{"id":48841,"date":"2026-03-22T12:00:18","date_gmt":"2026-03-22T10:00:18","guid":{"rendered":"https:\/\/koumentakislaw.gr\/articles\/odigia-nis2-efthyni-dioikisis-kyroseis\/"},"modified":"2026-09-27T21:53:51","modified_gmt":"2026-09-27T18:53:51","slug":"nis2-supervision-management-penalties","status":"publish","type":"post","link":"https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/","title":{"rendered":"NIS2 Directive: Supervision, Management Responsibility &#038; Penalties"},"content":{"rendered":"<p>The effective implementation of the NIS2 Directive, as transposed into Greek law by Law 5160\/2024, requires not only the establishment of substantive cybersecurity obligations but also an effective framework for supervision, accountability and enforcement.<\/p>\n<p>Within this framework, the role of senior management assumes particular importance. Cybersecurity must now be embedded at the core of the organisational and strategic operation of entities falling within the scope of NIS2. The potential penalties for non-compliance are far from insignificant.<\/p>\n<p><strong>Supervision<\/strong><\/p>\n<p>The supervisory regime applicable to Entities falling within the scope of the NIS2 Directive and its implementing legislation in Greece (Law 5160\/2024) differs according to whether they are classified as Essential or Important Entities.<\/p>\n<p>Essential Entities are subject to a comprehensive supervisory regime encompassing both preventive and reactive controls. Important Entities are subject to a simplified supervisory regime, which is activated only ex post.<\/p>\n<p>An <strong>ex ante supervisory regime<\/strong> refers to audits and supervision carried out periodically or on an ad hoc basis without a cybersecurity incident having occurred. An <strong>ex post supervisory regime<\/strong>, by contrast, refers to audits and supervision conducted following the occurrence of an incident.<\/p>\n<p>During ex ante and ex post audits, the Entity concerned must provide the relevant evidence, indications or information necessary to demonstrate its compliance with the applicable requirements, in accordance with the principle of accountability.<\/p>\n<p>The competent authority responsible for supervision, audits and the imposition of penalties under Law 5160\/2024 is the <strong>National Cybersecurity Authority<\/strong>, which has the necessary powers and means to exercise these responsibilities.<\/p>\n<p><strong>Responsibility &amp; Role of Senior Management<\/strong><\/p>\n<p>Senior management means any natural person who, as applicable, is responsible for or acts as the legal representative of the Entity by virtue of their authority to represent it, has the authority to take decisions on its behalf, or exercises control over it.<\/p>\n<p>The regulatory framework established by the NIS2 Directive, as transposed into Greek law, places particular emphasis on the obligations and accountability of senior management, effectively bringing cybersecurity into the boardroom.<\/p>\n<p>Compliance with the requirements of the legislation is no longer treated as a purely technical matter. It is a matter of management responsibility and corporate governance. Effective implementation and compliance therefore require senior management to adopt a strategic approach and actively participate in the design, implementation, supervision and evaluation of compliance measures.<\/p>\n<p>More specifically, the senior management of in-scope Entities, pursuant to Article 14 of Law 5160\/2024:<\/p>\n<p><strong>(a)<\/strong> approves the cybersecurity risk-management measures adopted by the Entity;<\/p>\n<p><strong>(b)<\/strong> oversees their implementation;<\/p>\n<p><strong>(c)<\/strong> undertakes training providing the knowledge and skills necessary to assess, adopt and monitor relevant decisions. This does not, of course, mean that members of senior management must become cybersecurity specialists. They must, however, possess sufficient knowledge to participate meaningfully in relevant discussions and make informed decisions;<\/p>\n<p><strong>(d)<\/strong> ensures that the Entity provides similar training to its employees on a regular basis, enabling them to acquire sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the Entity; and<\/p>\n<p><strong>(e)<\/strong> is accountable for breaches by the Entity of the obligations provided for in Article 14.