NIS2 Country Guide

NIS2 Greece: Law 5160/2024 (ν. 5160/2024)

Greece was the seventh EU member state to transpose NIS2, through Law 5160/2024 (ν. 5160/2024). This page covers who is in scope, registration in the Μητρώο Φορέων – Υπόχρεων and the platform that runs it, the 24-hour and 72-hour reporting chain, the supervision regime that differs by entity type, and the full fine schedule — including the per-article maximums and the range that applies to public bodies, none of which is published in English anywhere else.

Law 5160/2024, in force 2024 Authority: NCSA / ΕΑΚ Early warning: 24 hours Public bodies fined too Last updated: 11 August 2026

Introduction: NIS2 Directive & the Greek context

Greece had already implemented the original NIS Directive through Law 4577/2018, establishing a first generation of cybersecurity rules for operators of essential services and digital service providers.

Law 5160/2024 replaced that regime, expanding the number of entities in scope, tightening risk-management and reporting duties, and giving the National Cybersecurity Authority — the Εθνική Αρχή Κυβερνοασφάλειας, or ΕΑΚ — a central role in supervision and enforcement. Unusually, the same authority is both the competent authority and the national CSIRT.

Greece moved early. The NCSA records that Greece was the seventh member state in the EU to transpose NIS2 into national law. Most of the compliance machinery — the register, the requirements framework, the supervision regime — is already running, which is not true everywhere in Europe.
Quick link: New to NIS2? Start with our general guides “What is NIS2?” and “NIS vs NIS2”.

NIS2 implementation in Greece

Greece has fully transposed NIS2 through Law 5160/2024, which incorporates Directive (EU) 2022/2555 into the national legal framework and replaces the earlier NIS-based regime.

It was published in the Government Gazette as ΦΕΚ Α΄ 195/27.11.2024, replacing the NIS1 regime under ν. 4577/2018 (Α΄ 199).

The requirements themselves sit in a separate instrument that most English-language guidance does not name: ΚΥΑ 1689/2025 of 6 May 2025 (ΦΕΚ Β΄ 2186/06.05.2025), the Εθνικό Πλαίσιο Απαιτήσεων Κυβερνοασφάλειας — the National Cybersecurity Requirements Framework for essential and important entities. It sets out 22 requirements broken into technical, organisational and operational measures, built on international standards and NIS Cooperation Group guidance, and adopting an all-hazards approach. The NCSA describes it as the first of a series of regulatory acts, so more are expected.

Status

NIS2 is fully implemented in Greece. Law 5160/2024 is in force and secondary legislation on registration and security measures has been adopted.

Legal structure

ν. 5160/2024 carries the duties, the supervisory powers and the fine schedule. ΚΥΑ 1689/2025 carries the 22 technical and organisational requirements you actually have to implement. Reading the law alone will not tell you what to build.

Supervisory approach

The NCSA supervises under Articles 23–25, and the regime differs by entity type: essential entities face both ex ante and ex post supervision, important entities a simplified ex post regime only. See the supervision section.

Who is in scope in Greece

Greece follows the NIS2 model of essential and important entities and significantly expands the list of organisations subject to cybersecurity obligations, including both public and private sector operators.

Who is in scope?

  • Entities in NIS2 Annex I sectors (energy, transport, health, drinking water, digital infrastructure, public administration, etc.).
  • Entities in NIS2 Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, research, etc.).
  • Medium-sized and large organisations that meet NIS2 thresholds for staff and turnover.
  • Certain providers regardless of size (e.g. DNS, TLD registries, trust services, major cloud and data-centre operators).

Core obligations

  • Implement NIS2-aligned cybersecurity risk-management measures and policies.
  • Maintain asset inventories, network diagrams and documented security procedures.
  • Detect, manage and report significant incidents within strict deadlines (early warning, incident notification, final report).
  • Manage supply-chain risks and include security and notification clauses in contracts with key providers.
  • Ensure management bodies approve cybersecurity policies and receive regular training.

Check it formally

The NCSA publishes an official scope test (test υπαγωγής) that walks an entity through the graded thresholds and returns whether it falls under ν. 5160/2024. It also runs an enquiries desk and phone lines on working days. Use the official test before relying on any third-party checklist — ours included.

Practical note: Greece’s NIS2 implementation brought a large number of additional organisations into scope, including ICT service management for the first time. One category got extra time: for first-tier local government (Ο.Τ.Α. α΄ βαθμού) the law applies from 27 November 2025, a year after publication.

