Get in touch
NIS2

Who must comply with NIS2 in Greece

Published:

Short answer: NIS2 generally applies to medium-sized and large businesses and organisations that operate in specific sectors, such as energy, transport, health, digital infrastructure, managed service providers, food and manufacturing. Small and micro businesses are excluded, with a few exceptions. Below you can see how each case is assessed.

What NIS2 is

NIS2 is Directive (EU) 2022/2555 on a high common level of cybersecurity across the European Union. In Greece it was transposed by Law 5160/2024 (Government Gazette A 195/27.11.2024) and is supervised by the National Cybersecurity Authority. It requires in-scope entities to apply risk-management measures, report significant incidents and hold management accountable for security.

The specific measures that entities must apply in Greece are set out in Joint Ministerial Decision 1689/2025 (Government Gazette B 2186/06.05.2025), the "National Cybersecurity Requirements Framework for Essential and Important Entities" under Law 5160/2024.

Step 1: your sector

The Directive defines two lists of sectors. The first is the sectors of high criticality (Annex I):

  • Energy, transport, banking and financial market infrastructure
  • Health, drinking water and waste water
  • Digital infrastructure: cloud, data centres, DNS, providers of electronic communications and trust services
  • ICT service management for businesses: managed service and managed security service providers
  • Public administration and space

The second is the other critical sectors (Annex II):

  • Postal and courier services, waste management, chemicals
  • Food: industrial production, processing and wholesale distribution
  • Manufacturing: medical devices, electronics and optics, electrical equipment, machinery, vehicles
  • Digital providers: online marketplaces, search engines, social networking platforms
  • Research

Retail, hotels, accounting firms and general services are not included as sectors. A simple online shop selling its own products is usually not an "online marketplace" within the meaning of the Directive.

Step 2: your size

Size is assessed with the criteria of Recommendation 2003/361/EC. If you belong to a group, linked enterprises are counted as well.

Size thresholds
CategoryEmployeesFinancial figures
Small or microFewer than 50Turnover or balance sheet up to €10M
Medium-sizedFewer than 250Turnover up to €50M or balance sheet up to €43M
Large250 or moreOr turnover over €50M and balance sheet over €43M

Exceptions: in scope regardless of size

Some types of entity are in scope even if they are small:

  • Qualified trust service providers, top-level domain (TLD) name registries and DNS service providers, which are always essential entities
  • Providers of public electronic communications networks or services and non-qualified trust service providers
  • Central government public administration
  • The sole provider in the country of an essential service, or an entity whose disruption would significantly affect public safety

Essential or important entity

When you are in scope, you fall into one of two categories. The obligations are essentially the same, but supervision and fines differ.

The two categories
CategoryWhoMaximum fine (Directive)
EssentialLarge Annex I entities and certain types regardless of sizeUp to €10M or 2% of worldwide annual turnover
ImportantMedium-sized Annex I entities, medium-sized and large Annex II entitiesUp to €7M or 1.4% of worldwide annual turnover

The higher amount applies. The exact amounts and procedure are set by Law 5160/2024. Essential entities are supervised more strictly.

If you are not directly in scope

That does not mean it does not concern you. Your customers that are in scope must manage the security of their suppliers and may ask you for specific measures, such as multi-factor authentication, backups and staff training. In addition, the National Cybersecurity Authority may bring other entities into scope.

What to do now

  1. Check whether you are in scope, with our free tool. In four questions you see whether and as what.
  2. If you are in scope, assess your gaps against the Article 21 measures and the national framework of Decision 1689/2025, and register in the Entity Registry of the National Cybersecurity Authority.
  3. Set up an incident reporting procedure: early warning within 24 hours, notification within 72 hours and a final report within one month.

Frequently asked questions

Does a small business fall under NIS2?

As a rule, no. Small and micro businesses are excluded, apart from certain types of entity that are in scope regardless of size. They may, however, be asked for equivalent measures by customers that are in scope.

Does a hotel or an accounting firm fall under NIS2?

These sectors are not listed in Annexes I and II of the Directive. They may, however, have customers or partners that are in scope and who may ask them for security measures.

What is Decision 1689/2025?

It is Joint Ministerial Decision 1689/2025 (Government Gazette B 2186/06.05.2025), which establishes the National Cybersecurity Requirements Framework for Essential and Important Entities under Law 5160/2024, that is, the cybersecurity risk-management measures that in-scope entities must apply.

Where can I check whether I am in scope?

You can use ITHACA's free eligibility check. The result is indicative. The final decision rests with the National Cybersecurity Authority.