<\/p>\n<p>These obligations of senior management are further specified in Article 4 of Joint Ministerial Decision 1689\/30.4.2025 (Government Gazette B\u0384 2186\/6.5.2025).<\/p>\n<p>There may be circumstances in which enforcement measures imposed by the National Cybersecurity Authority prove ineffective or the Entity fails to respond effectively within the prescribed period.<\/p>\n<p>In such cases, the Governor of the National Cybersecurity Authority has the power to temporarily prohibit any natural person responsible for discharging managerial responsibilities at chief executive officer or legal representative level within an Essential Entity from exercising managerial functions.<\/p>\n<p>Any temporary suspension or prohibition imposed applies only until the Entity concerned takes the necessary measures to remedy the deficiencies or comply with the requirements of the competent authority.<\/p>\n<p><strong>Information and Communication Systems Security Officer<\/strong><\/p>\n<p>As part of its organisational compliance obligations, senior management must appoint an employee of the Entity as its <strong>Information and Communication Systems Security Officer (ICSSO)<\/strong>, who:<\/p>\n<p><strong>(a)<\/strong> acts as the point of contact and cooperates with the National Cybersecurity Authority and the competent CSIRT;<\/p>\n<p><strong>(b)<\/strong> coordinates and oversees the Entity&#8217;s compliance with obligations arising under European and national legislation concerning the security of network and information systems;<\/p>\n<p><strong>(c)<\/strong> supervises the implementation of the Entity&#8217;s Unified Security Policy and compliance with the basic security requirements, as well as the training and awareness of employees on information and network security;<\/p>\n<p><strong>(d)<\/strong> prepares the Entity&#8217;s self-assessment report to be submitted to the National Cybersecurity Authority; and<\/p>\n<p><strong>(e)<\/strong> attends audits conducted by the Inspection and Audit Team appointed by the National Cybersecurity Authority and provides all appropriate means necessary to facilitate its work.<\/p>\n<p>As regards the qualifications and incompatibilities applicable to the ICSSO, pursuant to Ministerial Decision 1899\/27.6.2025 (Government Gazette B\u0384 4250\/5.8.2025), the following should be noted:<\/p>\n<p><strong>(a)<\/strong> The ICSSO must possess sufficient knowledge of the Entity&#8217;s business processes and satisfy at least one of the following minimum qualification requirements:<\/p>\n<ol>\n<li>an undergraduate degree or a postgraduate qualification of at least one year&#8217;s duration in a field related to information and network security or cybersecurity; or<\/li>\n<li>at least five years of expertise in information and network security or cybersecurity; or<\/li>\n<\/ol>\n<p><strong>iii.<\/strong> certified knowledge of methodologies, procedures, techniques, tools and standards relating to information and digital systems security, together with at least two years of expertise in information and network security or cybersecurity.<\/p>\n<p><strong>(b)<\/strong> A person may not be appointed as ICSSO where they have previously been irrevocably convicted of at least one of the offences referred to in Article 6 \u00a7\u00a71 and 2 of Law 5002\/2022 or Articles 292A\u2013293 and 370\u2013370F of the Greek Criminal Code. To demonstrate the absence of such an impediment, Entities must require the prospective ICSSO to provide a copy of their criminal record.<\/p>\n<p><strong>(c)<\/strong> The duties of the ICSSO are incompatible with those of the Data Protection Officer (DPO) under Article 37 of the General Data Protection Regulation and Articles 7 and 8 of Law 4624\/2019, as well as with those of the person responsible for the Entity&#8217;s information and communication technologies (ICT) and electronic governance functions.