NIS2 Directive: Obligations of In-Scope Entities & Security Incidents

In a previous article, we examined the regulatory framework established by the NIS2 Directive and its implementing legislation in Greece (Law 5160/2024), focusing on its personal scope of application—that is, the entities required to comply with it. Taking our analysis further, it is important to examine the compliance framework applicable to in-scope Essential and Important Entities. We therefore focus below on their obligations and the framework governing the management of security incidents.

Obligation to Register with the Register of Obligated Entities

The deadline for completing registration with the Register of Obligated Entities of the National Cybersecurity Authority was set at 30 September 2025. Registration requires the disclosure of the information specified in Article 1 of Template I of Joint Ministerial Decision 1990/28.7.2025.

The information to be submitted includes the details of the Information and Communication Systems Security Officer (Υ.Α.Σ.Π.Ε.) appointed by the relevant Entity. We will address the qualifications, duties and incompatibilities associated with this role in a subsequent article.

The registration platform also allows entities that have already registered to update their information.

Obligation to Implement Cybersecurity Measures

In-scope Entities are required to implement appropriate and proportionate technical, operational and organisational measures.

These measures concern the management of risks posed to the security of network and information systems used by the Entities for their operations or for the provision of their services. They must also prevent or minimise the impact of incidents on recipients of their services or on other services and organisations.

Under Article 15 of Law 5160/2024, such measures must be based on an all-hazards approach and include, at a minimum:

(a) policies and procedures on risk analysis and information system security, enabling potential vulnerabilities to be identified in a timely manner;

(b) incident handling, including detection, response and recovery;

(c) business continuity, including backup management and the development of disaster recovery and crisis-management procedures;

(d) supply chain security, including security-related aspects concerning the relationships between each Entity and its direct suppliers or service providers;

(e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure throughout their lifecycle;

(f) policies and procedures for assessing the effectiveness of cybersecurity risk-management measures;

(g) basic cyber hygiene practices—that is, practices that users and organisations should follow to maintain the security of their systems, protect their data and reduce exposure to cyber threats—and cybersecurity training;

(h) policies and procedures regarding the use of cryptography and encryption to protect data against unauthorised access;

(i) human resources security, access-control policies and asset management; and

(j) the use of multi-factor authentication or continuous authentication solutions and secure voice, video, text and emergency communications.

Whenever non-compliance with the above measures is identified, each Entity must take the necessary, appropriate and proportionate corrective measures.

National Cybersecurity Requirements Framework

Under the implementing legislation (Article 30 §13(a) of Law 5160/2024), the National Cybersecurity Requirements Framework is established by decision of the Minister of Digital Governance and includes the technical, operational and organisational cybersecurity risk-management measures referred to above.

Joint Ministerial Decision 1689/30.4.2025 has been issued in this regard. Under its provisions, each Essential or Important Entity must:

(a) develop and implement a comprehensive cybersecurity risk-management programme;

(b) develop and maintain an appropriate cybersecurity risk-management framework, carry out periodic and proportionate risk assessments, and develop, implement and oversee a risk treatment plan;

(c) prepare a written general information security policy, together with written subject-specific security policies;

(d) define cybersecurity responsibilities and powers and assign them to specific roles;

(e) implement procedures for monitoring and assessing compliance with its regulatory cybersecurity obligations and, where non-compliance is identified, initiate corrective-action procedures;

(f) implement human resources security measures, including suitability checks, definition and communication of responsibilities and duties, disciplinary procedures and background checks for prospective personnel assuming cybersecurity roles and responsibilities;

(g) implement measures in the following areas: (i) hardware and software asset management; (ii) management of risks arising from relationships with ICT suppliers and service providers; (iii) account management and access control; (iv) secure configuration; (v) secure application development; (vi) change management; (vii) vulnerability management and disclosure; (viii) assessment of the effectiveness of cybersecurity risk-management measures; (ix) network security; (x) malware protection; (xi) staff training and awareness; (xii) use of cryptography; (xiii) physical and environmental security; (xiv) incident management; and (xv) business continuity and crisis management.

Essential Entities are additionally required to conduct periodic independent audits covering all aspects of their information security management programme and, where necessary, initiate corrective-action procedures.

Overall, the above measures must be assessed and updated at scheduled intervals, as well as whenever serious cybersecurity incidents occur or significant changes are made to the Entity’s operations.

