NIS2 Directive: Supervision, Management Responsibility & Penalties
The effective implementation of the NIS2 Directive, as transposed into Greek law by Law 5160/2024, requires not only the establishment of substantive cybersecurity obligations but also an effective framework for supervision, accountability and enforcement.
Within this framework, the role of senior management assumes particular importance. Cybersecurity must now be embedded at the core of the organisational and strategic operation of entities falling within the scope of NIS2. The potential penalties for non-compliance are far from insignificant.
Supervision
The supervisory regime applicable to Entities falling within the scope of the NIS2 Directive and its implementing legislation in Greece (Law 5160/2024) differs according to whether they are classified as Essential or Important Entities.
Essential Entities are subject to a comprehensive supervisory regime encompassing both preventive and reactive controls. Important Entities are subject to a simplified supervisory regime, which is activated only ex post.
An ex ante supervisory regime refers to audits and supervision carried out periodically or on an ad hoc basis without a cybersecurity incident having occurred. An ex post supervisory regime, by contrast, refers to audits and supervision conducted following the occurrence of an incident.
During ex ante and ex post audits, the Entity concerned must provide the relevant evidence, indications or information necessary to demonstrate its compliance with the applicable requirements, in accordance with the principle of accountability.
The competent authority responsible for supervision, audits and the imposition of penalties under Law 5160/2024 is the National Cybersecurity Authority, which has the necessary powers and means to exercise these responsibilities.
Responsibility & Role of Senior Management
Senior management means any natural person who, as applicable, is responsible for or acts as the legal representative of the Entity by virtue of their authority to represent it, has the authority to take decisions on its behalf, or exercises control over it.
The regulatory framework established by the NIS2 Directive, as transposed into Greek law, places particular emphasis on the obligations and accountability of senior management, effectively bringing cybersecurity into the boardroom.
Compliance with the requirements of the legislation is no longer treated as a purely technical matter. It is a matter of management responsibility and corporate governance. Effective implementation and compliance therefore require senior management to adopt a strategic approach and actively participate in the design, implementation, supervision and evaluation of compliance measures.
More specifically, the senior management of in-scope Entities, pursuant to Article 14 of Law 5160/2024:
(a) approves the cybersecurity risk-management measures adopted by the Entity;
(b) oversees their implementation;
(c) undertakes training providing the knowledge and skills necessary to assess, adopt and monitor relevant decisions. This does not, of course, mean that members of senior management must become cybersecurity specialists. They must, however, possess sufficient knowledge to participate meaningfully in relevant discussions and make informed decisions;
(d) ensures that the Entity provides similar training to its employees on a regular basis, enabling them to acquire sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the Entity; and
(e) is accountable for breaches by the Entity of the obligations provided for in Article 14.
These obligations of senior management are further specified in Article 4 of Joint Ministerial Decision 1689/30.4.2025 (Government Gazette B΄ 2186/6.5.2025).
There may be circumstances in which enforcement measures imposed by the National Cybersecurity Authority prove ineffective or the Entity fails to respond effectively within the prescribed period.
In such cases, the Governor of the National Cybersecurity Authority has the power to temporarily prohibit any natural person responsible for discharging managerial responsibilities at chief executive officer or legal representative level within an Essential Entity from exercising managerial functions.
Any temporary suspension or prohibition imposed applies only until the Entity concerned takes the necessary measures to remedy the deficiencies or comply with the requirements of the competent authority.
Information and Communication Systems Security Officer
As part of its organisational compliance obligations, senior management must appoint an employee of the Entity as its Information and Communication Systems Security Officer (ICSSO), who:
(a) acts as the point of contact and cooperates with the National Cybersecurity Authority and the competent CSIRT;
(b) coordinates and oversees the Entity’s compliance with obligations arising under European and national legislation concerning the security of network and information systems;
(c) supervises the implementation of the Entity’s Unified Security Policy and compliance with the basic security requirements, as well as the training and awareness of employees on information and network security;
(d) prepares the Entity’s self-assessment report to be submitted to the National Cybersecurity Authority; and
(e) attends audits conducted by the Inspection and Audit Team appointed by the National Cybersecurity Authority and provides all appropriate means necessary to facilitate its work.
As regards the qualifications and incompatibilities applicable to the ICSSO, pursuant to Ministerial Decision 1899/27.6.2025 (Government Gazette B΄ 4250/5.8.2025), the following should be noted:
(a) The ICSSO must possess sufficient knowledge of the Entity’s business processes and satisfy at least one of the following minimum qualification requirements:
- an undergraduate degree or a postgraduate qualification of at least one year’s duration in a field related to information and network security or cybersecurity; or
- at least five years of expertise in information and network security or cybersecurity; or
iii. certified knowledge of methodologies, procedures, techniques, tools and standards relating to information and digital systems security, together with at least two years of expertise in information and network security or cybersecurity.
