Guide · July 2026

NIS2 in Greece: who it applies to and what you actually have to do

For years, cybersecurity in most Greek companies was an IT line-item. NIS2 moves it to the boardroom: management approves the measures, management is trained, and management is personally accountable. Here is what the law actually requires — without the terminology fog.

Is NIS2 actually in force in Greece?

Yes. Directive (EU) 2022/2555 was transposed into Greek law with Law 5160/2024, and the competent supervisor is the National Cybersecurity Authority. This is no longer a “future European regulation” — it is national legislation with registration obligations and fines.

Does it apply to my company?

Two filters decide it: sector and size. The sectors span far beyond “tech”: energy, transport, banking, health, water, digital infrastructure and ICT services, public administration and space are high-criticality; postal services, waste, chemicals, food, key manufacturing (medical devices, electronics, machinery, vehicles), digital platforms and research count as “other critical”. Size-wise, the rule of thumb is 50+ employees or over €10m turnover — although for some activities (e.g. critical digital infrastructure) even smaller entities can fall in scope.

Essential or important — what is the difference?

Essential entities (large companies in high-criticality sectors) face stricter, proactive supervision and higher fines. Important entities are supervised mainly after the fact. The obligations themselves — risk measures, incident reporting — are substantially the same.

My company is small — can I ignore it?

Not necessarily. Even if you are out of scope, your large clients probably are not: NIS2 explicitly makes them responsible for their supply chain, which is why security questionnaires and contract clauses are already trickling down to suppliers of all sizes.

The 8 obligation areas (art. 21)

Incident reporting: the 24h / 72h / 1-month ladder

For significant incidents: early warning within 24 hours, full notification within 72 hours, final report within a month. These deadlines are unworkable without prepared procedures — you cannot draft an escalation plan while the ransomware clock is running.

The fines

Up to €10,000,000 or 2% of global annual turnover for essential entities; up to €7,000,000 or 1.4% for important ones — whichever is higher. Plus the power to suspend certifications or managers in extreme cases.

Where ISO 27001 fits in

ISO 27001 does not equal automatic NIS2 compliance — but it is the most direct vehicle: the article-21 measures map almost one-to-one onto its controls, and a certificate is the strongest evidence of compliance you can show the supervisor and your clients. If NIS2 concerns you, the practical route is one project covering both: an ISMS scoped to your NIS2 obligations. More on ISO 27001 →

Not sure whether you are in scope, or where to start? In the free assessment we check your classification, map your gaps against article 21 and give you a realistic plan.

Free Assessment

Start your journey to certification

Book a free initial assessment. We will analyse your needs and recommend the optimal standard and timeline.