Skip to main content
NIS2 · CYPRUS

NIS2 in Cyprus — a 6-hour early-warning clock, and a regulator that comes to you.

Cyprus transposed NIS2 by amending its 2020 networks and information systems law — Law 60(I)/2025, enacted on 25 April 2025 and now in force. The Digital Security Authority (DSA) is the competent authority and single point of contact, and runs the national incident-response team (CSIRT-CY); its powers are exercised in practice by the Commissioner for Communications. Unusually, there is no self-registration: the DSA identifies covered entities through its own national assessment and maintains the list, reviewing it at least every two years.

Cyprus sets the strictest incident clock of any member state: an early warning within 6 hours of becoming aware of a significant incident — against the directive's 24 — full notification within 72 hours, and progress reports every 15 days while an incident continues. Penalties reach the directive ceilings, add daily fines of up to EUR 10,000 for repeated infringements, and carry criminal liability of up to three years' imprisonment for failures to implement security measures. Directors face personal liability and, in serious cases, temporary bans from managerial functions.

Who it applies to

Essential and important entities across 18 designated sectors — generally medium-sized and larger (50+ employees or EUR 10 million turnover), with sector exceptions. No self-registration: the DSA compiles the entity list itself and offers a self-assessment tool on dsa.cy; in-scope entities must comply whether or not the DSA has contacted them. For banks and other financial entities, DORA takes precedence on overlapping obligations, with the DSA keeping residual NIS2 areas such as supply-chain security.

The clock

Competent authority: Digital Security Authority (DSA). Transposition: Security of Networks and Information Systems (Amendment) Law 60(I)/2025.

NIS2 in Cyprus · timeline
WhenWhat happens
25 Apr 2025Law 60(I)/2025 enacted and in force
OngoingDSA national assessment compiles the entity list — reviewed at least every two years
Per incident6 h early warning · 72 h notification · progress reports every 15 days

The regulator finds you; the clock is six hours

Two Cypriot choices change how compliance work starts. First, there is no registration portal to find: the DSA identifies essential and important entities through its own assessment and maintains the list — which means an entity can be in scope, and obliged, without ever having touched a government system. Second, the reporting clock is the fastest in the Union: six hours to the early warning, not twenty-four, with progress reports every fifteen days for as long as the incident runs. A six-hour clock cannot be met by a process that starts with finding the regulator's email address — it has to be built before anything happens. TruSecure's incident workflow is clocked from the moment of awareness with the Cypriot stages pre-set, and the entity's scope status is held as a dated record rather than assumed from silence.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Cyprus transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Cyprus requirements · how TruSecure answers them
What the law asksWhere it is answered
Know your status — the DSA lists you; there is no self-registrationScope determination · recorded against the DSA self-assessment criteria
Early warning to CSIRT-CY within 6 hoursIncident workflow · clocked from awareness, Cypriot stages pre-built
Notification in 72 h, progress reports every 15 daysReport templates · staged, dated, exportable
Implement the risk-management measuresControl library · mapped, owned, evidenced
Show management oversight — directors are personally liableGovernance workspace · approvals and training records, dated

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Cyprus NIS2 readiness file · excerptSample data
Scope status
in scope · DSA self-assessment criteria met, recorded
Incident clock
6 h early warning · rehearsed twice, last run 41 min
Controls evidenced
77/96 · supply-chain measures complete
DORA overlap
checked · not a financial entity, full NIS2 applies
Export
sealed · sha256:88b2...e510

Compliance roadmap

Typical timeline: 3–6 months to full compliance readiness

  1. 1Weeks 1–4

    Assessment

    Gap analysis against NIS2, risk review, remediation plan.

  2. 2Weeks 5–12

    Implementation

    Controls deployed, policies written, evidence flowing.

  3. 3Weeks 13–16

    Audit prep

    Gaps closed, evidence package assembled for the authority.

  4. 4Weeks 17–24

    Steady state

    Continuous evidence, reports on demand, drift alerts.

With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.

Where teams usually start

With a demo walked through by TruSecure — your scope position recorded, the six-hour clock rehearsed, and the measures mapped against what you already operate. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Cyprus by Digital Security Authority (DSA). TruSecure determines applicability against Cyprus's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Do I need to register with the Cypriot authority myself?
No — Cyprus has no self-registration system. The Digital Security Authority compiles the list of essential and important entities through its own national assessment, reviewed at least every two years. Its self-assessment tool on dsa.cy tells you whether to expect to be on it.