GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm
Enforcement Enforcement will be carried out by national market surveillance authorities (Greece must designate its authority by 11 June 2026). These authorities may: • request technical documentation; • conduct checks; and • impose corrective measures or restrict market placement. Under the CRA, if PDEs fail to meet requirements, authorities may: • order product recall or market withdrawal; • prohibit placement on the EU market; and • impose fines of up to EUR15 million or 2.5% of global revenue, whichever is higher. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation The EU Cybersecurity Act establishes an EU-wide cybersecurity certification framework for ICT prod - ucts, services, and processes. Under this framework, Greece designates the National Cybersecurity Author - ity (NCSA) as the National Cybersecurity Certification Authority. The European framework operates through certifica - tion schemes tailored to specific technology catego - ries. A key example is the European Cybersecurity Certification Scheme on Common Criteria (EUCC), which consolidates Common Criteria certification at the European level for defined product categories. The EUCC has been in force since 27 February 2025, mak - ing it the most clearly active European scheme at the implementation level. EU certification schemes may define three levels of assurance. • Basic – fundamental requirements and controls, typically based on lighter assessment. • Substantial – enhanced assessment offering greater security assurance.
• High – the most rigorous assessment, appropriate for particularly critical use cases. Although the Cybersecurity Act originally envisioned these schemes as voluntary, in practice they can become effectively mandatory in three key ways. • Public procurement – tenders may require compli - ance with a specific scheme or assurance level. • Sectoral regulatory compliance – frameworks such as NIS 2 or DORA may promote certification as evi - dence of due diligence. • Market access/CE-type logic – for certain “critical” product categories, certification may serve as proof of conformity or become necessary if mandated by secondary legislation. In addition, some sectors operate under their own established certification schemes, including the fol - lowing. • Automotive – vehicle cybersecurity requirements are embedded in type-approval regulations, effec - tively serving as a prerequisite for market entry. • Payments – standards such as PCI DSS and PCI PTS act as industry-mandated requirements for participation in the payment ecosystem. • Identity solutions – historically, Common Criteria (and now EUCC) has played a major role in the certification of smart cards, secure elements, and digital identity systems, where High assurance is a prerequisite for trust and security. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection In Greece, cybersecurity and personal data protection are closely interconnected, as the security of personal data is both a legal compliance requirement and a fundamental cybersecurity objective. The core frame - work is the GDPR, together with the Greek implement - ing law 4624/2019, which impose preventive security measures as well as strict obligations for managing and reporting data breaches. A key security obligation is that controllers and pro - cessors must implement “appropriate technical and
179 CHAMBERS.COM
Powered by FlippingBook