
NIS-2 - Network Cybersecurity
The European cybersecurity directive transposed into Greek law via Law 5160/2024
The NIS-2 Directive (Network and Information Systems Directive 2) aims to strengthen the cyber resilience of critical infrastructure and supply chains across the EU. Greece successfully transposed the Directive through Law 5160/2024.
The law requires essential and important entities to implement organizational and technical cybersecurity measures, train staff, and foster a cybersecurity culture. In May 2025, a framework of 22 cybersecurity topics was published.
Registration with the National Cyber Security Authority (NCSA) was extended until September 30, 2025, via digital platform. Structured risk assessments covering IT/OT systems, supply chain, and personal data environments are required.
Fines are significant: up to EUR 10,000,000 or 2% of global turnover for essential entities, and up to EUR 7,000,000 or 1.4% for important entities.
Who is this for
NIS-2 applies to essential entities (energy, transport, banking, healthcare, digital infrastructure, public administration) and important entities (postal, waste management, food, chemicals, manufacturing, digital providers). Medium and large enterprises in these sectors are subject to requirements.
Key Benefits
Fine Avoidance
Avoid fines up to EUR 10,000,000 or 2% of global turnover through documented compliance.
Legal Compliance
Full compliance with Law 5160/2024 and the NCSA 22-topic cybersecurity framework.
Enhanced Cyber Resilience
Structured response to cyber threats with technical and organizational cybersecurity measures.
Supply Chain Security
Assessment and strengthening of supply chain security per NIS-2 requirements.
ISO 27001 Alignment
NIS-2 requirements fully align with ISO 27001, enabling an integrated approach.
NIS-2 Compliance Process
Assessment & Classification
Determining whether the organization qualifies as essential or important entity and assessing current state.
NIS-2 Gap Analysis
Identification of gaps against the 22 cybersecurity topics and Law 5160/2024 requirements.
Training & Culture
Management and staff training on cybersecurity measures and fostering a security culture.
Implementation & Documentation
Implementation of technical/organizational measures, NCSA registration, compliance documentation.
Verification & Continuous Monitoring
Internal compliance audit, preparation for NCSA inspections, and continuous cyber threat monitoring.
NIS-2 FAQ
NIS-2 applies to essential entities (energy, transport, banking, healthcare, digital infrastructure) and important entities (postal, waste, food, chemicals, manufacturing). It affects medium and large enterprises in these sectors.
Registration with the National Cyber Security Authority (NCSA) was extended until September 30, 2025, via digital platform.
Essential entities: up to EUR 10,000,000 or 2% of global turnover. Important entities: up to EUR 7,000,000 or 1.4% of global turnover.
Yes, NIS-2 requirements closely align with ISO 27001. ISO 27001 certification is the most reliable way to document compliance.
Full NIS-2 compliance typically takes 4-8 months, depending on the organization's existing cybersecurity maturity.
In May 2025, the NCSA published a framework of 22 cybersecurity topics covering areas such as risk management, network security, threat detection, incident response, and training.
Comply with NIS-2
Contact us for a free NIS-2 readiness assessment before the registration deadline.
