6th Cyber Security Conference · with MastercardDetails
Infocredit Group
Cyprus campaign · NCC-CY-NIS2/0826

NIS2 Cybersecurity Funding for Cyprus SMEs
Enhancing cybersecurity for Important Entities

SMEs officially designated as Important Entities may be eligible for funding covering 70% of approved cybersecurity investments, with grants ranging from €20,000 to €100,000.

of eligible expenditure funded
70%
grant range per project
€20K–€100K
indicative project duration
Up to 12 months
submission deadline
10 Nov 2026, 13:00
assessed in order of submission
Subject to budget

Proposals are assessed in order of submission, subject to eligibility and available budget. The programme may close earlier than the stated deadline if the budget is exhausted.

Could your organisation be eligible?

The competent authorities decide eligibility. In general terms, an applicant is expected to meet all of the following conditions:

  • Qualify as an SME under the applicable EU definition.
  • Be legally established and operating in areas controlled by the Republic of Cyprus.
  • Have been officially designated as an Important Entity under NIS2 by the Digital Security Authority.
  • Have no outstanding amounts owed to the Digital Security Authority.
  • Meet the applicable de minimis state-aid requirements.
  • Meet the ownership and control requirements of the call.
  • Maintain updated beneficial ownership information.

Being an SME or operating in a NIS2-related sector does not automatically make an organisation eligible. Formal designation as an Important Entity must be confirmed.

What the funded project must achieve

From NIS2 readiness to CYFUN Basic verification

The grant is not paid for buying technology alone. The funded project must result in the implementation and successful verification of all 34 measures of CYFUN Basic 2025 — the baseline cybersecurity framework applied in Cyprus. In practice that means documented governance, protected systems, working detection and a tested ability to recover, all evidenced to an independent verifier.

Governance and risk management

Ownership of cybersecurity at management level, a documented risk assessment, policies, supplier requirements and staff awareness.

Protection of systems and data

Access control, hardening, patching, encryption, secure configuration and protection of the data the business depends on.

Detection and incident response

Logging, monitoring, alerting and a rehearsed process for handling, escalating and reporting security incidents.

Resilience, recovery and continuous improvement

Backups, tested recovery, business continuity arrangements and a cycle of review, testing and improvement.

Partial implementation is not sufficient for payment of the grant. The beneficiary must successfully complete the required verification process.

The journey

From first question to verified implementation

  1. 01

    Confirm potential eligibility

    Check SME status, place of establishment and — critically — formal designation as an Important Entity.

  2. 02

    Obtain an independent Gap Assessment

    An independent party assesses your position against the 34 CYFUN Basic measures and documents the gaps.

  3. 03

    Define the remediation plan and eligible requirements

    Translate the findings into a costed plan of organisational and technical measures for the application.

  4. 04

    Select and implement the required solutions

    Procure and deploy the services, technologies and processes the assessment identified.

  5. 05

    Collect evidence and prepare for verification

    Gather policies, configurations, logs, test results and records that demonstrate each measure is in place.

  6. 06

    Complete independent final verification

    An independent registered auditor confirms implementation of the required measures.

The organisation conducting the Gap Assessment cannot be the same organisation supplying or implementing the services and equipment identified through that assessment.

Where Infocredit Group fits

  • Review the technical requirements identified by the independent assessment.
  • Design an appropriate solution around those requirements.
  • Provide and implement relevant technologies and services.
  • Configure monitoring and reporting.
  • Support evidence collection and remediation tracking.
  • Provide local onboarding and ongoing support.

Capabilities

Cybersecurity capabilities supporting your remediation plan

Infocredit Group works with Mastercard to provide cybersecurity capabilities that may support specific requirements identified by an independent Gap Assessment.

RiskRecon

See and monitor external and third-party cyber risk

What it covers
  • Outside-in assessment of internet-facing infrastructure
  • Continuous cybersecurity posture ratings
  • Identification of external exposures and weaknesses
  • Supplier and third-party cyber-risk monitoring
  • Portfolio and supply-chain visibility
  • Issue alerts and prioritisation
  • Monitoring of subsidiaries, vendors and critical service providers
Best suited for
Third-party risk managementSupplier oversightExternal attack-surface visibilityContinuous monitoring
Product details
Cyber Quant

Quantify cyber exposure in financial terms

What it covers
  • Assessment of technology, processes and workforce practices
  • Financial quantification of cyber risk
  • Estimation of expected loss scenarios
  • Prioritisation of remediation actions
  • Comparison of security investment options
  • Board and management reporting
  • Measurement of potential risk reduction
Best suited for
Enterprise cyber-risk assessmentInvestment prioritisationBudget justificationManagement and board reporting
Product details
Cyber Front

Validate whether security controls actually work

What it covers
  • Safe breach and attack simulation
  • Validation of prevention and detection controls
  • Testing against real-world attack techniques
  • Identification of controls that blocked, detected or missed activity
  • Repeatable control-effectiveness testing
  • Evidence supporting remediation and assurance
Best suited for
Security-control validationTechnical readinessRemediation testingContinuous assurance
Product details

These capabilities may support parts of a wider CYFUN remediation programme. Additional organisational and technical measures may be required depending on the findings of the independent Gap Assessment.

