
Strengthen Your Cybersecurity with 70% Funding
Cyprus SMEs officially designated as Important Entities under NIS2 may be eligible for funding from €20,000 to €100,000 to implement approved cybersecurity measures and achieve CYFUN Basic verification.
Funding is subject to formal eligibility, project approval and successful completion of all required measures.
Could Your Business Qualify?
You may be potentially eligible if your organisation:
- qualifies as an SME;
- is legally established and operating in the Republic of Cyprus;
- has been officially designated as an Important Entity under NIS2;
- meets the applicable de minimis state-aid requirements;
- has no outstanding amounts owed to the Digital Security Authority;
- meets the programme's ownership and control requirements.
Operating in a NIS2-related sector does not automatically make a business eligible. The organisation must confirm that it has been formally designated as an Important Entity.
Has your organisation been officially designated as an Important Entity under NIS2?
This pre-check is informational only and does not constitute confirmation of eligibility or funding.
Estimate your funding split
VAT is not an eligible expenditure.
Worked examples
| Eligible project cost | Potential grant | Company contribution |
|---|---|---|
| €28,572 | €20,000 | €8,572 |
| €50,000 | €35,000 | €15,000 |
| €100,000 | €70,000 | €30,000 |
| €142,857 | €100,000 | €42,857 |
The calculation is indicative only. Final eligible expenditure and funding are determined by the competent authorities.
Build a Complete Cybersecurity Improvement Programme
Eligible expenditure may include services, hardware, software and equipment identified as necessary through the independent Gap Assessment.
Governance and NIS2 readiness
- ·cybersecurity policies and procedures
- ·roles and responsibilities
- ·risk-management framework
- ·asset-management procedures
- ·supplier-security procedures
- ·incident-reporting processes
Risk assessment
- ·organisational cyber-risk assessment
- ·external attack-surface assessment
- ·third-party and supplier risk
- ·financial cyber-risk quantification
- ·remediation prioritisation
Identity and access
- ·Multi-Factor Authentication
- ·Identity and Access Management
- ·privileged-access controls
- ·access reviews
- ·secure remote access
Protection and monitoring
- ·endpoint protection
- ·EDR/XDR
- ·network security
- ·SIEM
- ·SOC/MDR
- ·logging and alerting
- ·vulnerability management
Resilience
- ·backup security
- ·immutable backups
- ·disaster recovery
- ·business continuity
- ·restoration testing
- ·incident-response exercises
Validation and training
- ·vulnerability assessments
- ·penetration testing
- ·breach and attack simulation
- ·security awareness
- ·phishing simulations
- ·management and technical training
Every proposed cost must be supported by the findings of the independent Gap Assessment and accepted as eligible under the programme.
All 34 CYFUN Basic Measures Must Be Completed
The programme is designed to help beneficiaries implement the full CYFUN Basic 2025 baseline. Partial completion is not sufficient. Successful verification of all required measures is necessary for payment of the grant.
From Identified Gaps to Verified Readiness
The Cyber Co helps organisations translate the findings of an independent Gap Assessment into a practical cybersecurity programme. We can design, coordinate and implement the required technical and organisational improvements, provide continuous monitoring and help prepare the necessary evidence for independent verification.
- STEP 1Initial consultation
- STEP 2Confirmation of current status and needs
- STEP 3Independent Gap Assessment
- STEP 4Remediation and solution plan
- STEP 5Technology and service implementation
- STEP 6Evidence preparation and readiness support
- STEP 7Independent final verification
The organisation conducting the Gap Assessment cannot be the same organisation supplying or implementing the services and equipment identified by that assessment. We maintain the required separation of roles and can work with an independent assessor selected by the client.
Cyber-risk capabilities
External cyber-risk visibility
Continuously identify external exposures, weaknesses and changes in your internet-facing security posture.
Third-party cyber-risk monitoring
Assess and monitor the cybersecurity posture of critical suppliers, technology providers and other third parties.
Financial cyber-risk quantification
Translate cyber exposure into financial impact and prioritise investments according to their expected risk reduction.
Security-control validation
Safely test whether existing security controls detect, block or miss real-world attack techniques.
These capabilities support specific parts of a wider CYFUN remediation programme. Depending on the Gap Assessment, additional organisational and technical measures may be required.
Why work with The Cyber Co?
Cybersecurity capabilities powered by Mastercard technologies and supported locally.
Request Your Free Initial NIS2 Funding Consultation
Tell us where your organisation currently stands. A cybersecurity specialist will contact you to discuss the programme, your current readiness and the appropriate next steps.
The Cyber Co is an independent cybersecurity-services provider. It does not administer the NCC-CY-NIS2/0826 programme, determine eligibility, approve projects or guarantee funding. Eligibility, project approval and the acceptance of individual expenditure are determined exclusively by the competent authorities. All information should be verified against the official call documentation.
NIS2 & CYFUN Basic Readiness Checklist
A practical readiness resource covering the areas assessed under the CYFUN Basic baseline.
Register to receive the checklist when it becomes available.
This checklist is an initial readiness resource and does not replace the independent Gap Assessment required by the programme.
Frequently asked questions
Is every Cyprus SME eligible?
No. The call is specifically intended for qualifying SMEs officially designated as Important Entities under NIS2 and meeting the programme's other conditions.
How much funding is available?
The funding intensity is 70% of eligible expenditure, with funding between €20,000 and €100,000 per approved project.
Is VAT eligible?
No. VAT is not considered an eligible expenditure under the call.
Is a Gap Assessment required?
Yes. The proposal must include the required Gap Assessment, which identifies the measures, services and investments needed.
Can The Cyber Co conduct the assessment and implement the same solutions?
The programme requires separation between the organisation conducting the Gap Assessment and the organisation supplying or implementing the resulting services and equipment.
Are all cybersecurity products eligible?
No product is automatically eligible. Each cost must be necessary based on the Gap Assessment and accepted under the programme.
What happens if only some measures are completed?
The programme requires successful implementation and verification of the full CYFUN Basic baseline. Partial completion is not sufficient for grant payment.
Why should we act early?
Applications are considered in order of submission and the call may close when the available budget is exhausted.
Does The Cyber Co approve the application?
No. Eligibility, project approval and funding decisions are made by the competent authorities.
Do Not Wait Until the Funding Deadline
Eligibility confirmation, an independent Gap Assessment, solution planning and proposal preparation all require time. Begin your initial assessment now.
The Cyber Co is an independent cybersecurity-services provider. It does not administer the NCC-CY-NIS2/0826 programme, determine eligibility, approve projects or guarantee funding. Eligibility, project approval and the acceptance of individual expenditure are determined exclusively by the competent authorities. All information should be verified against the official call documentation.