Cybersecurity 2026

GREECE Trends and Developments Contributed by: Alexandros Choimes and Evangelos Katsaras, ALG Manousakis Law Firm

AI Threats, New Laws, and Expanding Obligations: The Future of Cybersecurity in Greece Introduction Cybersecurity in Greece is entering a defining period. By early 2026, the country will have implemented a new generation of legislative and strategic reforms. These developments go beyond routine legal updates and signal a broader shift in the maturity of Greece’s cybersecurity ecosystem. At the same time, the rapid adoption of emerging technologies – particularly arti - ficial intelligence (AI) – combined with increasingly sophisticated and complex cyber-attack methods, is fundamentally reshaping the risk landscape. Togeth - er, these factors significantly affect the obligations of both public and private sector organisations. This arti - cle examines the most important cybersecurity trends and regulatory developments expected in 2026, focusing on issues that are particularly relevant for organisations doing business in Greece or operating digital infrastructure connected to the Greek market. The regulatory landscape Since the start of the decade, the Greek regulatory landscape saw the adoption of numerous laws relating to the emergence of new and innovative technologies as well as to the rise of an increasingly complex cyber - security framework. What makes 2026 particularly sig - nificant is that several of these legislative initiatives are now advancing to a new stage of implementation. NIS2: Full enforcement, registration, and rising scrutiny Greece’s transposition of the EU NIS2 Directive through Law 5160/2024 has moved decisively from being merely “on the books” to being fully in force and actively enforced. A key feature of the Greek approach is the emphasis on registration and post- registration scrutiny. In-scope entities are required to register with the National Cybersecurity Authority (NCSA) and submit specific data sets via the Author - ity’s digital platform. This registration is not a purely formal or declaratory step. Once an entity becomes visible to the NCSA, it is subject to ongoing super - visory engagement, which may include requests for documentation, desk-based reviews, and on-site or remote audits.

These supervisory powers are reinforced by binding secondary measures, such as national requirements on cybersecurity policies, asset inventories, sup - plier and third-party oversight, and staff training. In practice, this “register-then-supervise” continuum is already being applied and is shaping how compliance is assessed and enforced in Greece. CER: Enforcement and the knock‑on effect for NIS2 scope Although the Critical Entities Resilience (CER) Directive is not a cybersecurity framework, its transposition into Greek law through Law 5236/2025 is expected to have one of the most significant indirect impacts on the scope of NIS2 in the coming years. CER establishes a new national regime for the identification and supervi - sion of critical entities across key sectors, including energy, transport, health, water, digital infrastructure, banking, public administration, and others. Its focus is on resilience against physical, natural, technological, and hybrid threats. The relevance of CER for cybersecurity practition - ers lies in the designation process. By 17 July 2026, Greece will be required to formally designate all critical entities and record them in a national register. In prac - tice, once an organisation is designated as a “critical entity” under CER, it will almost invariably fall within the highly critical or critical sectors already covered by NIS2. As a result, CER designation effectively oper - ates as an additional trigger for NIS2 applicability. Organisations not previously captured by the cyber - security regulatory framework will be brought into full NIS2 scope under such designation – not because of changes to cyber rules themselves, but because of their classification as critical entities under CER. In this way, CER is set to significantly expand the NIS2 compliance perimeter in Greece from 2026 onwards, subjecting a broader range of organisations to cyber - security oversight through the interplay between resil - ience and cybersecurity regulation. CRA: Gradual enforcement and product security obligations coming into focus The EU Cyber Resilience Act (CRA) is the Union’s first horizontal product security regulation for products with digital elements (PDE), a category that includes

184 CHAMBERS.COM

Powered by