For a company operating in Greece, cybersecurity is no longer a question of whether NIS2 will apply. It is a question of what Greek law requires of the particular legal entity, who carries the responsibility, and what evidence will demonstrate compliance if the authority asks. This article examines the Greek implementation of Directive (EU) 2022/2555 as it now stands under Law 5160/2024 and the implementing measures adopted under it, and focuses on the points where legal analysis must precede technical work.
Greek implementation goes beyond the directive
A Greek NIS2 project should not rely on the directive alone. Law 5160/2024 (Government Gazette A’ 195 of 27 November 2024) transposed Directive (EU) 2022/2555 and established the domestic framework. Implementing measures then gave the obligations their substance: KYA 1381/2025 (Gazette B’ 463 of 10 February 2025) creating the digital registration platform for essential and important entities, KYA 1645/2025 (Gazette B’ 1882 of 15 April 2025) amending it and extending submission deadlines, KYA 1689/2025 (Gazette B’ 2186 of 6 May 2025) establishing the National Cybersecurity Requirements Framework for Essential and Important Entities, KYA 1990/2025 (Gazette B’ 4241 of 4 August 2025), and Ministerial Decision 1899/2025 (Gazette B’ 4250 of 5 August 2025) setting the qualifications, duties, incompatibilities and obligations of the information and communication systems security officer. The applicable position emerges only when these instruments are read together.
Scope is an entity-level legal question
Sector, services, size criteria, special categories and the particular legal entity all matter. Group-wide assumptions can be misleading. The assessment should map which entities, which services, which territorial activities and which interfaces generate the obligation, because registration and the extent of the required measures both follow from that determination.
Management bodies cannot quietly delegate responsibility to IT
The Greek framework places management bodies inside the cybersecurity governance system. Management approves and oversees risk-management measures, must be sufficiently informed about material risks, significant incidents, third-party dependencies and overdue remediation, and is subject to training obligations. The presence of a security officer or an external managed security services provider does not remove the need for informed, documented oversight.
The national requirements framework needs operational mapping, not a tick-box exercise
The National Cybersecurity Requirements Framework should not be reduced to a checklist without context. Each applicable requirement needs an owner, the specific assets or services concerned, a control design, a procedure, a record and evidence. Existing information security management material can be reused, but certification against a standard is not automatically legal compliance with the Greek framework.
Incident governance and notification
The incident process should connect technical escalation, management decision, legal assessment, the data protection interface, supplier coordination and evidence preservation. Significance thresholds, timing and notification procedures towards the competent authority and the incident response team must be verified against the Greek framework in force before any internal process goes live, and revisited whenever that framework changes.
Supply chain and third parties
Cloud services, managed services and other ICT providers create dependencies that must be mapped. Due diligence, contractual security requirements, notification and cooperation rights in an incident, ongoing monitoring of the provider and exit planning should reflect the criticality of the service rather than a standard contractual annex.
The information and communication systems security officer
The qualifications, duties, incompatibilities and obligations attaching to this role are set by Ministerial Decision 1899/2025. Appointing a person is not an administrative formality: it connects to the internal allocation of responsibilities, the position of the role in the organization, independence from conflicting duties, and the flow of information to management. Incompatibilities that have not been examined legally tend to surface later, when the authority asks for records.
Start with legal scope, not a policy package
Before new policies are drafted or technical tools purchased, the organization needs a clear position on whether and how it is caught, which national requirements are triggered and what evidence it already holds. A prioritized remediation programme follows from that, with distinct legal and operational workstreams.
Turning the analysis into a controlled mandate
In a live mandate the work cannot stop at high-level advisory language. The legal conclusion should become a controlled workplan covering scope, registration, management oversight, the national requirements and the security officer role. Each material issue receives a factual owner and a legal owner, required documents, a decision point, dependencies and a completion criterion. This distinguishes genuine blockers from parallel workstreams, and provides disciplined change control when the client alters a business assumption during the project.
