Industry newsGovernance

NIS2 in Cyprus: who is in scope and what changes at board level

14 June 20265 min readFinalogic Advisory
Board of directors reviewing a cybersecurity briefing

Management bodies now carry direct accountability for cybersecurity risk-management measures — with personal consequences.

NIS2 widened the perimeter considerably. Entities that never considered themselves critical infrastructure — managed service providers, digital infrastructure operators, parts of the financial supply chain — now sit inside essential or important categories with proportionate but real obligations.

The most consequential change is not technical. It is the requirement that management bodies approve cybersecurity risk-management measures, oversee their implementation, and receive training. Where a board cannot show it understood the risk it accepted, sanctions can attach to individuals as well as the entity.

For Cyprus-based firms already subject to CySEC directives, much of the underlying control set overlaps with existing obligations. The gap is usually evidential: minutes that record approval, a training log, and a reporting line that surfaces incidents to the board within a defined window.

Contact

Start a confidential conversation.

Tell us about your regulatory deadline, audit finding or certification target. We respond within one business day with a qualified point of contact.

Office
Kafkasou 9, 2112, Aglantzia, Nicosia, Cyprus