Is Your Business Ready for Greece’s Cybersecurity Law? Law 5160/2024 in Practice, and Where Greece Stands in the EU

The article was drafted by Alexandros Sarris & Magdalini Mavromichali, Senior Associates for Lexology on 26 August 2026.

  1. The compliance deadline businesses already missed

Most companies still think of Greece’s cybersecurity law, Law 5160/2024, as a future obligation. It isn’t. The law transposing the EU’s NIS2 Directive has been in force since 27 November 2024, registration with the National Cybersecurity Authority closed earlier in 2025, and the regulator is now actively supervising the market. For essential entities, the exposure for getting this wrong runs to €10,000,000 or 2% of worldwide turnover, whichever is higher, and board members can be held personally liable for governance failures, including through suspension from their management functions.

This article sets out what the law actually requires, how it interacts with two regimes many affected entities already know well, DORA and the GDPR, and how Greece’s position compares with the rest of the EU, including the Netherlands, where equivalent legislation has just been confirmed to take effect on 15 August 2026.

  1. Background: from NIS to NIS2

NIS2 replaced the original 2016 NIS Directive following a wave of attacks on hospitals, energy grids, and supply chains across the Union. Compared with its predecessor, it widens the sectors in scope, tightens supervision, strengthens cross-border cooperation between Member States, expands the list of expected risk-management measures, and introduces a more structured incident-notification regime with defined deadlines. Law 5160/2024 mirrors the three pillars of the Directive itself: obligations placed directly on in-scope entities, a strengthened role for the national regulator, and a formal cooperation mechanism at EU level.

A defining feature of the regime is where accountability lands. The law requires a named Information Systems Security Officer for every in-scope entity. That officer must be a person distinct from the entity’s Data Protection Officer under Article 37 GDPR, must act autonomously in decision-making, and serves as the entity’s direct point of contact with the regulator. Administrative bodies bear personal responsibility for adopting and maintaining the required risk-management measures, placing accountability with the board and senior management rather than solely with IT functions.

  1. Affected entities/persons

The law casts a wide net, dividing covered activity into two tiers of sector. Sectors of high criticality include energy, digital infrastructure, transport, space, health, public administration, drinking water, banking, financial market infrastructure, and ICT service management. A broader tier of other critical sectors covers chemicals manufacturing and distribution, general manufacturing, research, postal and courier services, waste management, food production and distribution, and digital providers.

Within these sectors, entities are classified as either essential or important, based on criteria set out in Articles 3 and 4 of the law, generally tracking size and the criticality of the sector concerned. Essential entities are subject to materially tighter supervision, more intrusive enforcement powers, and higher potential fines than important entities. Certain categories, including cloud computing, DNS, and top-level domain registry providers, are treated as a distinct group under Article 19, reflecting the systemic role they play in the wider digital ecosystem, and were subject to an earlier registration deadline on that basis.

In our experience, the businesses most exposed right now are not the obvious critical-infrastructure operators who saw this coming years ago. They are mid-market companies in manufacturing, logistics, food production, and digital services who assumed this law was aimed at someone else, and are only now discovering they meet the size and sector thresholds.

  1. What compliance actually requires

Three obligations follow once an entity falls within scope.

  1. Registration: essential and important entities were required to submit the information specified in Article 4(3) to the National Cybersecurity Authority, with cloud, DNS, and TLD providers submitting their Article 19(1) information on an earlier timeline. Both windows have closed, and any entity that has not yet registered should treat the obligation as overdue.
  2. Risk management: administrative bodies must adopt cybersecurity measures that are technical, organizational, and business-related, proportionate to the entity’s risk exposure, size, and the likely severity of incidents. Article 15(2) sets these out in detail, including policies for risk analysis and information-system security, incident management, business continuity, basic cyber hygiene and staff training, the use of cryptography and encryption where appropriate, multi-factor or continuous authentication, and secured voice, video, text, and emergency communications.
  3. Incident reporting: significant incidents, meaning those compromising the availability, authenticity, integrity, or confidentiality of data or services and causing or risking severe operational disruption, financial loss, or harm, must be reported to the Greek CSIRT in three stages. An early warning is due within 24 hours of the entity becoming aware of the incident, indicating whether it appears to result from unlawful or malicious activity and whether it may have cross-border effects. An incident notification follows within 72 hours, updating the early warning with an initial assessment of severity, impact, and any available indicators of compromise. A final report is due no later than one month after the notification, describing the incident, the type of threat, and the mitigation measures applied.

On paper, this reads like a checklist. In practice, a considerable amount of businesses are missing at least one of the three pillars entirely, most commonly a tested incident-reporting process that would actually work at 2am on a Saturday.

You can read the full article here: Is Your Business Ready for Greece’s Cybersecurity Law? Law 5160/2024 in Practice, and Where Greece Stands in the EU 

 

 

 

Related Posts