Cybersecurity · Compliance

NIS2 Compliance in Cyprus: What Every Business Must Do in 2025

If you run a business in Cyprus and haven't heard of NIS2, now is the time to pay attention. The Network and Information Security Directive 2 (NIS2) — the EU's updated cybersecurity framework — came into force across member states in October 2024, and Cyprus has fully transposed it into national law.

The consequences of non-compliance are serious: fines of up to €10 million or 2% of global annual turnover for essential entities, and €7 million or 1.4% of turnover for important entities. More critically, NIS2 places personal liability on senior management — meaning company directors and executives can be held directly responsible.

💡 Key fact: Unlike its predecessor NIS1, the new directive applies to a far broader range of sectors and company sizes. Many Cyprus SMBs that were previously exempt now fall within scope.

What is NIS2 and Why Does It Matter for Cyprus Businesses?

NIS2 is the European Union's primary legislative framework for cybersecurity, replacing the original NIS Directive of 2016. The update was driven by a recognition that cyber threats had evolved dramatically — ransomware attacks, supply chain compromises and critical infrastructure targeting had become far more common and sophisticated.

Cyprus, as an EU member state, was required to transpose NIS2 into national law by October 17, 2024. The Cyprus competent authority responsible for NIS2 enforcement is the Digital Security Authority (DSA), which operates under the Deputy Ministry of Research, Innovation and Digital Policy.

What makes NIS2 different from previous regulation is its scope, its enforcement teeth, and its explicit focus on supply chain security — meaning that even if your business is not directly in scope, your clients who are in scope will likely require you to demonstrate cybersecurity compliance as a supplier or service provider.

Which Sectors and Businesses Are Affected?

NIS2 divides affected organisations into two categories:

CategorySectors IncludedMinimum Size
Essential EntitiesEnergy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, public administration250+ employees or €50M+ turnover
Important EntitiesPostal services, waste management, chemicals, food production, manufacturing, digital providers, research50+ employees or €10M+ turnover

However, regardless of size, certain entities are automatically included — including providers of public electronic communications networks, trust service providers, and entities deemed critical by member states.

⚠️ Important for Cyprus: Even if your company falls below the thresholds above, if you supply services or software to an entity that is in scope, they will likely require you to meet NIS2 standards as part of their supply chain security obligations.

What Does NIS2 Actually Require?

Article 21 of NIS2 sets out the specific cybersecurity risk-management measures that affected entities must implement. These are not optional guidelines — they are legal requirements:

1. Risk Analysis and Information System Security Policies

You must have a documented, up-to-date risk assessment and a formal information security policy. This means identifying your critical assets, assessing threats, and documenting how you protect against them. Ad-hoc or undocumented security is no longer acceptable.

2. Incident Handling

NIS2 requires a formal incident response procedure. Critically, significant incidents must be reported to the DSA within 24 hours of discovery (initial warning), with a full report within 72 hours, and a final report within one month. Failure to report is itself a violation.

3. Business Continuity and Backup

Entities must have documented business continuity plans covering backup management, disaster recovery, and crisis management. This includes regular testing of backups and documented recovery time objectives (RTOs).

4. Supply Chain Security

One of NIS2's most impactful requirements. You must assess and address cybersecurity risks in your supply chain — including your IT service providers, software vendors, and cloud providers. This is why managed IT providers like BitNova now play a compliance-critical role for many businesses.

5. Network and Information System Security

Implementing security in network acquisition, development and maintenance — including vulnerability handling and disclosure policies. This covers patch management, secure configuration, and network monitoring.

6. Cybersecurity Training

NIS2 explicitly requires organisations to provide cybersecurity training to all staff, with particular focus on management and senior leadership. Phishing awareness, secure password practices and incident recognition are baseline expectations.

7. Cryptography and Encryption

Policies on the use of cryptography and encryption for data at rest and in transit. This includes encrypted email for sensitive communications, encrypted storage, and encrypted remote access.

8. Access Control and Authentication

Multi-factor authentication (MFA) is effectively mandated for any access to critical systems. This applies to email, remote access, cloud services and internal systems alike.

9. Human Resources Security

Background checks for personnel with access to critical systems, clear off-boarding procedures, and defined access rights management policies.

Penalties for Non-Compliance

NIS2 penalties are significantly higher than NIS1, and the enforcement regime is more active:

Entity TypeMaximum FineManagement Liability
Essential Entities€10 million or 2% of global turnover (whichever is higher)Yes — personal liability of executives
Important Entities€7 million or 1.4% of global turnover (whichever is higher)Yes — personal liability of executives

Beyond financial penalties, the DSA has the power to issue public statements identifying non-compliant entities, temporarily prohibit individuals from management roles, and order immediate remediation actions.

A Practical NIS2 Compliance Checklist for Cyprus Businesses

  1. Determine if you are in scope — check your sector and size against the thresholds above
  2. Register with the DSA — in-scope entities must register with Cyprus's Digital Security Authority
  3. Conduct a risk assessment — identify and document your critical systems and threats
  4. Implement MFA — on all email, remote access and cloud systems immediately
  5. Set up automated, tested backups — minimum daily, with off-site or cloud copies
  6. Document an incident response plan — with a 24/72-hour reporting process in place
  7. Review your suppliers — ask your IT provider for evidence of their own security measures
  8. Train your staff — at minimum, a phishing awareness session for all employees
  9. Encrypt sensitive data — at rest and in transit, especially client data
  10. Appoint a responsible person — someone accountable for cybersecurity within your organisation

How BitNova IT Can Help You Achieve NIS2 Compliance

NIS2 compliance is not a one-off project — it is an ongoing programme of security management. For most SMBs in Cyprus, partnering with a managed IT provider is the most cost-effective and practical path to compliance.

At BitNova IT Tech Solutions, we provide a complete NIS2 readiness assessment, gap analysis, and implementation of all required technical controls — from MFA and encrypted backup to network monitoring and incident response planning. Our Cybersecurity Solutions and Managed IT Support packages are designed to cover the full NIS2 technical requirements for SMBs in Cyprus.

We also offer specialised compliance packages for law firms (LegalGuard) and accounting practices, where regulatory obligations under NIS2 and GDPR overlap significantly.

Is your business NIS2 compliant?

Book a free 30-minute assessment. We will review your current security posture and give you a written gap analysis — no cost, no commitment.

Book Free NIS2 Assessment →

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top