CEO · Cyprus Cap 113 + NIS2

Cyprus Cap 113 + NIS2: The CEO-Director Personal Liability Framework

For the CEO-director of a Cyprus-registered tech, AI, or fintech company, personal liability for compliance failures sits on two foundations: Cap 113 sections 311, 197, and 43, plus NIS2 Art. 20(1) (management-body duty) and Art. 32(5)(b) (suspension power), as transposed into Cyprus law. Section 197 bars contracting the duty away.

In brief: Cyprus Companies Law Cap 113 section 311 lets the company sue a director personally for breach of duty of care. Section 197 voids exemption clauses. Section 43 attaches personal liability for untrue prospectus statements. NIS2 Art. 20(1) places cybersecurity risk-management oversight on the management body and Art. 32(5)(b) gives competent authorities the power to request court-ordered suspension of a named natural person — both routed through Cyprus's national transposition (Law 60(I)/2025). No named Cap 113 compliance case is publicly documented; the framework is live.

The pain: a Cyprus-registered CEO wears two hats

DailyMind LTD, the publisher of Compliance Glossary, is one example (HE 439959). A CEO-director of a Cyprus-incorporated company operates under a statutory framework that pre-dates the EU regulatory wave by decades — with EU directives layered on top.

AGP Law, in its Cap 113 analysis, states the s.311 route plainly:

"it is for the company or its liquidator and not for individual shareholders to sue the director in breach under section 311 of the Companies Act, Cap. 113." AGP Law — Liabilities of Directors under Cyprus Law (verbatim)

Section 311 is captioned "Responsibility for fraudulent trading" in the statute; AGP Law and Cyprus practitioners cite it as the procedural vehicle for derivative claims against directors for breach of duty — the company (not individual shareholders) is the proper plaintiff. On contracting the duty away, section 197 Cap 113 permits directors' liability insurance but voids any contract or articles-of-association clause that "attempts to exempt a director or indemnify a director who has been in breach of his duty of care and skill" (AGP Law, verbatim).

Three sections matter for a CEO-director who is also an EU regulatory addressee:

On the EU layer, NIS2 Art. 20(1) places cybersecurity risk-management oversight on management bodies of essential and important entities, and Art. 32(5)(b) gives competent authorities of essential entities the power to request court-ordered suspension of a named natural person from exercising managerial functions. Personal-liability rules attach through national transposition — Cyprus transposed NIS2 via Law 60(I)/2025, amending Law 89(I)/2020. The national framework for a Cyprus-registered essential entity is Cap 113 plus the transposition.

What this costs the CEO personally

Statutory overlays on top of Cap 113 — each with its own liability standard:

AGP Law notes, verbatim, that "claims against directors for negligence are rare." The tail risk sits in the statutory overlays above — none of which can be waived under section 197.

The board meeting question

The 2026 diligence question for a Cyprus CEO is "what evidence of active director engagement with EU compliance obligations do you hold?" The KPMG 2025 CEO Outlook (n=1,350) found 69 percent of CEOs cite the pace of regulation as a barrier to success. The EY Responsible AI Pulse (August 2025) found only 14 percent of CEOs strongly agree their organization has appropriate AI controls in place — against 29 percent for the rest of the C-suite. In a Series A, a D&O reinsurance questionnaire, or an M&A data room, "I believe we are compliant" is a position; a time-stamped approval log is a document.

How terminology governance helps

Honest note: Compliance Glossary is not a legal shield. Cap 113 liability and any NIS2-derived personal liability (routed through national transposition of Art. 20(1)) are established by the court or supervisor on the facts. The product provides a governance artifact — a time-stamped, four-eyes-approved, version-controlled record supporting a reasonable-care defense.

The economics

For current pricing, see the Atlassian Marketplace.

Frequently asked questions

Can a Cyprus CEO-director be sued personally under Cap 113?

Yes. Under Cap 113 section 311, the company can bring a civil claim against a director for breach of duty of care. Section 197 voids clauses that attempt to contract the duty away. Named compliance-failure enforcement cases are not publicly documented, but the framework is in force and is reinforced by Cyprus's national transposition of NIS2 Art. 20(1) (management-body duty) for Cyprus-registered essential entities.

What does NIS2 add for Cyprus-registered companies?

NIS2 Art. 20(1) places cybersecurity risk-management oversight on management bodies of essential and important entities, and Art. 32(5)(b) gives competent authorities of essential entities the power to request that courts temporarily prohibit a named natural person from exercising managerial functions. Both are subject to Cyprus's national transposition. For a Cyprus-registered CEO-director of an essential entity in energy, digital infrastructure, banking, or another NIS2 sector, this layers EU-derived duty on top of the existing Cap 113 common-law and statutory duty. Important entities fall under Article 33's parallel but more limited regime.

Can the CEO-director contract out of Cap 113 liability?

No. Section 197 voids provisions that exempt or indemnify a director against liability for negligence, default, breach of duty, or breach of trust. Shareholders cannot waive it. D&O insurance remains available but does not change the statutory duty.

Does a documented governance artifact reduce Cap 113 exposure?

It is not a legal shield. Cap 113 liability is established by the court on the facts. A time-stamped, version-controlled, four-eyes-approved record is, however, the kind of documentary evidence a director uses to show reasonable care. It is an artifact in a duty-of-care defense, not a defense by itself.

Install before your next Cyprus board meeting

For current pricing, see the Atlassian Marketplace.

Evaluate in Confluence Read the Security Whitepaper

Related reading