
Cyprus is among the most significant ship-owning and ship-management centres in Europe and consistently ranks as one of the largest flag administrations globally. The entry into force of Directive (EU) 2022/2555 (the “NIS 2 Directive”) and its transposition into Cypriot law through the Security of Networks and Information Systems Law of 2020, as amended by Law 60(I)/2025 (the “Cyprus NIS 2 Law”), has raised important and complex questions for the Cypriot maritime industry. Whether, and to what extent, a Cyprus-based shipping company falls within scope depends on a multi-factorial analysis that goes well beyond a simple activity test. This article sets out the relevant legal framework and the key considerations for Cyprus shipping companies owning or operating Cyprus-flagged vessels.
1. What Is NIS 2?
The NIS 2 Directive was adopted on 14 December 2022, entered into force on 16 January 2023, and required all EU Member States to transpose it into national law by 17 October 2024. It replaced and significantly expanded the original NIS 1 Directive (Directive (EU) 2016/1148). Its objective, as stated in Article 1, is to achieve a high common level of cybersecurity across the Union by requiring Member States to establish national cybersecurity strategies and by imposing cybersecurity risk-management and incident-reporting obligations on a broad range of entities across critical sectors.
Cyprus transposed NIS 2 through Law 60(I)/2025, which amended the Security of Networks and Information Systems Law of 2020. The Digital Security Authority (the “Authority”) is the competent supervisory authority under the Cyprus NIS 2 Law.
2. Scope: Who Is Covered?
Under Article 2(1) of the NIS 2 Directive, mirrored in Section 2A(1)(a) of the Cyprus NIS 2 Law, the Directive applies to public or private entities that operate in one of the sectors listed in Annex I (sectors of high criticality) or Annex II (other critical sectors) and that qualify as medium-sized enterprises or exceed the ceilings for medium-sized enterprises, as defined in Article 2 of the Annex to Commission Recommendation 2003/361/EC. The entity must also provide services or carry out its activities within the EU.
The size assessment under Recommendation 2003/361/EC is not a single-variable test. It requires consideration of headcount (fewer than 250 employees for medium-sized enterprises), annual turnover (not exceeding €50 million), and balance-sheet total (not exceeding €43 million), as well as the partner and linked-enterprise rules, which aggregate the data of related entities where certain ownership or control thresholds are met. In the context of shipping groups, where ownership, chartering, and management responsibilities are frequently distributed across multiple legal entities, this aggregation exercise can produce results that are not immediately apparent from a single entity’s own financial data alone.
Article 2(1) sets the general threshold; however, Article 2(2) of the Directive provides that the Directive also applies to entities of any size where specific circumstances are present. These size-independent grounds for inclusion include: being a sole provider in a Member State of a service essential for critical societal or economic activities; a finding that disruption of the entity’s services could have a significant impact on public safety, public security, or public health; a finding that disruption could induce a significant systemic or cross-border risk; and specific importance at national or regional level. Additionally, Article 2(3) brings within scope, regardless of size, any entity identified as a critical entity under Directive (EU) 2022/2557. Member States and the competent authority may also make specific designations on a case-by-case basis. Cyprus shipping companies should not therefore assume that falling below the general size threshold is conclusive.
3. Essential Entities and Important Entities
Entities that fall within scope are classified as either essential entities or important entities under Article 3 of the NIS 2 Directive, as mirrored in Section 27 of the Cyprus NIS 2 Law. The classification matters because the two categories are subject to different supervisory regimes.
Under Article 3(1)(a) of the Directive, entities of a type referred to in Annex I that exceed the ceilings for medium-sized enterprises under Recommendation 2003/361/EC, or an annual turnover exceeding €50 million and a balance-sheet total exceeding €43 million, are classified as essential entities. Entities in Annex I that are medium-sized but do not exceed those ceilings are, by contrast, classified as important entities under Article 3(2), which covers entities falling within Annex I or II that do not qualify as essential. Essential entities are subject to proactive, comprehensive ex ante supervision; important entities are generally supervised subject to ex post supervision following evidence or indications of possible non-compliance.
Certain additional categories are always treated as essential regardless of size, including qualified trust service providers, DNS service providers, and top-level domain name registries (Article 3(1)(b) and (c)). Entities identified as critical entities under Directive (EU) 2022/2557, and any entities specifically designated by the competent authority, may also be classified as essential regardless of size (Article 3(1)(e) and (f)).
