Cybersecurity 2026

GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm

1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy Greece has established a modern, multi‑layered cybersecurity framework that brings together national strategies, legislative measures, sector‑specific regu - lations and directly applicable EU instruments. More specifically, the Greek legislature: • defines clear national priorities in the National Cybersecurity Strategy 2026–2030, focusing on strengthening resilience, improving governance, enhancing public–private co-operation and devel - oping national cybersecurity skills; • creates a unified regulatory architecture through Law 5160/2024 (transposing the EU NIS2 Direc - tive), which broadens the range of regulated sectors, sets minimum cybersecurity and inci - dent‑reporting requirements, and introduces explicit accountability obligations for top manage - ment; • centralises oversight under the National Cyber - security Authority (NCSA) as established by Law 5086/2024 – the NCSA acts as the national super - visory authority, issues binding requirements, co-ordinates cyber crisis response and serves as Greece’s EU Single Point of Contact; • enhances the resilience of critical entities through Law 5236/2025 (transposing the EU CER Direc - tive), extending protection beyond cyber threats to include physical and hybrid risks affecting essential services – this aligns cybersecurity measures with broader operational resilience standards across critical sectors; and • integrates key EU regulations – including DORA, the Cyber Resilience Act (CRA), and the EU Cyber - security Act – to ensure harmonised cybersecurity standards across financial services, digital prod - ucts, ICT supply chains and certification frame - works. Together, these elements form a cohesive, risk‑based regulatory ecosystem that ensures a high and consist - ent level of cybersecurity across Greece’s critical and emerging sectors, supporting the country’s transition toward a secure and resilient digital future.

1.2 Cybersecurity Laws Law 5160/2024, which transposes the NIS2 EU Direc - tive, constitutes the core horizontal cybersecurity framework in Greece. Subject Matter • Establishes an enhanced framework for cyberse - curity risk management, incident reporting, gov - ernance obligations, and supervisory/enforcement mechanisms. Organisations in Scope • Applies to essential and important entities across the sectors listed in Annexes I and II, including: energy, transport, digital infrastructure, public administration, health, finance, space, water, waste management, food, chemicals, and manufacturing. Notable Points • Introduces top‑management accountability, stricter incident‑reporting timelines, supply‑chain security controls, and detailed asset‑inventory obligations. • Requires registration with the National Cybersecu - rity Authority (NCSA). Greece has also issued multiple binding and qua - si‑binding secondary instruments to operationalise the new cybersecurity obligations. The most signifi - cant are Joint Ministerial Decisions (JMDs). JMD 1689/2025 – National Cybersecurity Requirements Framework This is the primary binding technical and organisa - tional guidance implementing Law 5160/2024 (NIS2). It sets out concrete controls, including: • cybersecurity policies and procedures; • risk assessments; • penetration testing; • vulnerability management; • supply‑chain security requirements; • encryption and access control; • staff training obligations; • mandatory appointment of a Security/ICS Officer; and • comprehensive asset inventories.

166 CHAMBERS.COM

Powered by