required to demonstrate compliance.
How Michael Vorkas & Partners LLC can assistNIS2 compliance sits at the intersection of cybersecurity, corporate governance, regulatory compliance, contractual risk and data protection.
Michael Vorkas & Partners LLC can assist Cyprus and international businesses in assessing the application of the Cyprus NIS2 framework to their operations and in developing an appropriate legal compliance structure.
Our assistance may include:
NIS2 applicability and classification assessments;
assessment of Essential or Important Entity status;
advice regarding notifications and interaction with the Digital Security Authority;
legal NIS2 gap assessments;
review and preparation of cybersecurity governance policies;
review of directors' and senior management responsibilities;
preparation and review of incident-response procedures;
review of supplier, outsourcing and IT service agreements;
cybersecurity and supply-chain contractual provisions;
coordination of NIS2 requirements with GDPR and other regulatory obligations; and
legal assistance following cybersecurity incidents and regulatory investigations.
Given the breadth of the new regime, businesses operating in potentially affected sectors should assess their position proactively rather than waiting for a cybersecurity incident or regulatory communication.
Michael Vorkas & Partners LLC
Cyprus Lawyers | Department of Corporate, Regulatory & Technology Law
This publication is provided for general information purposes only and does not constitute legal advice. Whether a particular organisation falls within the scope of the NIS2 framework requires an assessment of its specific activities, corporate structure, size and other relevant circumstances.