Failure modes to identify early
The most expensive problems are not always difficult points of law. They are often reliance on the directive alone, generic standards mapping without a Greek legal basis, and remediation launched before scope is determined. Those inconsistencies should be found before they become a filing, a statement to the authority, a board representation or a contractual commitment. Where a gap cannot responsibly be closed in time, it should be recorded and managed through an informed decision rather than concealed by drafting that creates a larger problem later.
Evidence, quality control and later review
A strong file allows an independent reviewer to trace the path from obligation to decision and from decision to implementation. Depending on the matter it should contain a scope memorandum, registration records, a requirement and control matrix, supplier evidence, an incident decision map and records of management review. Evidence should not sit in an unstructured folder: it should be linked to a specific requirement or action and carry an owner, date, version and review status.
Cross-border and professional-practice controls
The language of a deliverable does not determine the governing law. Greek analysis cannot be transferred unchanged to another Member State, because NIS2 operates through national legislation with material differences. Each country expansion therefore passes a separate jurisdiction, practice-rights and professional-conduct gate. OIKONOMAKIS LAW may act as coordinating counsel, while local-law conclusions and representation are allocated to appropriately qualified professionals where required.
KYA 1689/2025 creates a national operational baseline
The National Cybersecurity Requirements Framework moves Greek implementation from broad principle to a concrete set of requirements. The National Cybersecurity Authority has also put into operation a compliance assessment tool containing 169 control points across 24 thematic sections, aligned with Law 5160/2024 and KYA 1689/2025. The tool is an excellent organizational starting point for gap analysis, but it does not replace legal analysis of scope, entity classification or exceptions. Its value is that it allows legal requirement, control, evidence and maturity to be linked in a single auditable record.
Registration, security roles and governance form one system
Registration on the digital platform, appointment of the required responsible roles, management oversight, the incident notification architecture and the technical and organizational measures should be treated as one system. Registration without control ownership, or controls without a legal notification map, leaves the organization fragmented. Changes to submitted entity details and to responsible persons should not remain in internal records without a regulatory trigger to inform the authority.
Deeper analysis and implementation
Greece now has a concrete national baseline
Greek NIS2 implementation goes materially beyond Law 5160/2024. KYA 1689/2025 establishes the National Cybersecurity Requirements Framework for essential and important entities, while the 2025 measures address the registration platform and the role of the information and communication systems security officer. A Greece-specific assessment should therefore use the national regulatory set rather than generic checklists.
The Greek legislative landscape also remains active. Article 33 of Law 5305/2026 (Gazette A’ 85 of 29 May 2026) inserted Article 4A into Law 5086/2024 concerning the National Blocklist of Malicious Websites, a development that shows the cybersecurity framework is still expanding and that every internal assessment needs a scheduled review date.
Management body accountability
Management cannot transfer accountability entirely to a security officer or an external provider. The governance model should define which matters reach management, what thresholds trigger escalation, what training is required and what records demonstrate review and approval. The objective is informed oversight, not the conversion of the board into a technical security operations team.
National and European levels
Multinational groups may rely on common group security controls, but the Greek entity must demonstrate that those controls satisfy the Greek requirements and that local decision and escalation mechanisms exist. Translating a group policy is not, in itself, national implementation.
Conclusion
The most effective sequence is two-staged: first a legal scope and registration assessment, then a gap and evidence review against the National Cybersecurity Requirements Framework. This prevents expenditure on controls that have not been connected to the organization’s actual legal position, and produces a file that withstands later scrutiny.
Frequently asked questions
Which law transposes NIS2 in Greece?
Law 5160/2024 (Gazette A’ 195 of 27 November 2024), which transposes Directive (EU) 2022/2555 and is supplemented by implementing measures adopted under it.
What does KYA 1689/2025 regulate?
It establishes the National Cybersecurity Requirements Framework for Essential and Important Entities (Gazette B’ 2186 of 6 May 2025), that is, the body of requirements against which compliance is assessed.
Is an information security certification enough for compliance?
No. Existing material can be reused, but certification does not answer the legal question of scope and does not automatically satisfy the national requirements.
Who carries responsibility inside the organization?
