Cyprus transposed the NIS2 Directive (Directive (EU) 2022/2555) through the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025 (Official Gazette, Annex I(I), No. 5036, 25 April 2025), which amended the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020 (Cyprus's original NIS1 transposition), and entered into force on 25 April 2025, after Cyprus missed the Directive's own 17 October 2024 transposition deadline.
The consolidated Law binds an essential or important entity established in Cyprus (public or private, sized at the medium-enterprise threshold of Commission Recommendation 2003/361/EC or above, or regardless of size for certain named categories) across the sectors of Annexes I and II, including the digital providers those Annexes name (an online marketplace, an online search engine, a cloud computing service), to risk-management measures under Article 35, a management-body governance and accountability duty under Article 35A, and a graduated incident-notification duty under Article 35B, all owed to the Digital Security Authority (Αρχή Ψηφιακής Ασφάλειας), formerly the Office of the Commissioner of Electronic Communications and Postal Regulation, acting through the national CSIRT.
Cyprus's incident-notification clock departs from the Directive's own floor in one respect worth flagging: Article 35B(4)(a) sets the early-warning deadline at six hours from becoming aware of a significant incident, stricter than NIS2 Article 23(4)(a)'s 24-hour baseline, while the 72-hour incident notification, the one-month final report, and (for a trust service provider, which reports within 24 hours instead of 72) the derogation from that 72-hour clock all track the Directive.
Article 43A's penalty tiers for a violation of Articles 35 or 35B match the Directive's own ceiling: at least EUR 10,000,000 or 2 percent of worldwide annual turnover for an essential entity and at least EUR 7,000,000 or 1.4 percent for an important entity, whichever is higher in each case, both administrative.
Article 54's natural- and legal-person liability regime names only Articles 22 (non-compliance with the Authority's decision-issuance hearing procedure) and 43 (the Law's general, non-NIS2 administrative fine, up to EUR 200,000 plus EUR 10,000 per day of continuing violation) as offences it reaches, and pointedly not 35, 35A, 35B or 43A. The same 2025 amendment also partially transposes the Radio Equipment Directive (Directive 2014/53/EU): Article 42A requires radio equipment of categories or classes the Authority designates by Decision to be constructed so that it does not degrade the network, safeguards users' and subscribers' personal data and privacy, protects against fraud, and verifies the compatibility of any software before that software can be installed on the equipment, enforced by the Authority with a market-surveillance seizure power and, through Article 54's reach into Article 43, a criminal-liability channel the Article 35 and 35B duties do not carry.
No Cypriot instrument reviewed here imposes a general product-security or market-placement duty on a software manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.
Cyprus has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, and personal-data breach notification under GDPR Articles 33 and 34 to the Commissioner for Personal Data Protection sits in this jurisdiction's privacy row rather than here.