NIS2 Cybersecurity Funding for Cyprus SMEs
Enhancing cybersecurity for Important Entities
SMEs officially designated as Important Entities may be eligible for funding covering 70% of approved cybersecurity investments, with grants ranging from €20,000 to €100,000.
- of eligible expenditure funded
- 70%
- grant range per project
- €20K–€100K
- indicative project duration
- Up to 12 months
- submission deadline
- 10 Nov 2026, 13:00
- assessed in order of submission
- Subject to budget
Proposals are assessed in order of submission, subject to eligibility and available budget. The programme may close earlier than the stated deadline if the budget is exhausted.
Could your organisation be eligible?
The competent authorities decide eligibility. In general terms, an applicant is expected to meet all of the following conditions:
- Qualify as an SME under the applicable EU definition.
- Be legally established and operating in areas controlled by the Republic of Cyprus.
- Have been officially designated as an Important Entity under NIS2 by the Digital Security Authority.
- Have no outstanding amounts owed to the Digital Security Authority.
- Meet the applicable de minimis state-aid requirements.
- Meet the ownership and control requirements of the call.
- Maintain updated beneficial ownership information.
Being an SME or operating in a NIS2-related sector does not automatically make an organisation eligible. Formal designation as an Important Entity must be confirmed.
What the funded project must achieve
From NIS2 readiness to CYFUN Basic verification
The grant is not paid for buying technology alone. The funded project must result in the implementation and successful verification of all 34 measures of CYFUN Basic 2025 — the baseline cybersecurity framework applied in Cyprus. In practice that means documented governance, protected systems, working detection and a tested ability to recover, all evidenced to an independent verifier.
Governance and risk management
Ownership of cybersecurity at management level, a documented risk assessment, policies, supplier requirements and staff awareness.
Protection of systems and data
Access control, hardening, patching, encryption, secure configuration and protection of the data the business depends on.
Detection and incident response
Logging, monitoring, alerting and a rehearsed process for handling, escalating and reporting security incidents.
Resilience, recovery and continuous improvement
Backups, tested recovery, business continuity arrangements and a cycle of review, testing and improvement.
Partial implementation is not sufficient for payment of the grant. The beneficiary must successfully complete the required verification process.
The journey
From first question to verified implementation
- 01
Confirm potential eligibility
Check SME status, place of establishment and — critically — formal designation as an Important Entity.
- 02
Obtain an independent Gap Assessment
An independent party assesses your position against the 34 CYFUN Basic measures and documents the gaps.
- 03
Define the remediation plan and eligible requirements
Translate the findings into a costed plan of organisational and technical measures for the application.
- 04
Select and implement the required solutions
Procure and deploy the services, technologies and processes the assessment identified.
- 05
Collect evidence and prepare for verification
Gather policies, configurations, logs, test results and records that demonstrate each measure is in place.
- 06
Complete independent final verification
An independent registered auditor confirms implementation of the required measures.
The organisation conducting the Gap Assessment cannot be the same organisation supplying or implementing the services and equipment identified through that assessment.
Where Infocredit Group fits
- Review the technical requirements identified by the independent assessment.
- Design an appropriate solution around those requirements.
- Provide and implement relevant technologies and services.
- Configure monitoring and reporting.
- Support evidence collection and remediation tracking.
- Provide local onboarding and ongoing support.
Capabilities
Cybersecurity capabilities supporting your remediation plan
Infocredit Group works with Mastercard to provide cybersecurity capabilities that may support specific requirements identified by an independent Gap Assessment.
See and monitor external and third-party cyber risk
- Outside-in assessment of internet-facing infrastructure
- Continuous cybersecurity posture ratings
- Identification of external exposures and weaknesses
- Supplier and third-party cyber-risk monitoring
- Portfolio and supply-chain visibility
- Issue alerts and prioritisation
- Monitoring of subsidiaries, vendors and critical service providers
Quantify cyber exposure in financial terms
- Assessment of technology, processes and workforce practices
- Financial quantification of cyber risk
- Estimation of expected loss scenarios
- Prioritisation of remediation actions
- Comparison of security investment options
- Board and management reporting
- Measurement of potential risk reduction
Validate whether security controls actually work
- Safe breach and attack simulation
- Validation of prevention and detection controls
- Testing against real-world attack techniques
- Identification of controls that blocked, detected or missed activity
- Repeatable control-effectiveness testing
- Evidence supporting remediation and assurance
These capabilities may support parts of a wider CYFUN remediation programme. Additional organisational and technical measures may be required depending on the findings of the independent Gap Assessment.