Management approves and oversees the measures and must be adequately informed. Appointing an information and communication systems security officer, with the qualifications and incompatibilities set by Ministerial Decision 1899/2025, does not shift that responsibility.
Where should a company start if it does not know whether it is caught?
With a legal scope assessment per legal entity and service, before any expenditure on policies or technical tools.
Contact
OIKONOMAKIS LAW advises on scope and registration assessments under Law 5160/2024, gap analysis against the National Cybersecurity Requirements Framework, incident governance design, legal review of ICT supplier contracts, and support to management in discharging its oversight responsibility.
Email: leads@oikonomakislaw.com
Athens office telephone: +30 123456784
Service page: oikonomakislaw.com/services/nis2-digital-governance/ · Contact: oikonomakislaw.com/contact-us/
Disclaimer
This article is provided for information purposes, reflects the framework in force as at the legal review date stated above, and does not constitute legal advice on any specific matter. The scope and obligations of each entity depend on its own factual circumstances.
Primary and official sources
Directive (EU) 2022/2555 (NIS2) — https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
National Cybersecurity Authority — Greek cybersecurity legislation (Law 5160/2024 and implementing acts) — https://cyber.gov.gr/nomothesia/elliniki-nomothesia-gia-tin-kyvernoasfaleia/
Law 5160/2024 (Gazette A’ 195 of 27.11.2024) — https://cyber.gov.gr/wp-content/uploads/2024/12/ENOTHTA_5_ΝΟΜΟΘΕΣΙΑ_fek_a_195_2024-5160-2024-1.pdf
KYA 1689/2025 (Gazette B’ 2186 of 06.05.2025) — National Cybersecurity Requirements Framework — https://cyber.gov.gr/wp-content/uploads/2025/05/20250202186.pdf
Ministerial Decision 1899/2025 (Gazette B’ 4250 of 05.08.2025) — security officers — https://cyber.gov.gr/wp-content/uploads/2025/08/ΑΠΟΦΑΣΗ_ΥΠΟΥΡΓΟΥ_1899_20250204250.pdf
KYA 1990/2025 (Gazette B’ 4241 of 04.08.2025) — registration platform — https://cyber.gov.gr/wp-content/uploads/2025/08/Β-4241.pdf
KYA 1645/2025 (Gazette B’ 1882 of 15.04.2025) — amendment and extension of submission deadlines — https://cyber.gov.gr/wp-content/uploads/2025/04/FEK_KYA_1645_2025_paratasi_ypvolis_stoixeiwn_ontotitwn.pdf
KYA 1381/2025 (Gazette B’ 463 of 10.02.2025) — creation of the registration platform — https://cyber.gov.gr/wp-content/uploads/2025/03/KYA_APOFASI_10-Feb-2025_FEK-463_DEFTERO-TEFHOS.pdf
Law 5086/2024 (Gazette A’ 23/2024) — National Cybersecurity Authority — https://cyber.gov.gr/wp-content/uploads/2024/12/ΝΟΜΟΣ-5086_ΦΕΚ.pdf
Article 33 of Law 5305/2026 (Gazette A’ 85 of 29.05.2026) — https://cyber.gov.gr/wp-content/uploads/2026/08/FEK_85_A_29-5-2026_NOMOS-5305_2026.pdf
National Cybersecurity Authority — compliance assessment tool (169 control points / 24 thematic sections) — https://cyber.gov.gr/se-ischy-to-neo-ergaleio-axiologisis-symmorfosis-ontotiton-me-ton-n-5160-2024-m-mpletsas-thespizoyme-to-kanonistiko-plaisio-enischysis-tis-kyvernoanthektikotitas/
National Cybersecurity Authority — NIS2 scope guidance tool — https://cyber.gov.gr/nomothesia/ergaleio-kathodigisis-test-ypagogis-sto-pedio-efarmogis/
Prepared by Christos Oikonomakis, Chairman, OIKONOMAKIS LAW
CONFIDENTIAL – INTERNAL DEPLOYMENT DOCUMENT | OIKONOMAKIS LAW × F SOCIETY | Article 10 | Publication date: 15 September 2026 | Greece organic cleared / paid on hold
