Law / Cyprus

Security of Networks and Information Systems Law, Radio Equipment Cybersecurity Requirements

Art. 42A of the Security of Networks and Information Systems Law of 2020 N. 89(I)/2020, as inserted by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 25 April 2025.

A product security requirements rule binding private bodies.

As of 16 September 2026.

What it requires

  • This binds a manufacturer, importer or distributor placing on the Cypriot market radio equipment of a category or class the Authority has designated by Decision under Article 42A(2); which categories are in scope, and the conformity-assessment and notified-body approval procedure that applies to them, is fixed in that Decision and is not described here.
  • Construct the equipment so that it does not harm the network, and its operation does not misuse network resources so as to cause an unacceptable degradation of service.
  • Incorporate safeguards to protect the personal data and privacy of the equipment's users and subscriber, and support features protecting against fraud.
  • Support features ensuring that software can be installed on the radio equipment only once the compatibility of the combination of the radio equipment and the software has been demonstrated.
  • Expect the Authority to evaluate equipment presenting a risk to health, personal safety, or the security of networks and information systems, and to order compliance measures or the elimination of the risk, backed by a market-surveillance seizure power.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

A breach of Article 42A is punished as a general Article 43 infringement (Article 43A's NIS2-specific fine tiers are scoped only to Articles 35 and 35B). Article 54 treats an Article 43 infringement as an 'offence' for corporate-liability purposes and provides that a legal person's liability for it 'does not exclude the institution of criminal proceedings' against the natural persons who commit or participate in it, so an Article 42A breach carries a criminal-liability channel through Article 43 and 54 that the Article 35 and 35B duties do not. The Law does not itself state a term of imprisonment for an Article 43 offence the way Article 22 does; what Article 54 establishes is that the offence can be prosecuted, not a stated penalty range for doing so.

Penalty structure

Article 43(1): subject to Article 43A, where the Authority establishes an act or omission contrary to this Law, it may impose an administrative fine of up to EUR 200,000, depending on the seriousness of the infringement, and, on repetition, a further fine of up to EUR 10,000 for each day the infringement continues. This is the general fine that reaches an Article 42A radio-equipment breach, distinct from Article 43A's EUR 10,000,000/2 percent and EUR 7,000,000/1.4 percent tiers, which are scoped only to Articles 35 and 35B.

Rule
Fixed only
As of
16 September 2026
Currency
EUR
Fixed cap
200,000

Who enforces it

Enforcement body

The Digital Security Authority (Αρχή Ψηφιακής Ασφάλειας), with market-surveillance and seizure powers over non-conforming radio equipment.

Settledness

As of
16 September 2026
Guidance link
https://dsa.cy/en/legislation/laws
Guidance body
Digital Security Authority (DSA)
Open questions
Has the Authority yet issued the Decision under Article 42A(2) designating the categories or classes of radio equipment in scope and fixing the conformity-assessment and market-surveillance procedure?

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 42A, inserted to partially harmonize with the Radio Equipment Directive (Directive 2014/53/EU), requires the Digital Security Authority to ensure that radio equipment of categories or classes it designates by Decision is constructed to meet essential requirements set by the European Commission.

In particular, the equipment must not harm the network or degrade service by misusing network resources, must incorporate safeguards protecting users' and subscribers' personal data and privacy, must support features protecting against fraud, and must support features ensuring that software can be installed on the equipment only once the compatibility of that hardware-software combination has been demonstrated.

The Authority sets the specific conformity-assessment procedure, notified-body approval criteria, and market-surveillance process, including a seizure power, by its own Decision, and orders compliance measures or the elimination of risk where equipment endangers health, personal safety, or network and information-system security.

When LexLint raises it

  • distributes_software_product

Read the law

Security of Networks and Information Systems Law of 2020 (89(I)/2020), consolidated with Law 60(I)/2025, CyLaw

Back to the example  ·  Lint your app