Coverage

Requirement areas and relevant capabilities

External cyber exposure
Relevant capability
RiskRecon
Purpose
Identify and monitor internet-facing risks
Third-party and supplier risk
Relevant capability
RiskRecon
Purpose
Continuously assess vendors and critical providers
Cyber-risk assessment
Relevant capability
Cyber Quant
Purpose
Assess organisational cyber-risk exposure
Financial risk quantification
Relevant capability
Cyber Quant
Purpose
Translate cyber scenarios into financial impact
Investment prioritisation
Relevant capability
Cyber Quant
Purpose
Rank remediation based on expected risk reduction
Security-control validation
Relevant capability
Cyber Front
Purpose
Test whether existing controls detect and block attacks
Continuous assurance
Relevant capability
RiskRecon and Cyber Front
Purpose
Monitor exposure and repeatedly validate controls
Governance, policies and procedures
Relevant capability
Complementary services
Purpose
Address organisational CYFUN requirements
IAM, EDR, SIEM, SOC, backups and resilience
Relevant capability
Complementary solutions
Purpose
Address infrastructure and operational requirements
Final verification
Relevant capability
Independent registered auditor
Purpose
Confirm implementation of the required measures

Indicative scope

Investment areas that may be included

Subject to the findings of the Gap Assessment and to approval by the competent authorities, a funded project may include:

  • Cybersecurity consulting services
  • Policies and procedures
  • Security awareness and staff training
  • Hardware and software
  • Network and data-security solutions
  • Identity and access management
  • Vulnerability management
  • Monitoring and incident detection
  • Backup and disaster recovery
  • Supplier and third-party risk management
  • Testing and control validation
  • The cost of one verification audit

All proposed costs must be necessary, reasonable, connected to the findings of the Gap Assessment and accepted by the competent authorities.

Pre-check

Potential eligibility pre-check

Five short questions to help you see where you stand before speaking to us.

Has your organisation been officially designated as an Important Entity under NIS2?
Does your organisation qualify as an SME?
Is your organisation established and operating in the Republic of Cyprus?
Have you completed a CYFUN Gap Assessment?
Which areas are you considering?

This pre-check is informational only and does not constitute confirmation of eligibility.

Resource

NIS2 & CYFUN Basic Readiness Checklist – Cyprus 2026

A working checklist to record your position against each CYFUN Basic measure and to plan the evidence you will need for verification.

  • CYFUN measure
  • Current status
  • Existing control
  • Existing evidence
  • Identified gap
  • Required action
  • Responsible owner
  • Target date
  • Relevant solution
  • Verification status

Coming soon — register your interest and we will send it as soon as it is published.

Talk to us

Request an NIS2 Consultation

Tell us where you are in the process and we will come back with a practical view of what a remediation programme could look like for your organisation.

Infocredit Group is an independent provider of cybersecurity technologies and services. It does not administer the NCC-CY-NIS2/0826 programme, determine eligibility or approve funding.

Areas of interest

FAQ

Questions about the funding call

Who may apply for the funding?

The call is aimed at SMEs that have been officially designated as Important Entities falling within the scope of NIS2 and that meet the further conditions set out in the official call. The competent authorities decide who may apply.

Is every Cyprus SME eligible?

No. SME status alone is not enough. Formal designation as an Important Entity by the Digital Security Authority, together with the other conditions of the call, must be met.

What does “Important Entity” mean?

It is a classification used under the NIS2 framework for organisations in specified sectors that are subject to cybersecurity obligations. In Cyprus, designation is made by the Digital Security Authority; the official call is the definitive reference.

What is CYFUN Basic?

CYFUN Basic 2025 is the baseline cybersecurity framework applied in Cyprus. It sets out 34 measures spanning governance, protection, detection, response and recovery.

Is a Gap Assessment mandatory?

The programme is built around an independent assessment of your position against CYFUN Basic, which then defines the remediation plan and the eligible requirements. Please confirm the exact requirement in the official call documentation.

Can Infocredit perform the Gap Assessment and implement the solution?

No. The organisation conducting the Gap Assessment cannot be the same organisation supplying or implementing the resulting services and equipment. Infocredit Group positions itself as the implementation partner.

Are Mastercard solutions automatically eligible?

No. No product is automatically eligible. Costs must be necessary, reasonable, connected to the findings of the independent Gap Assessment and accepted by the competent authorities.

What costs may be covered?

Indicatively: consulting, policies and procedures, awareness and training, hardware and software, network and data security, identity and access management, vulnerability management, monitoring and detection, backup and recovery, third-party risk management, testing and validation, and the cost of one verification audit.

Is VAT eligible?

Treatment of VAT and other cost categories is set out in the official call documentation and decided by the competent authorities. Please check the call before budgeting.

When is the submission deadline?

Proposals must be submitted by 10 November 2026, 13:00. Proposals are assessed in order of submission, subject to eligibility and available budget.

Why should organisations act early?

Selection is in order of submission and subject to available budget, so the programme may close earlier than the deadline. A Gap Assessment, remediation plan and costings also take time to prepare properly.

What happens if all 34 measures are not verified?

Partial implementation is not sufficient for payment of the grant. The beneficiary must successfully complete the required verification process.

Can Infocredit support the complete remediation programme?

Infocredit Group can design and deliver a broad implementation programme covering the technical and operational measures identified, and coordinate complementary services where specialist input is required.

Who completes the final verification?

An independent registered auditor confirms that the required measures have been implemented, in line with the requirements of the call.

Funding disclaimer

Infocredit Group is an independent provider of cybersecurity technologies and services. It does not administer the NCC-CY-NIS2/0826 programme, determine eligibility or approve funding. Eligibility, project approval and the acceptance of individual costs are determined by the competent authorities. Information on this page is provided for general informational purposes and should be verified against the official call documentation.

Last updated: 2026-09-07 · NCC-CY-NIS2/0826