Cybersecurity 2026

GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm

JMD 1990/2025 – Registration and Data Submission to NCSA • Governs how entities must register and submit data to the NCSA under Law 5160/2024. JMD 1899/2025 – Appointment and Duties of the Information and Communication Systems Security Officer (ICSSO) This JMD details the qualifications and responsibilities of the ICSSO required by Law 5160/2024 and JMD 1689/2025. It establishes: • ICSSO eligibility and qualification criteria; • conflict‑of‑interest rules (eg, ICSSO cannot also serve as DPO or Head of IT); • integrity and background‑check requirements; and • detailed ICSSO operational responsibilities cover - ing oversight of security, policies, controls, and reporting. The national framework is complemented by directly applicable EU regulations. A. Digital Operational Resilience Act (DORA) – Regulation (EU) 2022/2554 Subject matter • Establishes uniform EU‑wide rules on ICT risk management, incident reporting, digital oper - ational‑resilience testing, governance, and ICT third‑party risk oversight for the financial sector. Organisations in scope • Applies to banks, investment firms, insurers, payment institutions, CCPs, CSDs, crypto‑asset service providers, and ICT service providers sup - porting financial entities. Notable points • Is directly applicable in Greece and prevails over NIS2 obligations where both frameworks apply. • Establishes the oversight framework for critical ICT providers, such as cloud service providers.

B. Cyber Resilience Act (CRA) – Regulation (EU) 2024/2847 Subject matter • Imposes security‑by‑design and vulnerability‑man - agement obligations for digital products and software, covering secure development, life cycle management, patching, and co-ordinated vulner - ability disclosure. Organisations in scope • Applies to manufacturers, developers, importers, and distributors of digital products placed on the EU market. Notable points • Complements NIS2 by regulating product‑level security, while NIS2 focuses on service‑level resil - ience. • Introduces conformity assessment, technical‑doc - umentation requirements, and CE marking obliga - tions. 1.3 Cybersecurity Regulators The NCSA is Greece’s central cybersecurity authority, established under Law 5086/2024. It is responsible for developing the national cybersecurity strategy, super - vising NIS2 obligations, setting technical cybersecu - rity requirements, and co-ordinating national cyber incident response. In addition to supervising covered entities, the NCSA serves a co-ordinating and regulatory role. It can issue mandatory cybersecurity requirements and publish guidelines for both essential and important entities. The NCSA also operates Greece’s National Computer Security Incident Response Team (CSIRT) and acts as the country’s cyber crisis management authority. It serves as Greece’s single point of contact at the EU level for cybersecurity co-operation networks, such as the CSIRTs Network. Finally, the NCSA is responsible for conducting com - pliance checks, issuing binding orders to address identified deficiencies, and imposing administrative penalties where necessary.

167 CHAMBERS.COM

Powered by