NIS2 in Cyprus: who is in scope and what changes at board level

Management bodies now carry direct accountability for cybersecurity risk-management measures — with personal consequences.
NIS2 widened the perimeter considerably. Entities that never considered themselves critical infrastructure — managed service providers, digital infrastructure operators, parts of the financial supply chain — now sit inside essential or important categories with proportionate but real obligations.
The most consequential change is not technical. It is the requirement that management bodies approve cybersecurity risk-management measures, oversee their implementation, and receive training. Where a board cannot show it understood the risk it accepted, sanctions can attach to individuals as well as the entity.
For Cyprus-based firms already subject to CySEC directives, much of the underlying control set overlaps with existing obligations. The gap is usually evidential: minutes that record approval, a training log, and a reporting line that surfaces incidents to the board within a defined window.
Contact
Start a confidential conversation.
Tell us about your regulatory deadline, audit finding or certification target. We respond within one business day with a qualified point of contact.
- Office
- Kafkasou 9, 2112, Aglantzia, Nicosia, Cyprus
- info@finalogic.com



