Security of Networks and Information Systems Law, Incident Notification Obligations
Art. 35B of the Security of Networks and Information Systems Law of 2020 N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 25 April 2025.
A vulnerability and incident reporting rule binding public and private bodies.
As of 16 September 2026.
What it requires
- This binds an essential or important entity established in Cyprus under Article 2A, sized at or above the medium-enterprise threshold of Commission Recommendation 2003/361/EC, or regardless of size for a category the Law names outright (a public electronic communications provider, a trust service provider, a top-level domain (TLD) registry), across the sectors listed in Annexes I and II, which name an online marketplace, an online search engine and a cloud computing service among the digital providers they reach; the wider sector classes those Annexes also reach (energy, transport, banking, health, water, digital infrastructure and public administration) are a sector and size designation no activity in this vocabulary expresses, so they are not separately flagged here. The obligation runs to this jurisdiction's own row, which is a companion of this jurisdiction's risk-management and governance row.
- Notify the Digital Security Authority without undue delay, and in any event within six (6) hours of becoming aware of a significant incident, with an early warning stating, where applicable, whether the incident is suspected to result from unlawful or malicious acts and whether it may have a cross-border impact.
- Follow with an incident notification within 72 hours of becoming aware, updating the early warning and giving an initial assessment of the incident's severity and impact, including any indicators of compromise where available.
- Submit an intermediate report on the Authority's request, and a final report within one month of the incident notification (or, for an incident still ongoing at that point, a progress report every fifteen days, and a final report within fifteen days of restoring the affected network or information system's normal operation).
- Where you are a trust service provider, notify within 24 hours rather than 72 for a significant incident affecting the trust services you supply.
- Where applicable, notify without undue delay the recipients of your services who may be affected by a significant cyber threat, of any measures or corrective action they can take, and notify them of a significant incident likely to adversely affect their use of the service.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 54's corporate- and natural-person liability regime names only Articles 22 and 43 as offences it reaches; it does not name Article 35B or 43A, so a breach of this notification duty carries the Article 43A administrative fine and nothing else.
Penalty structure
The same Article 43A(4) and (5) tiers that govern an Article 35 infringement govern an Article 35B infringement: at least EUR 10,000,000 or 2 percent of worldwide turnover for an essential entity, and at least EUR 7,000,000 or 1.4 percent for an important entity, whichever is higher in each case.
- Rule
- Higher of
- As of
- 16 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The Digital Security Authority (Αρχή Ψηφιακής Ασφάλειας), Cyprus's national competent NIS authority, acting through the national CSIRT, which the Authority forwards each notification to on receipt.
Settledness
- As of
- 16 September 2026
- Guidance link
- https://dsa.cy/en/legislation/laws
- Guidance body
- Digital Security Authority (DSA)
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 35B requires an essential or important entity to notify the Digital Security Authority, without undue delay, of any incident that has a significant impact on the provision of its services, on a graduated clock: an early warning within six hours of becoming aware of the significant incident (stricter than NIS2 Article 23(4)(a)'s 24-hour floor), a fuller incident notification within 72 hours, an intermediate report on the Authority's request, and a final report within one month of the incident notification (or, for an incident still ongoing at that point, a progress report every 15 days and a final report within 15 days of restoring the affected network or system).
A trust-service provider notifies within 24 hours rather than 72 for an incident affecting its trust services. The Authority responds to the early warning within 24 hours with initial feedback and, on request, guidance, and forwards the notification to the national CSIRT.
When LexLint raises it
operates_social_platform