< Back to all clusters
[TECHNOLOGY] · Greece · 2 sources

Greece Adopts NIS2 Cybersecurity Directive, Raising Business Resilience Standards

The European Union’s NIS2 Directive has been transposed into Greek law through Law 5160/2024, creating a comprehensive framework for managing cyber‑risk across a wide array of critical sectors, including energy, transport, finance, health, water, digital infrastructure and public administration.

According to Bureau Veritas, the directive expands the scope of organisations subject to mandatory cybersecurity measures, requiring entities with more than 50 employees or a turnover exceeding €10 million to register with the National Cybersecurity Authority’s Registry of Essential and Important Entities. The authority will oversee compliance, provide an online self‑assessment tool and enforce deadlines for registration and reporting.

The new regime aims to integrate cyber‑security directly with overall business resilience, making it a core component of operational risk management rather than a purely IT‑department concern.

Entities: Bureau Veritas · European Union · Law 5160/2024 · NIS2 Directive · National Cybersecurity Authority