Skip to content
ARROW Consulting
NIS-2 EU cybersecurity directive compliance

NIS-2 - Network Cybersecurity

The European cybersecurity directive transposed into Greek law via Law 5160/2024

The NIS-2 Directive (Network and Information Systems Directive 2) aims to strengthen the cyber resilience of critical infrastructure and supply chains across the EU. Greece successfully transposed the Directive through Law 5160/2024.

The law requires essential and important entities to implement organizational and technical cybersecurity measures, train staff, and foster a cybersecurity culture. In May 2025, a framework of 22 cybersecurity topics was published.

Registration with the National Cyber Security Authority (NCSA) was extended until September 30, 2025, via digital platform. Structured risk assessments covering IT/OT systems, supply chain, and personal data environments are required.

Fines are significant: up to EUR 10,000,000 or 2% of global turnover for essential entities, and up to EUR 7,000,000 or 1.4% for important entities.

Who is this for

NIS-2 applies to essential entities (energy, transport, banking, healthcare, digital infrastructure, public administration) and important entities (postal, waste management, food, chemicals, manufacturing, digital providers). Medium and large enterprises in these sectors are subject to requirements.

Key Benefits

1

Fine Avoidance

Avoid fines up to EUR 10,000,000 or 2% of global turnover through documented compliance.

2

Legal Compliance

Full compliance with Law 5160/2024 and the NCSA 22-topic cybersecurity framework.

3

Enhanced Cyber Resilience

Structured response to cyber threats with technical and organizational cybersecurity measures.

4

Supply Chain Security

Assessment and strengthening of supply chain security per NIS-2 requirements.

5

ISO 27001 Alignment

NIS-2 requirements fully align with ISO 27001, enabling an integrated approach.

NIS-2 Compliance Process

01

Assessment & Classification

Determining whether the organization qualifies as essential or important entity and assessing current state.

02

NIS-2 Gap Analysis

Identification of gaps against the 22 cybersecurity topics and Law 5160/2024 requirements.

03

Training & Culture

Management and staff training on cybersecurity measures and fostering a security culture.

04

Implementation & Documentation

Implementation of technical/organizational measures, NCSA registration, compliance documentation.

05

Verification & Continuous Monitoring

Internal compliance audit, preparation for NCSA inspections, and continuous cyber threat monitoring.

NIS-2 FAQ

NIS-2 applies to essential entities (energy, transport, banking, healthcare, digital infrastructure) and important entities (postal, waste, food, chemicals, manufacturing). It affects medium and large enterprises in these sectors.

Registration with the National Cyber Security Authority (NCSA) was extended until September 30, 2025, via digital platform.

Essential entities: up to EUR 10,000,000 or 2% of global turnover. Important entities: up to EUR 7,000,000 or 1.4% of global turnover.

Yes, NIS-2 requirements closely align with ISO 27001. ISO 27001 certification is the most reliable way to document compliance.

Full NIS-2 compliance typically takes 4-8 months, depending on the organization's existing cybersecurity maturity.

In May 2025, the NCSA published a framework of 22 cybersecurity topics covering areas such as risk management, network security, threat detection, incident response, and training.

Comply with NIS-2

Contact us for a free NIS-2 readiness assessment before the registration deadline.