(b) A person may not be appointed as ICSSO where they have previously been irrevocably convicted of at least one of the offences referred to in Article 6 §§1 and 2 of Law 5002/2022 or Articles 292A–293 and 370–370F of the Greek Criminal Code. To demonstrate the absence of such an impediment, Entities must require the prospective ICSSO to provide a copy of their criminal record.
(c) The duties of the ICSSO are incompatible with those of the Data Protection Officer (DPO) under Article 37 of the General Data Protection Regulation and Articles 7 and 8 of Law 4624/2019, as well as with those of the person responsible for the Entity’s information and communication technologies (ICT) and electronic governance functions.
Finally, the ICSSO’s role within the organisational structure of the Entity must be independent and must not give rise to conflicts of interest with any other employment roles held by that person.
Penalties
The sanctions framework established by the NIS2 Directive, as further specified by Law 5160/2024, is intended to ensure a high level of cybersecurity through proportionate, effective and dissuasive enforcement measures.
Penalties vary according to the seriousness of the infringement and whether the Entity is classified as Essential or Important.
In addition to specific administrative measures—such as temporary suspensions and prohibitions under Article 24—the following financial penalties may be imposed:
(a) Failure to implement cybersecurity risk-management measures or comply with incident-reporting obligations
Where an Entity fails to implement appropriate cybersecurity risk-management measures, implements inadequate measures, or breaches its security incident-reporting obligations—that is, where Articles 15 or 16 are infringed—a fine may be imposed of:
- up to €10,000,000 for Essential Entities and €7,000,000 for Important Entities; or
- up to 2% for Essential Entities and 1.4% for Important Entities of the Entity’s total worldwide annual turnover in the preceding financial year,
whichever is higher.
(b) Failure by management to approve and supervise cybersecurity risk-management measures
Where management fails to comply with its obligation to approve cybersecurity risk-management measures and supervise their implementation—that is, where Article 14 §1 is infringed—a fine of up to €200,000 may be imposed.
(c) Failure to undertake or provide cybersecurity training
Where management fails to undertake cybersecurity training or to ensure that relevant training is provided to the Entity’s employees—that is, where Article 14 §2 is infringed—a fine of up to €100,000 may be imposed.
(d) Failure to register
Failure to register with the Register of Entities—that is, an infringement of Article 19—may result in a fine of up to €200,000.
(e) Failure to maintain a specific domain name registration database
Failure to maintain the specific domain name registration database required under Article 20 may result in a fine of up to €800,000.
(f) Failure to notify participation in an information-sharing arrangement
Failure to promptly notify the National Cybersecurity Authority of participation in, or withdrawal from, an information-sharing arrangement—that is, an infringement of Article 21 §3—may result in a fine of up to €100,000.
(g) Breach of supervisory measures imposed by the National Cybersecurity Authority
Where an Entity breaches measures imposed by the National Cybersecurity Authority in the exercise of its supervisory functions—that is, where Article 24 §§2 or 4 or Article 25 §2 is infringed—a fine of up to €500,000 for Essential Entities and €350,000 for Important Entities may be imposed.
(h) Failure to use required ICT products, services or processes
An infringement of the requirement to use specified ICT products, services or processes under Article 15 §6 may result in a fine of up to €300,000.
(i) Escalation of administrative fines
Where an Essential Entity breaches binding instructions or guidelines issued by the National Cybersecurity Authority, a fine of up to €1,000,000 may be imposed.
Where an Important Entity breaches binding instructions or orders requiring the remediation of identified deficiencies, a fine of up to €700,000 may be imposed (Article 26 §6).
The NIS2 Directive and its implementing legislation in Greece, Law 5160/2024, reflect a clear shift away from a narrowly technical approach to cybersecurity towards a comprehensive framework of corporate governance.
Supervision, the active involvement of senior management and the introduction of escalating penalties are interconnected elements of a framework designed to ensure a high level of resilience among Essential and Important Entities.
Compliance with this framework cannot be reduced to the formal fulfilment of individual obligations. It requires systematic organisation, continuous assessment and the development of a cybersecurity culture throughout every level of the Entity.
Managing Partner
Koumentakis and Associates Law Firm
Note: This article forms part of a broader series published by our Law Firm on NIS2. In this series, we examine the relevant European and Greek legislation, always from a business-oriented perspective.