NIS2 Greece: Law 5160/2024 (ν. 5160/2024)
Greece was the seventh EU member state to transpose NIS2, through Law 5160/2024 (ν. 5160/2024). This page covers who is in scope, registration in the Μητρώο Φορέων – Υπόχρεων and the platform that runs it, the 24-hour and 72-hour reporting chain, the supervision regime that differs by entity type, and the full fine schedule — including the per-article maximums and the range that applies to public bodies, none of which is published in English anywhere else.
Introduction: NIS2 Directive & the Greek context
Greece had already implemented the original NIS Directive through Law 4577/2018, establishing a first generation of cybersecurity rules for operators of essential services and digital service providers.
Law 5160/2024 replaced that regime, expanding the number of entities in scope, tightening risk-management and reporting duties, and giving the National Cybersecurity Authority — the Εθνική Αρχή Κυβερνοασφάλειας, or ΕΑΚ — a central role in supervision and enforcement. Unusually, the same authority is both the competent authority and the national CSIRT.
NIS2 implementation in Greece
Greece has fully transposed NIS2 through Law 5160/2024, which incorporates Directive (EU) 2022/2555 into the national legal framework and replaces the earlier NIS-based regime.
It was published in the Government Gazette as ΦΕΚ Α΄ 195/27.11.2024, replacing the NIS1 regime under ν. 4577/2018 (Α΄ 199).
The requirements themselves sit in a separate instrument that most English-language guidance does not name: ΚΥΑ 1689/2025 of 6 May 2025 (ΦΕΚ Β΄ 2186/06.05.2025), the Εθνικό Πλαίσιο Απαιτήσεων Κυβερνοασφάλειας — the National Cybersecurity Requirements Framework for essential and important entities. It sets out 22 requirements broken into technical, organisational and operational measures, built on international standards and NIS Cooperation Group guidance, and adopting an all-hazards approach. The NCSA describes it as the first of a series of regulatory acts, so more are expected.
Status
NIS2 is fully implemented in Greece. Law 5160/2024 is in force and secondary legislation on registration and security measures has been adopted.
Legal structure
ν. 5160/2024 carries the duties, the supervisory powers and the fine schedule. ΚΥΑ 1689/2025 carries the 22 technical and organisational requirements you actually have to implement. Reading the law alone will not tell you what to build.
Supervisory approach
The NCSA supervises under Articles 23–25, and the regime differs by entity type: essential entities face both ex ante and ex post supervision, important entities a simplified ex post regime only. See the supervision section.
Who is in scope in Greece
Greece follows the NIS2 model of essential and important entities and significantly expands the list of organisations subject to cybersecurity obligations, including both public and private sector operators.
Who is in scope?
- Entities in NIS2 Annex I sectors (energy, transport, health, drinking water, digital infrastructure, public administration, etc.).
- Entities in NIS2 Annex II sectors (postal and courier services, waste management, food, manufacturing of critical products, research, etc.).
- Medium-sized and large organisations that meet NIS2 thresholds for staff and turnover.
- Certain providers regardless of size (e.g. DNS, TLD registries, trust services, major cloud and data-centre operators).
Core obligations
- Implement NIS2-aligned cybersecurity risk-management measures and policies.
- Maintain asset inventories, network diagrams and documented security procedures.
- Detect, manage and report significant incidents within strict deadlines (early warning, incident notification, final report).
- Manage supply-chain risks and include security and notification clauses in contracts with key providers.
- Ensure management bodies approve cybersecurity policies and receive regular training.
Check it formally
The NCSA publishes an official scope test (test υπαγωγής) that walks an entity through the graded thresholds and returns whether it falls under ν. 5160/2024. It also runs an enquiries desk and phone lines on working days. Use the official test before relying on any third-party checklist — ours included.
Registration: the Mitroo and the platform that runs it
The NCSA states the basic obligation plainly: entities in scope must complete «Εγγραφή στο Μητρώο Φορέων – Υπόχρεων» — entry in the Register of Obliged Entities.
Where it happens
Registration runs through a dedicated NCSA platform for the αυτοδήλωση (self-declaration) of entities, reachable from the authority's own site and listed as a formal public service on gov.gr. Both public-sector bodies and private companies register in the same place.
Who registers
Public-sector organisations and private-sector businesses that meet the essential or important entity tests. The obligation is on you to assess your own status first — which is what the NCSA's scope test is for.
Local government got a year
For Ο.Τ.Α. α΄ βαθμού — first-tier local government — the law applies from 27 November 2025, one year after publication, rather than from the general commencement.
Incident reporting: 24 hours, 72 hours, one month
Every incident with a significant impact on the services of an essential or important entity must be notified to the ΕΑΚ — which is also the CSIRT, so there is only one destination. Four stages:
When is an incident "significant"?
An incident is significant if it has caused or may cause serious operational disruption of services or financial loss to the entity, or has affected or may affect other natural or legal persons by causing considerable material or non-material damage. Sector criteria sharpen this. For data centre providers, for example, an incident counts as significant if a managed data centre service is fully unavailable, if its availability is limited for more than one hour, if the integrity, confidentiality or authenticity of stored or processed data is compromised by a suspected malicious act, or if physical access to the data centre is compromised.
NIS2 timeline & key dates (Greece)
Sector-specific notes for Greece
- Energy: electricity and gas operators, as well as key energy infrastructure, are treated as essential entities.
- Transport: air, maritime and port services are especially important given Greece’s role in regional and international shipping.
- Tourism & services: while not a separate NIS2 sector, many tourism-related operators rely on digital infrastructure that can fall under NIS2 categories (e.g. data centres, cloud, payment services).