Registration: the Mitroo and the platform that runs it

The NCSA states the basic obligation plainly: entities in scope must complete «Εγγραφή στο Μητρώο Φορέων – Υπόχρεων» — entry in the Register of Obliged Entities.

Where it happens

Registration runs through a dedicated NCSA platform for the αυτοδήλωση (self-declaration) of entities, reachable from the authority's own site and listed as a formal public service on gov.gr. Both public-sector bodies and private companies register in the same place.

Who registers

Public-sector organisations and private-sector businesses that meet the essential or important entity tests. The obligation is on you to assess your own status first — which is what the NCSA's scope test is for.

Local government got a year

For Ο.Τ.Α. α΄ βαθμού — first-tier local government — the law applies from 27 November 2025, one year after publication, rather than from the general commencement.

We do not print a single national registration deadline for Greece. Dates circulate in secondary guidance that we could not trace to the law, a ministerial decision or an NCSA publication. The register is live and the duty is current; if you are in scope and not registered, the answer is to register now rather than to look for a date.

Competent authority and CSIRT

Greece is genuinely centralised, and in one respect more so than most member states: the ΕΑΚ is both the competent authority and the CSIRT, so supervision and incident response sit in the same body. Your incident reports and your supervisor are the same organisation.

Role Authority Notes
National competent authority & Single Point of Contact National Cyber Security Authority (NCSA) Responsible for monitoring and supervising implementation of NIS2, acting as single point of contact and national cyber crisis management authority.
National CSIRT CSIRT-GR (operated under the NCSA) Receives incident notifications, provides technical guidance and coordinates response at national level.
Requirements framework Ministries of Digital Governance and of National Economy and Finance Issued ΚΥΑ 1689/2025 (ΦΕΚ Β΄ 2186/06.05.2025), the 22-requirement National Cybersecurity Requirements Framework, jointly.
Cryptography The national CRYPTO authority ν. 5160/2024 requires that policies on the use of cryptography and encryption be set in cooperation with the national CRYPTO authority where required — a Greek addition with no equivalent in the Directive.

Incident reporting: 24 hours, 72 hours, one month

Every incident with a significant impact on the services of an essential or important entity must be notified to the ΕΑΚ — which is also the CSIRT, so there is only one destination. Four stages:

24 hours — early warning (έγκαιρη προειδοποίηση): without undue delay and in any case within 24 hours of becoming aware, stating where applicable whether the incident is suspected to have been caused by unlawful or malicious acts, or could have cross-border impact.
72 hours — incident notification (κοινοποίηση περιστατικού): updates the early warning and adds an initial assessment of the incident including its severity and impact, plus indicators of compromise where these exist.
On request — interim report (ενδιάμεση έκθεση), where the NCSA asks for status updates.
One month — final report (τελική έκθεση), at the latest one month after either submission of the incident notification or the closing of the incident.
The final-report clock has an alternative trigger, and it is in your favour. Most member states run the month strictly from the 72-hour notification. Greece drafts it as one month after the notification or the closing of the incident, which gives a long-running incident room that a flat deadline does not.

When is an incident "significant"?

An incident is significant if it has caused or may cause serious operational disruption of services or financial loss to the entity, or has affected or may affect other natural or legal persons by causing considerable material or non-material damage. Sector criteria sharpen this. For data centre providers, for example, an incident counts as significant if a managed data centre service is fully unavailable, if its availability is limited for more than one hour, if the integrity, confidentiality or authenticity of stored or processed data is compromised by a suspected malicious act, or if physical access to the data centre is compromised.

NIS2 timeline & key dates (Greece)

August 2024 — Draft NIS2 transposition law published for public consultation.
27 November 2024 — Law 5160/2024 published in the Government Gazette as ΦΕΚ Α΄ 195/27.11.2024, making Greece the seventh EU member state to transpose NIS2.
Late 2024 — Law 5160/2024 enters into force, replacing the previous NIS regime.
6 May 2025 — ΚΥΑ 1689/2025 (ΦΕΚ Β΄ 2186/06.05.2025) establishes the National Cybersecurity Requirements Framework and its 22 requirements.
2025 — the NCSA register of obliged entities and its self-declaration platform go live for both public and private sector entities.
27 November 2025 — the law begins to apply to first-tier local government, one year after publication.
Ongoing — supervision under Articles 23–25: ex ante and ex post for essential entities, ex post only for important entities.

