NIS2 in Cyprus — the DSA, subsidiaries in scope, and assessment by entity facts.
Cyprus transposed NIS2 through its National Cybersecurity Law, establishing the Digital Security Authority (DSA) as the competent authority and CSIRT-CY as the national CSIRT. What makes Cyprus distinctive is the market structure: most entities that meet NIS2 size and sector thresholds in Cyprus are subsidiaries or branches of larger regional or global organizations rather than standalone domestic companies. The question of whether NIS2 applies turns on the Cyprus entity's own facts — its size, its sector, its operations — not on where its parent company is located.
The transposition follows the standard EU structure, but the DSA's approach to subsidiaries emphasizes that the Cyprus entity itself must meet the thresholds and must comply in its own right. A subsidiary of a non-EU parent company is subject to NIS2 if the Cyprus operation meets the criteria; a subsidiary of an EU parent company is subject to NIS2 on the same basis. The parent's location does not shield the Cyprus entity, nor does it automatically include it.
Who it applies to
Essential and important entities in Cyprus that meet the size and sector thresholds, regardless of whether they are standalone domestic companies or subsidiaries of foreign parents. Most in-scope entities in Cyprus are subsidiaries of larger regional groups, and the DSA assesses each Cyprus entity on its own facts.
The clock
Competent authority: Digital Security Authority (DSA). Transposition: National Cybersecurity Law (NIS2 transposition).
| When | What happens |
|---|---|
| National Cybersecurity Law | Transposition enters into force · DSA established |
| On classification | Registration with DSA · risk-assessment filing |
| Ongoing | Incident reporting to CSIRT-CY · annual compliance updates |
Subsidiaries assessed on entity facts
Cyprus's small market means most in-scope entities are subsidiaries of larger regional or global organizations, and the distinctive question is how NIS2 applies to these structures. The DSA's position is clear: the Cyprus entity is assessed on its own facts. A subsidiary of a non-EU parent company is subject to NIS2 if the Cyprus operation meets the thresholds; a subsidiary of an EU parent company is subject on the same basis. The parent's location does not shield or include the Cyprus entity.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Cyprus transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Assess Cyprus entity on its own facts | Applicability engine · Cyprus-specific size/sector/threshold check, independent of parent |
| Register with DSA | Entity profile · Cyprus-specific registration, even if group-level compliance exists |
| File risk-management documentation | Risk register · Cyprus-specific controls and evidence |
| Report incidents to CSIRT-CY | Incident workflow · Cyprus-specific reporting, coordinated with group where applicable |
| Maintain Cyprus-specific compliance | Compliance workspace · Cyprus operations tracked separately |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Applicability
- confirmed · Cyprus subsidiary of non-EU parent, essential classification
- DSA registration
- complete · Cyprus-specific filing
- Parent coordination
- documented · group-level controls mapped to Cyprus requirements
- Controls evidenced
- 45/58 · 13 open, with Cyprus-specific ownership
- Export
- sealed · sha256:8b2d...4f9e
Where teams usually start
With a demo walked through by TruSecure — your Cyprus entity assessed on its own facts, independent of parent-company location, with the DSA registration and compliance obligations scoped to the Cyprus operation.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Cyprus by Digital Security Authority (DSA). TruSecure determines applicability against Cyprus's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.