- Public administration: central ministries and key public bodies are included to strengthen the resilience of digital public services.
- Digital infrastructure: cloud providers, data centres, telecom networks and trust-service providers are a major focus of the Greek law.
Penalties and the fine schedule
Greece publishes an unusually detailed sanctions structure: the Directive's headline ceilings, a separate escalation tier for ignoring binding instructions, a dedicated range for public bodies, and a per-article schedule of maximums. None of the last three appears in English-language guidance.
Headline fines, for breach of Articles 15 or 16
| Entity | Maximum | Or, if higher |
|---|---|---|
| Essential entities (βασικές οντότητες) | EUR 10,000,000 | 2 % of the previous financial year's total worldwide annual turnover |
| Important entities (σημαντικές οντότητες) | EUR 7,000,000 | 1.4 % of the same base |
Escalation: ignoring a binding instruction costs separately
- Essential entities that fail to comply with binding instructions and directions, including measures necessary to prevent or remediate an incident: up to EUR 1,000,000.
- Important entities that fail to comply with binding instructions or orders to remedy identified deficiencies: up to EUR 700,000.
The per-article schedule
| Provision of ν. 5160/2024 breached | Maximum fine |
|---|---|
| Article 14(1) | EUR 200,000 |
| Article 14(2) | EUR 100,000 |
| Article 15(6) | EUR 300,000 |
| Article 19 | EUR 200,000 |
| Article 20 | EUR 800,000 |
| Article 21(3) | EUR 100,000 |
| Articles 24(2) and 24(4) | EUR 500,000 |
| Article 25(2) | EUR 350,000 |
Where a reprimand or formal warning procedure is used instead, an administrative fine may be imposed on the organisation under Article 15 of the older ν. 4577/2018 (Α΄ 199).
Supervision: ex ante and ex post
The NCSA supervises under Articles 23, 24 and 25, and the regime it applies depends on what you are. This is the single most practical distinction on the page.
| Essential entities | Important entities | |
|---|---|---|
| Regime | Full ex ante and ex post | Simplified, ex post only |
| Inspections | On-site inspections and off-site supervision, including sampling checks by inspectors | On-site inspections and after-the-fact supervision, on and off premises |
| Audits | Regular and targeted security audits by the NCSA, plus ad hoc special audits | Targeted security audits by the NCSA |
| Scanning | Security scans on objective, impartial, fair and transparent risk-assessment criteria | |
Management liability and mandatory training
ν. 5160/2024 defines who counts as senior management rather than leaving it to interpretation: any natural person who is responsible for the entity or acts as its legal representative, or who has authority to take decisions on its behalf or to exercise control over it.
- Senior management retains responsibility for selecting and implementing the risk-management measures, for being informed about incidents, and for providing the information the NCSA requires.
- Training is mandatory and its content is set by the State. A joint decision of the Ministers of Digital Governance, of Education, Religious Affairs and Sports, and of Labour and Social Security — issued on the proposal of the Governor of the NCSA — fixes the procedures, the duration of the training, the qualifications of trainers and the training material.
- Management must also provide comparable training to employees on a regular basis, so that staff can identify risks and assess cybersecurity risk-management practices and their impact on the organisation's services.
- Where enforcement measures are not effective, or the organisation does not respond adequately within a set period, further consequences follow for the management body.
Greek terms you will meet
The law, the register and NCSA correspondence are in Greek. These are the terms worth recognising, with the transliteration where it helps.
| Greek | What it means |
|---|---|
| ν. 5160/2024 | Law 5160/2024, the NIS2 transposition |
| ΦΕΚ Α΄ 195/27.11.2024 | Its Government Gazette reference |
| Εθνική Αρχή Κυβερνοασφάλειας (ΕΑΚ) | The National Cybersecurity Authority — the NCSA |
| βασικές οντότητες | Essential entities |
| σημαντικές οντότητες | Important entities |
| Μητρώο Φορέων – Υπόχρεων | The Register of Obliged Entities |
| αυτοδήλωση | Self-declaration — how you enter the register |
| test υπαγωγής | The NCSA's official scope test |
| έγκαιρη προειδοποίηση | The 24-hour early warning |
| κοινοποίηση περιστατικού | The 72-hour incident notification |
| τελική έκθεση | The final report |
| ΚΥΑ 1689/2025 | The joint ministerial decision carrying the 22 requirements |
| σαρώσεις ασφαλείας | Security scans, a supervisory power |
| αρχή της λογοδοσίας | The principle of accountability — you prove your own compliance |
How to prepare for NIS2 in Greece
- Determine if you are in scope: map your services and size against NIS2 Annex I & II and Law 5160/2024.
- Run the NCSA's official scope test: it is published by the authority itself and settles the question better than any third-party checklist.
- Register in the Mitroo: complete the self-declaration in the NCSA's Register of Obliged Entities if you are in scope and have not already done so.
- Assess against the 22 requirements: the gap assessment that matters is against ΚΥΑ 1689/2025, the National Cybersecurity Requirements Framework, not against the law in the abstract.
- Build your evidence file: under the principle of accountability you must produce proof of compliance during an audit — and essential entities can be audited with no incident having occurred.
- Strengthen incident readiness: establish monitoring, escalation and reporting procedures aligned with NIS2 timelines.
- Review supply-chain risk: update contracts with critical suppliers to include cybersecurity and incident-notification clauses.
- Align with recognised frameworks: use ISO/IEC 27001 or similar to structure governance, risk management and documentation.
- Train leadership and staff: management training is mandatory and its duration, trainer qualifications and material are fixed by joint ministerial decision — and management must provide comparable training to staff regularly.
