NIS2 Directive: Objectives & Scope
A defining feature of modern international business is that it operates within an increasingly complex digital environment—even for experts in the field. The benefits are evident; so too are its vulnerabilities. The growing frequency and severity of cyberattacks and cyber threats are a source of serious concern—not only for large and medium-sized enterprises.
Rapid—indeed relentless—technological development, increasing dependence on network and information systems and the cross-border nature of cyber threats have made it necessary to establish a strong and coherent framework of protection. The obligations of entities falling within its scope have already begun to apply, starting with registration, by 30 September 2025, in the Register of Obligated Entities maintained by the National Cybersecurity Authority. More substantial obligations follow, which we will address in a subsequent article.
Introduction
Cybersecurity encompasses the protection of network and information systems (NIS), their users and other affected persons, businesses and entities against cyber incidents and related threats.
Cyber incidents—that is, incidents compromising the availability, authenticity, integrity or confidentiality of data and systems and causing serious operational disruption or financial loss—are becoming increasingly frequent. The need to address the European Union’s growing exposure to cyber threats led to the adoption of the NIS2 Directive.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022, known as the NIS2 Directive (Network and Information Security Directive), establishes a common legal framework for safeguarding cybersecurity across 18 critical sectors.
The NIS2 Directive ensures a coherent approach to cybersecurity, focusing on the protection of critical infrastructure against constantly increasing cyber threats. The need to protect the entities falling within its scope stems from the fact that disruption to the security of the services they provide may have a significant adverse impact on the internal market and/or the functioning of the State.
The NIS2 Directive, concerning measures for a high common level of cybersecurity across the Union, was transposed into Greek law by Law 5160/2024.
Compliance Framework
The framework introduced by the NIS2 Directive for entities falling within its scope establishes enhanced requirements for the protection of critical infrastructure and essential services.
In summary—and to be examined in greater detail in a subsequent article—the framework introduces:
(a) common minimum security standards;
(b) enhanced cybersecurity risk-management and timely incident-reporting measures;
(c) reporting obligations; and
(d) increased accountability of senior management.
Relationship with the NIS1 Directive
To better understand the evolution of the regulatory framework, it is important to consider the relationship between NIS2 and its predecessor, NIS1.
The NIS2 Directive is the revised version of the original Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016, commonly known as the NIS1 Directive, which was transposed into Greek law by Law 4577/2018.
NIS2 modernises the existing legal framework, adapting it to increased digitalisation requirements and the constantly evolving cyber-threat landscape.
The new Directive builds on the architecture and provisions of NIS1 while raising the EU’s common level of ambition in cybersecurity. It expands its scope to include additional sectors, introduces new obligations and stricter security measures for entities subject to the compliance framework, and establishes new mechanisms for supervision, enforcement, accountability and penalties.
It also promotes cooperation between EU Member States in jointly addressing cyber threats through new mechanisms for cooperation and information sharing. In this way, NIS2 further strengthens the resilience and incident-response capabilities of public and private entities, competent authorities and the EU as a whole.
Essential and Important Entities
Critical infrastructure, businesses, bodies and organisations falling within the regulatory scope of the NIS2 Directive are collectively referred to as “entities”. They operate within specified sectors and, as a general rule, must satisfy certain size criteria.
The NIS2 Directive and, consequently, Greek Law 5160/2024 recognise two categories of entities falling within their scope: Essential Entities and Important Entities.
This distinction takes into account their degree of criticality—having regard to the sector in which they operate and the type of services they provide—as well as their size.
Essential Entities are considered more critical than Important Entities and are consequently subject to stricter requirements. It follows that Essential Entities are also subject to a stricter supervisory and enforcement regime than Important Entities, as we will examine in a subsequent article.
More specifically:
(a) Essential Entities
The following are considered Essential Entities:
- Entities that exceed the ceilings for medium-sized enterprises laid down in Article 2(1) of the Annex to Commission Recommendation 2003/361/EC and are therefore classified as large enterprises, and, in addition, operate within the sectors and subsectors listed in Annex I to the NIS2 Directive.
These sectors include energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ICT service management (business-to-business), public administration and space.
- Irrespective of their size: trust service providers and top-level domain name registries, as well as DNS service providers; providers of public electronic communications networks or publicly available electronic communications services that qualify as medium-sized enterprises; public administration entities of central government; any other entities of a type referred to in Annex I or II that are identified as Essential Entities due to their criticality; entities identified as critical entities under Directive (EU) 2022/2557; and entities previously identified as operators of essential services under Greek Law 4577/2018.
