Law / Cyprus

Security of Networks and Information Systems Law, Incident Notification Obligations

Art. 35B of the Security of Networks and Information Systems Law of 2020 N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 25 April 2025.

A vulnerability and incident reporting rule binding public and private bodies.

As of 16 September 2026.

What it requires

  • This binds an essential or important entity established in Cyprus under Article 2A, sized at or above the medium-enterprise threshold of Commission Recommendation 2003/361/EC, or regardless of size for a category the Law names outright (a public electronic communications provider, a trust service provider, a top-level domain (TLD) registry), across the sectors listed in Annexes I and II, which name an online marketplace, an online search engine and a cloud computing service among the digital providers they reach; the wider sector classes those Annexes also reach (energy, transport, banking, health, water, digital infrastructure and public administration) are a sector and size designation no activity in this vocabulary expresses, so they are not separately flagged here. The obligation runs to this jurisdiction's own row, which is a companion of this jurisdiction's risk-management and governance row.
  • Notify the Digital Security Authority without undue delay, and in any event within six (6) hours of becoming aware of a significant incident, with an early warning stating, where applicable, whether the incident is suspected to result from unlawful or malicious acts and whether it may have a cross-border impact.
  • Follow with an incident notification within 72 hours of becoming aware, updating the early warning and giving an initial assessment of the incident's severity and impact, including any indicators of compromise where available.
  • Submit an intermediate report on the Authority's request, and a final report within one month of the incident notification (or, for an incident still ongoing at that point, a progress report every fifteen days, and a final report within fifteen days of restoring the affected network or information system's normal operation).
  • Where you are a trust service provider, notify within 24 hours rather than 72 for a significant incident affecting the trust services you supply.
  • Where applicable, notify without undue delay the recipients of your services who may be affected by a significant cyber threat, of any measures or corrective action they can take, and notify them of a significant incident likely to adversely affect their use of the service.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 54's corporate- and natural-person liability regime names only Articles 22 and 43 as offences it reaches; it does not name Article 35B or 43A, so a breach of this notification duty carries the Article 43A administrative fine and nothing else.

Penalty structure

The same Article 43A(4) and (5) tiers that govern an Article 35 infringement govern an Article 35B infringement: at least EUR 10,000,000 or 2 percent of worldwide turnover for an essential entity, and at least EUR 7,000,000 or 1.4 percent for an important entity, whichever is higher in each case.

Rule
Higher of
As of
16 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The Digital Security Authority (Αρχή Ψηφιακής Ασφάλειας), Cyprus's national competent NIS authority, acting through the national CSIRT, which the Authority forwards each notification to on receipt.

Settledness

As of
16 September 2026
Guidance link
https://dsa.cy/en/legislation/laws
Guidance body
Digital Security Authority (DSA)

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 35B requires an essential or important entity to notify the Digital Security Authority, without undue delay, of any incident that has a significant impact on the provision of its services, on a graduated clock: an early warning within six hours of becoming aware of the significant incident (stricter than NIS2 Article 23(4)(a)'s 24-hour floor), a fuller incident notification within 72 hours, an intermediate report on the Authority's request, and a final report within one month of the incident notification (or, for an incident still ongoing at that point, a progress report every 15 days and a final report within 15 days of restoring the affected network or system).

A trust-service provider notifies within 24 hours rather than 72 for an incident affecting its trust services. The Authority responds to the early warning within 24 hours with initial feedback and, on request, guidance, and forwards the notification to the national CSIRT.

When LexLint raises it

  • operates_social_platform

Read the law

Security of Networks and Information Systems Law of 2020 (89(I)/2020), consolidated with Law 60(I)/2025, CyLaw

Back to the example  ·  Lint your app