Cybersecurity 2026

GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm

Cross‑Jurisdictional Recognition The TIBER‑EU framework is explicitly designed to avoid duplication where multiple EU jurisdictions require TLPT. A TIBER‑EU test conducted in any EU member state can satisfy DORA TLPT requirements, provided the entity also meets the formal TLPT obliga - tions set by its competent authority. Entities Subject to Mandatory TLPT Under DORA Only “significant” financial entities fall under DORA’s mandatory TLPT requirement. These are defined by impact, risk, and systemic‑relevance criteria set out in the RTS. Examples include: • significant banks; • insurance undertakings; • systemically important payment and e‑money institutions; and • CCPs, CSDs, and major trading venues. Indicative (non‑exhaustive) thresholds include: • banks with total assets exceeding EUR30 billion; • institutions with very large customer bases or transaction volumes; and • entities operating across at least five EU member states. Frequency of TLPT Under DORA TLPT must be carried out at least once every three years. Supervisors may mandate more frequent test - ing based on identified risk. There is currently no autonomous, unified Greek “cyber-resilience law” that horizontally covers all ICT products and services. Instead, Greece follows a multi-layered cybersecurity and cyber-resilience framework aligned with EU legislation. This framework combines the following. • NIS2 (Law 5160/2024) – establishes horizontal cybersecurity obligations for essential and impor - tant entities, including governance, risk manage - ment, and incident reporting requirements. 4. Cyber-Resilience 4.1 Cyber-Resilience Legislation

• DORA (Reg. 2022/2554) – Defines digital opera - tional resilience obligations for financial entities, covering ICT risk management, incident response, and threat-led penetration testing (TLPT). • CRA (Reg. 2024/2847) – Introduces product-based security-by-design requirements for ICT products and connected devices. • EU Cybersecurity Act – Provides voluntary and mandatory certification schemes for ICT products and cloud services. The core product-focused obligations now derive from the Cyber Resilience Act (CRA), which is already in force and will be fully applicable from 11 Decem - ber 2027, with some requirements taking effect ear - lier. NIS2 (Law 5160/2024) and DORA complement the CRA. • NIS2 imposes horizontal cybersecurity duties across sectors, including digital infrastructure and managed service providers. • DORA imposes operational resilience requirements specifically for financial entities. Together, these frameworks cover most risks arising in cloud and SaaS environments, even when a service does not strictly qualify as a “product” under the CRA. The CRA applies to any hardware or software product with digital components (PDE), and its scope is inten - tionally broad. It includes: • IoT and connected consumer products (any device that connects to a network, directly or indirectly); • industrial controllers and embedded systems; • networking equipment; • operating systems and security software; • standalone software; and • cloud/SaaS components that support the function - ality of a PDE. In addition, the CRA introduces mandatory notification obligations for actively exploited vulnerabilities and for serious cybersecurity incidents, with strict reporting timelines.

177 CHAMBERS.COM

Powered by