If you run a business in Cyprus, there’s a good chance the NIS2 Directive already applies to you — and the deadline has passed.

NIS2 is the EU’s new cybersecurity law. It came into force in October 2024 and it’s stricter, broader and more serious than anything that came before it. Fines can reach €10 million or 2% of global turnover.

The good news? Getting compliant doesn’t have to be complicated. This guide explains everything in plain English.

NIS2 (Network and Information Security Directive 2) is an EU law that forces businesses to take cybersecurity seriously. It replaces the original NIS Directive from 2016 and covers far more businesses this time.

The goal is simple: make sure that critical services across Europe can’t be taken down by cyberattacks.

You’re likely covered if your business:

✅ Has more than 50 employees or annual turnover above €10 million

✅ Operates in one of these sectors:

Even if you’re smaller, your clients may require you to comply as part of their supply chain.

Here’s what you need to have in place:

1. Risk Management Policy A written plan that identifies your IT risks and how you manage them.

2. Incident Reporting If you suffer a cyberattack or data breach, you must report it to authorities within 24 hours of discovery.

3. Business Continuity Plan A clear process for keeping your business running during and after a cyber incident.

4. Supply Chain Security You must assess the cybersecurity practices of your suppliers and partners.

5. Access Controls & Encryption Multi-factor authentication (MFA), encrypted data storage and strict access policies.

6. Regular Security Testing Vulnerability scans and penetration testing at least once a year.

Non-compliance with NIS2 can result in significant fines. For essential entities, fines can reach up to €10 million or 2% of global annual turnover — whichever is higher. For important entities, fines can reach €7 million or 1.4% of global annual turnover

Most SMBs in Cyprus don’t have a full-time IT security team. That’s where we come in.

We help you:

One dedicated engineer. No call centres. No jargon.

My business is small, do I really need to worry about NIS2?

If you’re under 50 employees and under €10M turnover, you may be exempt. But if you supply services to larger companies or government, they may require you to comply. It’s worth checking.

Is Cyprus enforcing NIS2?

Yes. Cyprus transposed NIS2 into national law. The Digital Security Authority (DSA) is the supervisory body.

How long does it take to become compliant?

For most SMBs, 4–8 weeks with the right support. We handle the technical side — you focus on your business.

What’s the first step?

A cybersecurity assessment. We review your current setup and tell you exactly what needs to change.

Scroll to Top