4. Maritime Transport Under NIS 2
Transport is listed in Annex I of the NIS 2 Directive as a sector of high criticality. The maritime sub-sector is expressly included. Annex I covers:
“Inland, sea and coastal passenger and freight water transport companies, as defined for maritime transport in Annex I to Regulation (EC) No 725/2004 of the European Parliament and of the Council, not including the individual vessels operated by those companies.”
Three points of the definition are particularly relevant for Cyprus shipping practice.
First, the Directive attaches obligations to the company operating the vessel, not to the vessel itself. Individual vessels are explicitly excluded from scope.
Second, the definition of “Company” is drawn from Annex I to Regulation (EC) No 725/2004, which integrates Chapter XI-2 of the International Convention for the Safety of Life at Sea (SOLAS — a binding international maritime safety treaty). Under SOLAS Regulation IX/1, and as mirrored in Article 2 of Regulation (EC) No 336/2006 on the implementation of the International Safety Management (ISM) Code within the EU, the “Company” means the shipowner or any other organisation or person, such as the ship manager or bareboat charterer, that has assumed responsibility for the operation of the ship from the shipowner and, in doing so, has agreed to take over all duties and responsibilities imposed by the ISM Code. The entity that formally holds these responsibilities is identified by the Document of Compliance (DOC- a mandatory certificate issued to the managing company by or on behalf of the flag State administration confirming ISM compliance) and is referred to in the vessel’s Safety Management Certificate (SMC- a certificate issued to the individual vessel confirming that the ship and its management company operate in accordance with the ISM Code). The Continuous Synopsis Record (CSR- an onboard record maintained by the flag State documenting the vessel’s registration history) also identifies the ISM-responsible company.
Third, the DOC is a strong indicator of which entity has assumed operational responsibility under the ISM framework and is therefore a significant factor in determining which entity constitutes the “water transport company” for NIS 2 purposes. It is not, however, the sole legal test for scope under the Directive. The full scope analysis must also consider the entity’s sector and activities, its place of establishment within the EU, its size calculated in accordance with Recommendation 2003/361/EC including the partner and linked-enterprise rules, and whether any size-independent ground for inclusion applies. A company that does not hold the DOC and has not assumed ISM responsibility will generally not meet the definition of a water transport operator for purposes of the maritime transport sector classification. However, it may still fall within scope through another activity it performs, another sector in which it operates, or a specific regulatory designation by the competent authority.
5. Jurisdiction: Which Member State’s Law Applies?
The applicable national implementation law for an entity is determined primarily by the entity’s place of establishment within the EU, not by the jurisdiction in which the vessel is flagged or by the law governing the management contract. Article 26 of the NIS 2 Directive sets out specific jurisdictional rules, providing that entities are generally subject to the jurisdiction of the Member State where they are established. Specific rules apply to digital service providers and DNS-related entities operating across borders. For cross-border or cross-sectoral incidents, the competent authorities of affected Member States are required to cooperate and exchange information under Article 37 of the Directive.
In the context of Cyprus shipping structures, this means that a Cyprus-incorporated entity is subject to the Cyprus NIS 2 Law, while a related ship management company incorporated in another EU Member State, even if it holds the DOC for a Cyprus-flagged vessel, is subject to that other Member State’s implementation of NIS 2. A group-wide assessment across all relevant jurisdictions of establishment is therefore essential.
6. Key Obligations for Entities in Scope
Entities that fall within scope as essential or important entities are subject to a comprehensive set of obligations under the Cyprus NIS 2 Law. The principal obligations are:
- Cybersecurity risk-management measures (Article 35 of the Cyprus NIS 2 Law, reflecting Article 21 of the Directive). Entities must implement appropriate and proportionate technical, operational, and organisational measures to manage risks to their network and information systems. The measures must be based on an all-hazards approach and must include, at a minimum: policies on risk analysis and information system security; incident handling; business continuity and crisis management including backup and disaster recovery; supply chain security; security in network acquisition, development, and maintenance; policies on cryptography and encryption; human resources security, access control, and asset management; and the use of multi-factor authentication where appropriate.
- Governance (Article 35A of the Cyprus NIS 2 Law, reflecting Article 20 of the Directive). The senior management of essential and important entities must approve the applicable cybersecurity risk-management measures, supervise their implementation and may be held accountable for infringements of those obligations. Where the statutory conditions are satisfied, natural persons holding relevant representation, decision-making or control powers may also bear personal responsibility, including responsibility for the payment of administrative fines. In relation to essential entities, persistent non-compliance may additionally result in a temporary prohibition from exercising managerial functions.
