Law / Cyprus

Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and Governance

Arts. 35 and 35A of the Security of Networks and Information Systems Law of 2020 N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 25 April 2025.

A sector security regimes rule binding public and private bodies.

As of 16 September 2026.

What it requires

  • This binds an essential or important entity established in Cyprus under Article 2A, sized at or above the medium-enterprise threshold of Commission Recommendation 2003/361/EC, or regardless of size for a category the Law names outright (a public electronic communications provider, a trust service provider, a top-level domain (TLD) registry), across the sectors listed in Annexes I and II, which name an online marketplace, an online search engine and a cloud computing service among the digital providers they reach; the wider sector classes those Annexes also reach (energy, transport, banking, health, water, digital infrastructure and public administration) are a sector and size designation no activity in this vocabulary expresses, so they are not separately flagged here.
  • Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems you use for your activities or to provide your services, proportionate to the risk, and to prevent or minimise the impact of an incident on the recipients of your services or on other services.
  • Cover at least: risk-analysis and information-system security policies; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the security of your relationships with your direct suppliers and service providers; secure acquisition, development and maintenance of systems, including vulnerability handling and disclosure; policies to assess the effectiveness of these measures; basic cyber hygiene practices and cybersecurity training; cryptography and, where appropriate, encryption policies; human-resources security, access-control policies and asset management; and, where appropriate, multi-factor or continuous authentication, and secure voice, video, text and emergency communications.
  • Have your senior management approve these risk-management measures and oversee their implementation; senior management can be held accountable for the entity's breach of this duty, and must undergo, and offer staff, regular training so they can identify risks and assess cybersecurity risk-management practices.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 54's corporate- and natural-person liability regime for an offence under this Law names only Articles 22 (non-compliance with the Authority's decision-issuance hearing procedure) and 43 (the Law's general administrative fine); it does not name Article 35, 35A or 43A, so a breach of the risk-management or governance duty carries the Article 43A administrative fine and nothing else.

Penalty structure

Article 43A(4): an essential entity's breach of Article 35 or 35B draws an administrative fine of a maximum of at least EUR 10,000,000 or 2 percent of the undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher. Article 43A(5) sets an important entity's maximum at at least EUR 7,000,000 or 1.4 percent, whichever is higher, mirroring NIS2 Article 34(4) and (5). Article 43 sets a separate, lower general fine (up to EUR 200,000, plus EUR 10,000 per day of continuing violation) for a breach of the Law that Article 43A does not itself cover.

Rule
Higher of
As of
16 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The Digital Security Authority (Αρχή Ψηφιακής Ασφάλειας), Cyprus's national competent NIS authority (formerly the Office of the Commissioner of Electronic Communications and Postal Regulation), acting through the national CSIRT.

Settledness

As of
16 September 2026
Guidance link
https://dsa.cy/en/legislation/laws
Guidance body
Digital Security Authority (DSA)

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 35 requires an essential or important entity to take appropriate and proportionate technical, operational and organisational measures, proportionate to the risk, to manage the risks to the security of the network and information systems it uses for its activities or to provide its services, covering at least risk-analysis and security policy, incident handling, business continuity and disaster recovery, supply-chain security, secure system acquisition and development including vulnerability handling and disclosure, effectiveness-assessment policies, cyber hygiene and training, cryptography and encryption, human-resources security and access control, and multi-factor authentication, transposing NIS2 Article 21.

Article 35A requires the entity's senior management to approve these measures, oversee their implementation, and undergo (and offer staff) regular cybersecurity training, and it can be held accountable for the entity's breach of the Article 35 duty.

When LexLint raises it

  • operates_social_platform

Read the law

Security of Networks and Information Systems Law of 2020 (89(I)/2020), consolidated with Law 60(I)/2025, CyLaw

Back to the example  ·  Lint your app