Organisations that keep the economy and daily life moving, energy, transport, health, water, food, digital infrastructure, public administration, now operate in an environment where disruption is no longer the exception. Extreme weather, cyber-attacks, geopolitical tension, supply-chain failure and technology outages can hit physical assets, people and data at the same time.
With the Civil Defence (Resilience of Critical Entities) Regulations of 2025 (K.D.P. 204/2025, Official Gazette Series III(I) No. 5958/11.7.2025), the Republic of Cyprus transposed Directive (EU) 2022/2557 on the resilience of critical entities (the CER Directive). The test is no longer whether a site is fenced. It is whether an organisation can prevent, protect against, resist, absorb and recover from an incident so that the essential service still reaches citizens and the market.
| The message boards need to hear
The Regulations are already in force. The Commander of Civil Defence was required to complete designation by 17 July 2026. Formal notification starts the clock: nine months for the entity-level risk assessment and ten months before the core obligations apply. Delay has a price — regulatory, operational and reputational. |
What is different from the old “critical infrastructure” model
The previous EU regime (Directive 2008/114/EC) focused mainly on protecting designated infrastructure. CER shifts the centre of gravity to the service: who provides it, which dependencies sustain it, and what happens to society if it stops.
That change is practical. An organisation is judged not only on the building or network it owns, but on its role in the ecosystem. A failure at a third-party supplier, a cross-border interconnection or among key personnel can be as serious as physical damage on site. That is why the Regulations require a full governance system, risk assessment, technical and organisational measures, a resilience plan, a contact point with the authority, incident notification and, in practice, board-level accountability.
Who is in scope
The Regulations apply to critical entities in energy, transport, banking and financial-market infrastructure, health, drinking water and wastewater, digital infrastructure, public administration, space, and the production, processing and distribution of food.
Operating in one of those sectors is not enough on its own. An entity is critical when it provides one or more essential services, operates and holds critical infrastructure on the territory of the Republic, and an incident would cause a significant disruption to that service or to other essential services that depend on it. Designation is made by the competent authority (as a rule, the Commander of Civil Defence), based on the national strategy for the resilience of critical entities and the national risk assessment, and recorded in the list of critical entities.
Two nuances matter. First, an entity that provides the same or similar essential services in six or more Member States may be identified as a critical entity of particular European significance, with extra Union-level coordination. Second, banking, financial-market infrastructure and digital infrastructure have their own competent authorities (the Central Bank of Cyprus, the Cyprus Securities and Exchange Commission and the Digital Security Authority respectively) and, under Regulation 8, fall outside Regulation 11 and Parts III, IV and V, the critical-entity obligations and the supervision and enforcement regime, because equivalent requirements already apply under DORA and NIS2. That is not a free pass on resilience; it is a different allocation of duties that must be mapped with care.
The obligations that matter in practice
1. Risk assessment
Within nine months of the designation notice, and at least every four years thereafter, the critical entity must assess all relevant natural and man-made risks (accidents, natural disasters, public-health emergencies, hybrid threats, terrorist offences), including cross-sector and cross-border threats, as well as dependencies on other sectors. Existing work (enterprise risk, BCM, NIS2, climate adaptation) may be reused only if it actually meets the requirements of the Regulations. A document in a drawer is not an assessment.
2. Resilience measures and the plan
The entity must take appropriate and proportionate technical, security and organisational measures: incident prevention and climate adaptation, physical protection of sites, crisis management and early warning, recovery and alternative supply chains, personnel security (critical roles, qualifications, background checks where justified) and training through exercises. These sit inside a resilience plan that is used, not filed.
3. Contact point and incident notification
A liaison officer or equivalent is designated as the contact point with the competent authority. Incidents that significantly disrupt, or are capable of significantly disrupting, an essential service must be notified without undue delay: an initial report within 24 hours of becoming aware of the incident and a detailed report within one month. Materiality turns on factors such as the number and share of users affected, duration and geographic spread.
4. Supervision and sanctions
The Commander of Civil Defence supervises compliance, may inspect on site and may order remedial measures. Contravention of the Regulations is a criminal offence punishable by imprisonment of up to two years or a fine of up to €100,000, or both. The cost of a weak programme is not only the penalty; it is supervisory scrutiny, the service outage and the loss of trust.
CER and NIS2: two regimes, one operating reality
Law 89(I)/2020, as amended by Law 60(I)/2025 (NIS2), addresses cybersecurity, with the Digital Security Authority as competent authority. K.D.P. 204/2025 addresses resilience against the full risk landscape, physical, hybrid and technological. In practice the same organisation will often have to answer to both. The sound approach is unified: one inventory of essential services, one dependency map, one board governance model and a clear split of roles among the CISO, the business-continuity lead, physical security and legal. Two parallel “compliance programmes” cost twice as much and fail at the joints.
Five moves worth starting now
- Map essential services and their dependencies. Which service, if it stops, harms citizens, customers or other critical sectors? Which suppliers, sites, systems and roles does it rest on?
- Measure the gap to the Regulations. Compare existing BCM, physical-security, crisis and NIS2 artefacts with Regulations 12–15 of K.D.P. 204/2025. Record gaps, owners and priority.
- Put decision-making governance in place. Appoint the authority contact point, define board and executive roles, escalation thresholds and the 24-hour notification rule, before an incident arrives.
- Write a resilience plan that can be executed. Not a statement of intent. Scenarios, alternate supply, authority and public communication, restoration of critical functions, exercises and lessons learned.
- Brief the board with numbers. Fine exposure, service-interruption risk, investment required, the timeline to obligation start. Resilience is a management issue, not a technical side project.
How we can help
Baker Tilly Cyprus has one of the most experienced teams in the country in this field. It brings together regulatory insight, operational continuity, physical security and cybersecurity. We do not deliver another compliance memo. We design, with your leadership, a programme that can withstand both a supervisory review and a real incident.
- CER / K.D.P. 204/2025 readiness diagnostic: current-state review, gap analysis against Regulations 12–15 and a sequenced action plan.
- Essential-service and interdependency mapping: inside the organisation, across third parties and across sectors.
- Critical-entity risk assessment: a method aligned with the national assessment, reusing existing work instead of duplicating it.
- Resilience plan and incident-notification pack: 24-hour / one-month procedures, roles, reporting templates, tabletop and field exercises.
- CER–NIS2–DORA–BCM alignment: one governance model instead of parallel programmes.
- Board support and supervisory readiness: board briefings, inspection file preparation, contact-point coaching.
If your organisation sits in an Annex sector, or has already received a designation notice, a focused diagnostic session is worth holding before the regulatory clocks run out. Speak with the Resilience & Governance team at Baker Tilly Cyprus.
Savvas M. Klitou
Regional Managing Partner
Head of Tax Services
s.klitou@bakertilly.com.cy
Ανέστης Δημόπουλος
Director
Head of Digital and Risk Advisory
a.dimopoulos@bakertilly.gr