Sector-specific notes for Greece

  • Energy: electricity and gas operators, as well as key energy infrastructure, are treated as essential entities.
  • Transport: air, maritime and port services are especially important given Greece’s role in regional and international shipping.
  • Tourism & services: while not a separate NIS2 sector, many tourism-related operators rely on digital infrastructure that can fall under NIS2 categories (e.g. data centres, cloud, payment services).
  • Public administration: central ministries and key public bodies are included to strengthen the resilience of digital public services.
  • Digital infrastructure: cloud providers, data centres, telecom networks and trust-service providers are a major focus of the Greek law.

Penalties and the fine schedule

Greece publishes an unusually detailed sanctions structure: the Directive's headline ceilings, a separate escalation tier for ignoring binding instructions, a dedicated range for public bodies, and a per-article schedule of maximums. None of the last three appears in English-language guidance.

Headline fines, for breach of Articles 15 or 16

EntityMaximumOr, if higher
Essential entities (βασικές οντότητες) EUR 10,000,000 2 % of the previous financial year's total worldwide annual turnover
Important entities (σημαντικές οντότητες) EUR 7,000,000 1.4 % of the same base

Escalation: ignoring a binding instruction costs separately

  • Essential entities that fail to comply with binding instructions and directions, including measures necessary to prevent or remediate an incident: up to EUR 1,000,000.
  • Important entities that fail to comply with binding instructions or orders to remedy identified deficiencies: up to EUR 700,000.
Greece fines public bodies, and sets a floor when it does. Administrative fines on public administration entities run from EUR 20,000 to EUR 500,000. That is the opposite of Spain and France, whose transpositions exempt public bodies from fines altogether. If you are a Greek public authority, the sanction regime applies to you and has a minimum.

The per-article schedule

Provision of ν. 5160/2024 breachedMaximum fine
Article 14(1)EUR 200,000
Article 14(2)EUR 100,000
Article 15(6)EUR 300,000
Article 19EUR 200,000
Article 20EUR 800,000
Article 21(3)EUR 100,000
Articles 24(2) and 24(4)EUR 500,000
Article 25(2)EUR 350,000

Where a reprimand or formal warning procedure is used instead, an administrative fine may be imposed on the organisation under Article 15 of the older ν. 4577/2018 (Α΄ 199).

Supervision: ex ante and ex post

The NCSA supervises under Articles 23, 24 and 25, and the regime it applies depends on what you are. This is the single most practical distinction on the page.

Essential entitiesImportant entities
Regime Full ex ante and ex post Simplified, ex post only
Inspections On-site inspections and off-site supervision, including sampling checks by inspectors On-site inspections and after-the-fact supervision, on and off premises
Audits Regular and targeted security audits by the NCSA, plus ad hoc special audits Targeted security audits by the NCSA
Scanning Security scans on objective, impartial, fair and transparent risk-assessment criteria
Ex ante means without an incident. Essential entities can be audited periodically or at short notice with nothing having gone wrong. Important entities are supervised after an incident. And in both cases the burden sits with the entity: during an audit you must produce the evidence of your own compliance — the NCSA calls this the principle of accountability. Being compliant is not the same as being able to prove it on request.

Management liability and mandatory training

ν. 5160/2024 defines who counts as senior management rather than leaving it to interpretation: any natural person who is responsible for the entity or acts as its legal representative, or who has authority to take decisions on its behalf or to exercise control over it.

  • Senior management retains responsibility for selecting and implementing the risk-management measures, for being informed about incidents, and for providing the information the NCSA requires.
  • Training is mandatory and its content is set by the State. A joint decision of the Ministers of Digital Governance, of Education, Religious Affairs and Sports, and of Labour and Social Security — issued on the proposal of the Governor of the NCSA — fixes the procedures, the duration of the training, the qualifications of trainers and the training material.
  • Management must also provide comparable training to employees on a regular basis, so that staff can identify risks and assess cybersecurity risk-management practices and their impact on the organisation's services.
  • Where enforcement measures are not effective, or the organisation does not respond adequately within a set period, further consequences follow for the management body.
A state-defined curriculum is unusual. Most member states require management to be trained and leave the content to the organisation. Greece sets the duration, the trainer qualifications and the material by ministerial decision.

Greek terms you will meet

The law, the register and NCSA correspondence are in Greek. These are the terms worth recognising, with the transliteration where it helps.