Coverage
Requirement areas and relevant capabilities
- Relevant capability
- RiskRecon
- Purpose
- Identify and monitor internet-facing risks
- Relevant capability
- RiskRecon
- Purpose
- Continuously assess vendors and critical providers
- Relevant capability
- Cyber Quant
- Purpose
- Assess organisational cyber-risk exposure
- Relevant capability
- Cyber Quant
- Purpose
- Translate cyber scenarios into financial impact
- Relevant capability
- Cyber Quant
- Purpose
- Rank remediation based on expected risk reduction
- Relevant capability
- Cyber Front
- Purpose
- Test whether existing controls detect and block attacks
- Relevant capability
- RiskRecon and Cyber Front
- Purpose
- Monitor exposure and repeatedly validate controls
- Relevant capability
- Complementary services
- Purpose
- Address organisational CYFUN requirements
- Relevant capability
- Complementary solutions
- Purpose
- Address infrastructure and operational requirements
- Relevant capability
- Independent registered auditor
- Purpose
- Confirm implementation of the required measures
Indicative scope
Investment areas that may be included
Subject to the findings of the Gap Assessment and to approval by the competent authorities, a funded project may include:
- Cybersecurity consulting services
- Policies and procedures
- Security awareness and staff training
- Hardware and software
- Network and data-security solutions
- Identity and access management
- Vulnerability management
- Monitoring and incident detection
- Backup and disaster recovery
- Supplier and third-party risk management
- Testing and control validation
- The cost of one verification audit
All proposed costs must be necessary, reasonable, connected to the findings of the Gap Assessment and accepted by the competent authorities.
Potential eligibility pre-check
Five short questions to help you see where you stand before speaking to us.
This pre-check is informational only and does not constitute confirmation of eligibility.
NIS2 & CYFUN Basic Readiness Checklist – Cyprus 2026
A working checklist to record your position against each CYFUN Basic measure and to plan the evidence you will need for verification.
- CYFUN measure
- Current status
- Existing control
- Existing evidence
- Identified gap
- Required action
- Responsible owner
- Target date
- Relevant solution
- Verification status
Coming soon — register your interest and we will send it as soon as it is published.
Request an NIS2 Consultation
Tell us where you are in the process and we will come back with a practical view of what a remediation programme could look like for your organisation.
Infocredit Group is an independent provider of cybersecurity technologies and services. It does not administer the NCC-CY-NIS2/0826 programme, determine eligibility or approve funding.
FAQ
Questions about the funding call
Who may apply for the funding?
The call is aimed at SMEs that have been officially designated as Important Entities falling within the scope of NIS2 and that meet the further conditions set out in the official call. The competent authorities decide who may apply.
Is every Cyprus SME eligible?
No. SME status alone is not enough. Formal designation as an Important Entity by the Digital Security Authority, together with the other conditions of the call, must be met.
What does “Important Entity” mean?
It is a classification used under the NIS2 framework for organisations in specified sectors that are subject to cybersecurity obligations. In Cyprus, designation is made by the Digital Security Authority; the official call is the definitive reference.
What is CYFUN Basic?
CYFUN Basic 2025 is the baseline cybersecurity framework applied in Cyprus. It sets out 34 measures spanning governance, protection, detection, response and recovery.
Is a Gap Assessment mandatory?
The programme is built around an independent assessment of your position against CYFUN Basic, which then defines the remediation plan and the eligible requirements. Please confirm the exact requirement in the official call documentation.
Can Infocredit perform the Gap Assessment and implement the solution?
No. The organisation conducting the Gap Assessment cannot be the same organisation supplying or implementing the resulting services and equipment. Infocredit Group positions itself as the implementation partner.
Are Mastercard solutions automatically eligible?
No. No product is automatically eligible. Costs must be necessary, reasonable, connected to the findings of the independent Gap Assessment and accepted by the competent authorities.
What costs may be covered?
Indicatively: consulting, policies and procedures, awareness and training, hardware and software, network and data security, identity and access management, vulnerability management, monitoring and detection, backup and recovery, third-party risk management, testing and validation, and the cost of one verification audit.
Is VAT eligible?
Treatment of VAT and other cost categories is set out in the official call documentation and decided by the competent authorities. Please check the call before budgeting.
When is the submission deadline?
Proposals must be submitted by 10 November 2026, 13:00. Proposals are assessed in order of submission, subject to eligibility and available budget.
Why should organisations act early?
Selection is in order of submission and subject to available budget, so the programme may close earlier than the deadline. A Gap Assessment, remediation plan and costings also take time to prepare properly.
What happens if all 34 measures are not verified?
Partial implementation is not sufficient for payment of the grant. The beneficiary must successfully complete the required verification process.
Can Infocredit support the complete remediation programme?
Infocredit Group can design and deliver a broad implementation programme covering the technical and operational measures identified, and coordinate complementary services where specialist input is required.
Who completes the final verification?
An independent registered auditor confirms that the required measures have been implemented, in line with the requirements of the call.
Funding disclaimer
Infocredit Group is an independent provider of cybersecurity technologies and services. It does not administer the NCC-CY-NIS2/0826 programme, determine eligibility or approve funding. Eligibility, project approval and the acceptance of individual costs are determined by the competent authorities. Information on this page is provided for general informational purposes and should be verified against the official call documentation.
Last updated: 2026-09-07 · NCC-CY-NIS2/0826