Obligations Regarding the Allocation of Roles and Responsibilities

Specific obligations apply to the allocation of cybersecurity roles and responsibilities within each Entity and to strengthening the accountability of its management body (Articles 14 and 15 of Law 5160/2024).

Within this framework, in-scope Entities must:

(a) appoint an appropriately qualified and experienced officer as their Information and Communication Systems Security Officer (Υ.Α.Σ.Π.Ε.);

(b) maintain a comprehensive cybersecurity policy encompassing all individual measures, policies and procedures relating to the minimum technical and organisational compliance requirements. Where the Entity maintains separate documented policies and procedures, the comprehensive cybersecurity policy should refer to those documents for the relevant details;

(c) maintain a complete inventory of tangible and intangible information and communication assets, classified according to their criticality; and

(d) provide appropriate cybersecurity training to members of management as well as to the Entity’s employees.

Security Incidents

A Security Incident means any event compromising the availability, integrity or confidentiality of data stored, transmitted or processed, or of services offered by or accessible through network and information systems.

An incident is considered significant where:

(a) it has caused or is capable of causing severe operational disruption to services or financial loss to the Entity concerned; or

(b) it has affected or is capable of affecting other natural or legal persons by causing significant material or other damage.

The NIS2 Directive requires any incident having a significant impact on the provision of services by Essential or Important Entities to be notified without undue delay to the National Cybersecurity Authority.

Greek Law 5160/2024 establishes a clear timetable for such notifications. Notifications are submitted to the Computer Security Incident Response Team (CSIRT) of the National Cybersecurity Authority as follows:

(1) Early warning: without undue delay and, in any event, within 24 hours of becoming aware of the significant incident. Where applicable, the early warning must indicate whether the significant incident is suspected of having been caused by unlawful or malicious acts or whether it could have a cross-border impact.

(2) Incident notification: without undue delay and, in any event, within 72 hours of becoming aware of the significant incident. Where applicable, the notification must update the information previously provided and include an initial assessment of the significant incident, including its severity and impact and, where available, indicators of compromise.

(3) Intermediate report: upon request by the National Cybersecurity Authority, providing relevant status updates.

(4) Final report: no later than one month after submission of the incident notification or the closure of the incident.

(5) Ongoing incidents: where the incident is still ongoing when the final report would otherwise be due, the Entity must submit a progress report at that time and a final report within one month after it has handled the significant incident.

Essential and Important Entities must additionally inform recipients of their services who may potentially be affected by a significant cyber threat of the existence of that threat. They must also communicate, without undue delay, any measures or remedial actions that those recipients may take in response.

The National Cybersecurity Authority may also require an Entity to inform the public within a specified period where public awareness is necessary to prevent a significant incident, address an ongoing significant incident, or where disclosure of the significant incident is otherwise in the public interest.

Information Sharing & Compliance

Entities may voluntarily exchange cybersecurity-related information with one another. Such information sharing takes place within communities of Essential and Important Entities and, where appropriate, their suppliers or service providers.

Essential and Important Entities must notify the National Cybersecurity Authority, without undue delay, of their participation in an information-sharing arrangement and must likewise notify the Authority when they withdraw from such an arrangement.

For the purpose of demonstrating compliance with the cybersecurity measures described above, an Entity may be required to use specific ICT products, services and processes certified under European cybersecurity certification schemes.

Finally, Entities must comply with the National Cybersecurity Authority’s measures of comprehensive, proactive and reactive supervision—including audits and inspections—as well as its enforcement measures. These will be examined in greater detail in a subsequent article.

Cybersecurity has already become a fundamental pillar of business resilience and corporate responsibility. It necessarily requires a holistic and well-structured approach, beginning with the Entity’s strategy and governance and extending across every technical and operational level.

Compliance with these specific requirements—and, more broadly, with the framework established by the NIS2 Directive and its implementing legislation—strengthens preparedness and security against cyber threats and ultimately safeguards business continuity.

Supervision, the role of management and the applicable penalties will be the subject of the next—and final—article in this series.

Stavros Koumentakis

Managing Partner

Koumentakis and Associates Law Firm

Note: This article forms part of a broader series published by our Law Firm on NIS2. In this series, we examine the relevant European and Greek legislation, always from a business-oriented perspective.