NIS2 in Cyprus — a 6-hour early-warning clock, and a regulator that comes to you.
Cyprus transposed NIS2 by amending its 2020 networks and information systems law — Law 60(I)/2025, enacted on 25 April 2025 and now in force. The Digital Security Authority (DSA) is the competent authority and single point of contact, and runs the national incident-response team (CSIRT-CY); its powers are exercised in practice by the Commissioner for Communications. Unusually, there is no self-registration: the DSA identifies covered entities through its own national assessment and maintains the list, reviewing it at least every two years.
Cyprus sets the strictest incident clock of any member state: an early warning within 6 hours of becoming aware of a significant incident — against the directive's 24 — full notification within 72 hours, and progress reports every 15 days while an incident continues. Penalties reach the directive ceilings, add daily fines of up to EUR 10,000 for repeated infringements, and carry criminal liability of up to three years' imprisonment for failures to implement security measures. Directors face personal liability and, in serious cases, temporary bans from managerial functions.
Who it applies to
Essential and important entities across 18 designated sectors — generally medium-sized and larger (50+ employees or EUR 10 million turnover), with sector exceptions. No self-registration: the DSA compiles the entity list itself and offers a self-assessment tool on dsa.cy; in-scope entities must comply whether or not the DSA has contacted them. For banks and other financial entities, DORA takes precedence on overlapping obligations, with the DSA keeping residual NIS2 areas such as supply-chain security.
The clock
Competent authority: Digital Security Authority (DSA). Transposition: Security of Networks and Information Systems (Amendment) Law 60(I)/2025.
| When | What happens |
|---|---|
| 25 Apr 2025 | Law 60(I)/2025 enacted and in force |
| Ongoing | DSA national assessment compiles the entity list — reviewed at least every two years |
| Per incident | 6 h early warning · 72 h notification · progress reports every 15 days |
The regulator finds you; the clock is six hours
Two Cypriot choices change how compliance work starts. First, there is no registration portal to find: the DSA identifies essential and important entities through its own assessment and maintains the list — which means an entity can be in scope, and obliged, without ever having touched a government system. Second, the reporting clock is the fastest in the Union: six hours to the early warning, not twenty-four, with progress reports every fifteen days for as long as the incident runs. A six-hour clock cannot be met by a process that starts with finding the regulator's email address — it has to be built before anything happens. TruSecure's incident workflow is clocked from the moment of awareness with the Cypriot stages pre-set, and the entity's scope status is held as a dated record rather than assumed from silence.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Cyprus transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Know your status — the DSA lists you; there is no self-registration | Scope determination · recorded against the DSA self-assessment criteria |
| Early warning to CSIRT-CY within 6 hours | Incident workflow · clocked from awareness, Cypriot stages pre-built |
| Notification in 72 h, progress reports every 15 days | Report templates · staged, dated, exportable |
| Implement the risk-management measures | Control library · mapped, owned, evidenced |
| Show management oversight — directors are personally liable | Governance workspace · approvals and training records, dated |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Scope status
- in scope · DSA self-assessment criteria met, recorded
- Incident clock
- 6 h early warning · rehearsed twice, last run 41 min
- Controls evidenced
- 77/96 · supply-chain measures complete
- DORA overlap
- checked · not a financial entity, full NIS2 applies
- Export
- sealed · sha256:88b2...e510
Compliance roadmap
Typical timeline: 3–6 months to full compliance readiness
- 1Weeks 1–4
1.Assessment
Gap analysis against NIS2, risk review, remediation plan.
- 2Weeks 5–12
2.Implementation
Controls deployed, policies written, evidence flowing.
- 3Weeks 13–16
3.Audit prep
Gaps closed, evidence package assembled for the authority.
- 4Weeks 17–24
4.Steady state
Continuous evidence, reports on demand, drift alerts.
With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.
Where teams usually start
With a demo walked through by TruSecure — your scope position recorded, the six-hour clock rehearsed, and the measures mapped against what you already operate. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Cyprus by Digital Security Authority (DSA). TruSecure determines applicability against Cyprus's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.