- Incident reporting (Article 35B of the Cyprus NIS 2 Law, reflecting Article 23 of the Directive). Entities must report to the Authority any incident that has a significant impact on the provision of their services (a “significant incident” — one that has caused or is capable of causing severe operational disruption or financial loss, or that has affected or is capable of affecting others by causing considerable material or non-material damage). The reporting timeline under the Cyprus NIS 2 Law is: an initial warning submitted without undue delay and in any event within six (6) hours of becoming aware of the significant incident; a full incident notification submitted without undue delay and in any event within 72 hours of becoming aware; an intermediate report on request by the Authority; and a final report within one month of submitting the incident notification. Where an incident is still ongoing at the time the final report falls due, entities must instead provide a progress report every 15 days until the incident is resolved, followed by a final report within 15 days of restoration.
Note: the Cyprus NIS 2 Law specifies an initial warning period of six hours, which is shorter than the 24-hour period in the NIS 2 Directive itself (Article 23(4)(a)). Cyprus has therefore adopted a more stringent requirement than the Directive’s minimum.
7. Sanctions
The Cyprus NIS 2 Law establishes a tiered sanctions regime under Article 43A. Administrative fines for essential entities that infringe Article 35 (risk-management measures) or Article 35B (incident reporting) of the Cyprus NIS 2 Law are subject to a maximum of at least €10,000,000 or 2% of the total worldwide annual turnover of the undertaking to which the entity belongs in the preceding financial year, whichever is higher. For important entities, the maximum is at least €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher. Fines are intended to be effective, proportionate, and dissuasive, and are assessed having regard to the circumstances of each individual case. The Cyprus NIS 2 Law also provides for criminal offences in cases of failure to report a severe incident or failure to implement required security measures, with penalties including imprisonment.
8. Practical Guidance for Cyprus Shipping Companies
In light of the above, Cyprus-based shipping companies should consider the following.
Conduct a thorough scope analysis. Determine whether the company operates in a sector covered by Annex I or Annex II, calculate size correctly under Recommendation 2003/361/EC including any partner or linked-enterprise aggregation, and consider whether any size-independent ground for inclusion may apply. This analysis should be specific to each legal entity within the group.
Identify the ISM-responsible entity for each vessel. Establish who holds the DOC for each vessel in the fleet. This is a strong indicator of which entity assumes water transport operational responsibilities for NIS 2 purposes, though it is not the only factor in the scope analysis.
Assess the group structure across all EU jurisdictions of establishment. Each entity within the shipping group should be assessed under the NIS 2 implementation law of the Member State in which it is established, which may not be Cyprus. A related DOC-holding ship management company established in another EU jurisdiction will be subject to that jurisdiction’s implementing law.
Engage with the Digital Security Authority. The Authority is in the process of identifying and classifying essential and important entities. Companies that have been listed should review the basis for their classification. Where classification appears incorrect, a formal request for review supported by relevant documentation should be submitted promptly.
Obtain tailored legal advice. The applicable framework involves EU cybersecurity law, international maritime law (SOLAS and the ISM Code), EU maritime security regulation, and Cypriot national law. The scope analysis is necessarily multi-factorial and fact-specific. A legal opinion addressing the particular corporate and fleet structure of your group is strongly recommended before reaching any compliance conclusions.
Conclusion
NIS 2 is now in force in Cyprus and presents real obligations for shipping companies that fall within its scope. Whether a particular Cyprus-based shipping company is in scope, and in which category, depends on a multi-factorial assessment covering the nature of the entity’s activities, its place of establishment, its size calculated under the applicable EU enterprise definition, and whether any size-independent ground for inclusion applies. The DOC is a significant indicator of which entity bears water transport operational responsibility for the purposes of the maritime transport sector classification, but it is one factor among several and is not determinative in isolation. Equally, the absence of a DOC does not, by itself, rule out the possibility of scope through a different route.
For those entities that are in scope, the obligations are immediate and material: robust cybersecurity risk-management measures, board-level governance accountability, structured incident-reporting timelines, and the prospect of significant administrative fines. Early engagement with the regulatory framework, the Digital Security Authority, and specialist legal counsel is the most effective way of managing NIS 2 exposure.
This article has been prepared by Chrysses Demetriades & Co. LLC, Limassol, Cyprus, as at July 2026. It is intended for general information purposes only and does not constitute legal advice. Whether a particular entity falls within the scope of the Cyprus NIS 2 Law depends on the entity’s specific activities, corporate structure, size, place of establishment, and any applicable regulatory designation, and requires a case-specific analysis. For advice specific to your circumstances, please contact our Shipping Department or info@demetriades.com.