GreekWhat it means
ν. 5160/2024Law 5160/2024, the NIS2 transposition
ΦΕΚ Α΄ 195/27.11.2024Its Government Gazette reference
Εθνική Αρχή Κυβερνοασφάλειας (ΕΑΚ)The National Cybersecurity Authority — the NCSA
βασικές οντότητεςEssential entities
σημαντικές οντότητεςImportant entities
Μητρώο Φορέων – ΥπόχρεωνThe Register of Obliged Entities
αυτοδήλωσηSelf-declaration — how you enter the register
test υπαγωγήςThe NCSA's official scope test
έγκαιρη προειδοποίησηThe 24-hour early warning
κοινοποίηση περιστατικούThe 72-hour incident notification
τελική έκθεσηThe final report
ΚΥΑ 1689/2025The joint ministerial decision carrying the 22 requirements
σαρώσεις ασφαλείαςSecurity scans, a supervisory power
αρχή της λογοδοσίαςThe principle of accountability — you prove your own compliance

How to prepare for NIS2 in Greece

  1. Determine if you are in scope: map your services and size against NIS2 Annex I & II and Law 5160/2024.
  2. Run the NCSA's official scope test: it is published by the authority itself and settles the question better than any third-party checklist.
  3. Register in the Mitroo: complete the self-declaration in the NCSA's Register of Obliged Entities if you are in scope and have not already done so.
  4. Assess against the 22 requirements: the gap assessment that matters is against ΚΥΑ 1689/2025, the National Cybersecurity Requirements Framework, not against the law in the abstract.
  5. Build your evidence file: under the principle of accountability you must produce proof of compliance during an audit — and essential entities can be audited with no incident having occurred.
  6. Strengthen incident readiness: establish monitoring, escalation and reporting procedures aligned with NIS2 timelines.
  7. Review supply-chain risk: update contracts with critical suppliers to include cybersecurity and incident-notification clauses.
  8. Align with recognised frameworks: use ISO/IEC 27001 or similar to structure governance, risk management and documentation.
  9. Train leadership and staff: management training is mandatory and its duration, trainer qualifications and material are fixed by joint ministerial decision — and management must provide comparable training to staff regularly.

Official links & resources

NCSA — the NIS2 Directive in Greece — the authority's own NIS2 page, with the scope test and the register
gov.gr — self-declaration of entities under NIS2 — the register as a formal public service

FAQ: NIS2 in Greece

Has Greece fully transposed NIS2?
Yes. Greece has fully transposed the NIS2 Directive through Law 5160/2024, complemented by secondary legislation on registration and cybersecurity requirements.
Who is the NIS2 competent authority in Greece?
The National Cyber Security Authority (NCSA) is the main NIS2 competent authority, single point of contact, national CSIRT operator and cyber crisis management authority.
Do we need to register, and where?
Yes, if you qualify as an essential or important entity. Registration is «Εγγραφή στο Μητρώο Φορέων – Υπόχρεων» — entry in the NCSA's Register of Obliged Entities — and it is done by self-declaration through the authority's platform, which is also listed as a formal public service on gov.gr. Public bodies and private companies use the same route.
How much can we be fined?
For breach of Articles 15 or 16, up to EUR 10,000,000 or 2 % of total worldwide annual turnover for essential entities, and EUR 7,000,000 or 1.4 % for important entities, whichever is higher. Separately, ignoring binding instructions costs up to EUR 1,000,000 (essential) or EUR 700,000 (important), and there is a per-article schedule with maximums from EUR 100,000 to EUR 800,000.
Are public sector bodies exempt from fines?
No — and this is where Greece differs sharply from Spain and France, whose transpositions exempt public bodies. Administrative fines on Greek public administration entities run from EUR 20,000 to EUR 500,000.
Will we be audited even if nothing goes wrong?
If you are an essential entity, yes. Essential entities are subject to a full ex ante and ex post regime, and ex ante supervision happens periodically or at short notice with no incident having occurred. Important entities face a simplified, ex post only regime. In both cases you must be able to produce evidence of your compliance on request.
Is ISO 27001 certification mandatory?
ISO/IEC 27001 is not mandatory by law, but alignment with recognised standards is strongly recommended to structure and demonstrate NIS2 compliance.
Information provided for general guidance; always consult ν. 5160/2024 (ΦΕΚ Α΄ 195/27.11.2024), ΚΥΑ 1689/2025 (ΦΕΚ Β΄ 2186/06.05.2025), the publications of the Εθνική Αρχή Κυβερνοασφάλειας and legal counsel for definitive NIS2 compliance requirements.