NIS2 in Greece: who it applies to and what you actually have to do
For years, cybersecurity in most Greek companies was an IT line-item. NIS2 moves it to the boardroom: management approves the measures, management is trained, and management is personally accountable. Here is what the law actually requires — without the terminology fog.
Is NIS2 actually in force in Greece?
Yes. Directive (EU) 2022/2555 was transposed into Greek law with Law 5160/2024, and the competent supervisor is the National Cybersecurity Authority. This is no longer a “future European regulation” — it is national legislation with registration obligations and fines.
Does it apply to my company?
Two filters decide it: sector and size. The sectors span far beyond “tech”: energy, transport, banking, health, water, digital infrastructure and ICT services, public administration and space are high-criticality; postal services, waste, chemicals, food, key manufacturing (medical devices, electronics, machinery, vehicles), digital platforms and research count as “other critical”. Size-wise, the rule of thumb is 50+ employees or over €10m turnover — although for some activities (e.g. critical digital infrastructure) even smaller entities can fall in scope.
Essential or important — what is the difference?
Essential entities (large companies in high-criticality sectors) face stricter, proactive supervision and higher fines. Important entities are supervised mainly after the fact. The obligations themselves — risk measures, incident reporting — are substantially the same.
My company is small — can I ignore it?
Not necessarily. Even if you are out of scope, your large clients probably are not: NIS2 explicitly makes them responsible for their supply chain, which is why security questionnaires and contract clauses are already trickling down to suppliers of all sizes.
The 8 obligation areas (art. 21)
- ▸Risk-analysis and information-security policies
- ▸Incident handling (detection, response, logging)
- ▸Business continuity: backups, disaster recovery, crisis management
- ▸Supply-chain security — assessment of your own suppliers
- ▸Secure development & vulnerability management
- ▸Cryptography and, where appropriate, encryption
- ▸Access control, asset management and multi-factor authentication (MFA)
- ▸Cyber-hygiene training — including for management, which bears personal responsibility
Incident reporting: the 24h / 72h / 1-month ladder
For significant incidents: early warning within 24 hours, full notification within 72 hours, final report within a month. These deadlines are unworkable without prepared procedures — you cannot draft an escalation plan while the ransomware clock is running.
The fines
Up to €10,000,000 or 2% of global annual turnover for essential entities; up to €7,000,000 or 1.4% for important ones — whichever is higher. Plus the power to suspend certifications or managers in extreme cases.
Where ISO 27001 fits in
ISO 27001 does not equal automatic NIS2 compliance — but it is the most direct vehicle: the article-21 measures map almost one-to-one onto its controls, and a certificate is the strongest evidence of compliance you can show the supervisor and your clients. If NIS2 concerns you, the practical route is one project covering both: an ISMS scoped to your NIS2 obligations. More on ISO 27001 →
Not sure whether you are in scope, or where to start? In the free assessment we check your classification, map your gaps against article 21 and give you a realistic plan.
Free Assessment