(b) Important Entities
The following are considered Important Entities:
- Entities operating in the sectors and subsectors listed in Annex II to the NIS2 Directive, namely postal and courier services, waste management, manufacture, production and distribution of chemicals, food production, processing and distribution, manufacturing, digital providers and research; and
- entities operating in the sectors and subsectors listed in Annex I to the NIS2 Directive that do not satisfy the applicable size criterion—that is, they are not classified as “large enterprises” and therefore do not qualify as Essential Entities on that basis.
Scope of Application
Based on the Entity Size Criterion
In determining whether an entity falls within the scope of the NIS2 Directive and Greek Law 5160/2024, the following conditions must, as a general rule, be satisfied cumulatively:
(a) the entity must be established, provide services or carry out its activities within Greek territory;
(b) it must operate in one of the sectors or subsectors referred to in Annexes I and II; and
(c) it must qualify, at a minimum, as a medium-sized enterprise within the meaning of Article 2(1) of the Annex to Recommendation 2003/361/EC.
Irrespective of Entity Size
Irrespective of size, the following entities fall within the scope:
(a) Entities providing: (i) public electronic communications networks or publicly available electronic communications services; (ii) trust services; or (iii) top-level domain name registry services, as well as DNS service providers.
(b) Organisations that are the sole provider in Greece of a service essential for maintaining critical societal or economic activities.
(c) Organisations where disruption of the services they provide could have a significant impact on public safety, public security or public health.
(d) Organisations where disruption of the services they provide could create a significant systemic risk, including in sectors where such disruption could have a cross-border impact.
(e) Organisations that are critical because of their particular importance at national or regional level for the relevant sector or type of service, or for other interdependent sectors in Greece.
(f) Public-sector bodies comprising: (i) central government bodies (Article 14 §1(c) of Law 4270/2014); and (ii) regional and local authorities at first or second level.
Exceptions
Article 4 of the NIS2 Directive provides for exceptions to its application for entities that, although satisfying the general criteria, are simultaneously subject to sector-specific EU legal acts imposing requirements that are at least equivalent with respect to:
(a) cybersecurity risk-management measures; and
(b) immediate access to incident notifications by CSIRTs (Computer Security Incident Response Teams), competent authorities or single points of contact, as well as requirements concerning the notification of significant incidents.
An example of an EU sector-specific legal act falling within this category is Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022—the Digital Operational Resilience Act (DORA).
The Entity Size Rule
General
For the purposes of determining whether an undertaking qualifies, at a minimum, as medium-sized, the following distinctions should be recalled:
(a) The category of micro, small and medium-sized enterprises (SMEs) consists of enterprises employing fewer than 250 persons and having an annual turnover not exceeding €50 million or an annual balance sheet total not exceeding €43 million.
(b) A medium-sized enterprise is an enterprise employing between 50 and 249 persons and having an annual turnover not exceeding €50 million or an annual balance sheet total not exceeding €43 million.
(c) A small enterprise is an enterprise employing fewer than 50 persons and having an annual turnover or annual balance sheet total not exceeding €10 million.
(d) A microenterprise is an enterprise employing fewer than 10 persons and having an annual turnover or annual balance sheet total not exceeding €2 million.
More specifically:
(a) The relevant financial and employment data—number of employees, annual turnover and annual balance sheet total—of the latest approved accounting period must be taken into account, in accordance with Article 4 §2 of the Annex to Recommendation 2003/361/EC.
(b) Where an undertaking is close to the applicable minimum thresholds in relation to any of the relevant financial or employment criteria, the corresponding data for the two most recent consecutive financial years should be taken into account, in accordance with Article 4 §2 of the Annex to Recommendation 2003/361/EC.
(c) Part-time employees, seasonal workers and persons who did not work throughout the entire year are counted as fractions of annual work units, in accordance with Article 5 of the Annex to Recommendation 2003/361/EC.
The new regulatory framework introduced by the NIS2 Directive—and by Greek Law 5160/2024 implementing it—strengthens cybersecurity as a fundamental pillar of the effective operation of critical infrastructure.
The compliance requirements established by this framework are not limited to formal procedures. They reflect the need for substantive risk management and institutional preparedness for cyber incidents.
The importance of assessing whether or not an entity falls within the scope of this legislative framework cannot be overstated. The specific implementation issues and obligations imposed on entities subject to NIS2 will be examined in greater detail in a subsequent article.
Managing Partner
Koumentakis and Associates Law Firm
Note: This article forms part of a broader series published by our Law Firm on NIS2. In this series, we examine the relevant European and Greek legislation, always from a business-oriented perspective.