Skip to main content
NIS2 · CYPRUS

NIS2 in Cyprus — the DSA, subsidiaries in scope, and assessment by entity facts.

Cyprus transposed NIS2 through its National Cybersecurity Law, establishing the Digital Security Authority (DSA) as the competent authority and CSIRT-CY as the national CSIRT. What makes Cyprus distinctive is the market structure: most entities that meet NIS2 size and sector thresholds in Cyprus are subsidiaries or branches of larger regional or global organizations rather than standalone domestic companies. The question of whether NIS2 applies turns on the Cyprus entity's own facts — its size, its sector, its operations — not on where its parent company is located.

The transposition follows the standard EU structure, but the DSA's approach to subsidiaries emphasizes that the Cyprus entity itself must meet the thresholds and must comply in its own right. A subsidiary of a non-EU parent company is subject to NIS2 if the Cyprus operation meets the criteria; a subsidiary of an EU parent company is subject to NIS2 on the same basis. The parent's location does not shield the Cyprus entity, nor does it automatically include it.

Who it applies to

Essential and important entities in Cyprus that meet the size and sector thresholds, regardless of whether they are standalone domestic companies or subsidiaries of foreign parents. Most in-scope entities in Cyprus are subsidiaries of larger regional groups, and the DSA assesses each Cyprus entity on its own facts.

The clock

Competent authority: Digital Security Authority (DSA). Transposition: National Cybersecurity Law (NIS2 transposition).

NIS2 in Cyprus · timeline
WhenWhat happens
National Cybersecurity LawTransposition enters into force · DSA established
On classificationRegistration with DSA · risk-assessment filing
OngoingIncident reporting to CSIRT-CY · annual compliance updates

Subsidiaries assessed on entity facts

Cyprus's small market means most in-scope entities are subsidiaries of larger regional or global organizations, and the distinctive question is how NIS2 applies to these structures. The DSA's position is clear: the Cyprus entity is assessed on its own facts. A subsidiary of a non-EU parent company is subject to NIS2 if the Cyprus operation meets the thresholds; a subsidiary of an EU parent company is subject on the same basis. The parent's location does not shield or include the Cyprus entity.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Cyprus transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Cyprus requirements · how TruSecure answers them
What the law asksWhere it is answered
Assess Cyprus entity on its own factsApplicability engine · Cyprus-specific size/sector/threshold check, independent of parent
Register with DSAEntity profile · Cyprus-specific registration, even if group-level compliance exists
File risk-management documentationRisk register · Cyprus-specific controls and evidence
Report incidents to CSIRT-CYIncident workflow · Cyprus-specific reporting, coordinated with group where applicable
Maintain Cyprus-specific complianceCompliance workspace · Cyprus operations tracked separately

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Cyprus NIS2 readiness file · excerptSample data
Applicability
confirmed · Cyprus subsidiary of non-EU parent, essential classification
DSA registration
complete · Cyprus-specific filing
Parent coordination
documented · group-level controls mapped to Cyprus requirements
Controls evidenced
45/58 · 13 open, with Cyprus-specific ownership
Export
sealed · sha256:8b2d...4f9e

Where teams usually start

With a demo walked through by TruSecure — your Cyprus entity assessed on its own facts, independent of parent-company location, with the DSA registration and compliance obligations scoped to the Cyprus operation.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Cyprus by Digital Security Authority (DSA). TruSecure determines applicability against Cyprus's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Does NIS2 apply to a Cyprus subsidiary of a non-EU parent company?
Yes, where the Cyprus entity itself meets the size and sector thresholds — Cyprus's small market means most in-scope entities are subsidiaries of larger regional groups, and TruSecure assesses the Cyprus entity on its own facts, not the parent's.