<\/p>\n<p>Finally, the ICSSO&#8217;s role within the organisational structure of the Entity must be independent and must not give rise to conflicts of interest with any other employment roles held by that person.<\/p>\n<p><strong>Penalties<\/strong><\/p>\n<p>The sanctions framework established by the NIS2 Directive, as further specified by Law 5160\/2024, is intended to ensure a high level of cybersecurity through proportionate, effective and dissuasive enforcement measures.<\/p>\n<p>Penalties vary according to the seriousness of the infringement and whether the Entity is classified as Essential or Important.<\/p>\n<p>In addition to specific administrative measures\u2014such as temporary suspensions and prohibitions under Article 24\u2014the following financial penalties may be imposed:<\/p>\n<p><strong>(a) Failure to implement cybersecurity risk-management measures or comply with incident-reporting obligations<\/strong><\/p>\n<p>Where an Entity fails to implement appropriate cybersecurity risk-management measures, implements inadequate measures, or breaches its security incident-reporting obligations\u2014that is, where Articles 15 or 16 are infringed\u2014a fine may be imposed of:<\/p>\n<ol>\n<li>up to <strong>\u20ac10,000,000 for Essential Entities<\/strong> and <strong>\u20ac7,000,000 for Important Entities<\/strong>; or<\/li>\n<li>up to <strong>2% for Essential Entities<\/strong> and <strong>1.4% for Important Entities<\/strong> of the Entity&#8217;s total worldwide annual turnover in the preceding financial year,<\/li>\n<\/ol>\n<p>whichever is higher.<\/p>\n<p><strong>(b) Failure by management to approve and supervise cybersecurity risk-management measures<\/strong><\/p>\n<p>Where management fails to comply with its obligation to approve cybersecurity risk-management measures and supervise their implementation\u2014that is, where Article 14 \u00a71 is infringed\u2014a fine of up to <strong>\u20ac200,000<\/strong> may be imposed.<\/p>\n<p><strong>(c) Failure to undertake or provide cybersecurity training<\/strong><\/p>\n<p>Where management fails to undertake cybersecurity training or to ensure that relevant training is provided to the Entity&#8217;s employees\u2014that is, where Article 14 \u00a72 is infringed\u2014a fine of up to <strong>\u20ac100,000<\/strong> may be imposed.<\/p>\n<p><strong>(d) Failure to register<\/strong><\/p>\n<p>Failure to register with the Register of Entities\u2014that is, an infringement of Article 19\u2014may result in a fine of up to <strong>\u20ac200,000<\/strong>.<\/p>\n<p><strong>(e) Failure to maintain a specific domain name registration database<\/strong><\/p>\n<p>Failure to maintain the specific domain name registration database required under Article 20 may result in a fine of up to <strong>\u20ac800,000<\/strong>.<\/p>\n<p><strong>(f) Failure to notify participation in an information-sharing arrangement<\/strong><\/p>\n<p>Failure to promptly notify the National Cybersecurity Authority of participation in, or withdrawal from, an information-sharing arrangement\u2014that is, an infringement of Article 21 \u00a73\u2014may result in a fine of up to <strong>\u20ac100,000<\/strong>.<\/p>\n<p><strong>(g) Breach of supervisory measures imposed by the National Cybersecurity Authority<\/strong><\/p>\n<p>Where an Entity breaches measures imposed by the National Cybersecurity Authority in the exercise of its supervisory functions\u2014that is, where Article 24 \u00a7\u00a72 or 4 or Article 25 \u00a72 is infringed\u2014a fine of up to <strong>\u20ac500,000 for Essential Entities<\/strong> and <strong>\u20ac350,000 for Important Entities<\/strong> may be imposed.<\/p>\n<p><strong>(h) Failure to use required ICT products, services or processes<\/strong><\/p>\n<p>An infringement of the requirement to use specified ICT products, services or processes under Article 15 \u00a76 may result in a fine of up to <strong>\u20ac300,000<\/strong>.<\/p>\n<p><strong>(i) Escalation of administrative fines<\/strong><\/p>\n<p>Where an Essential Entity breaches binding instructions or guidelines issued by the National Cybersecurity Authority, a fine of up to <strong>\u20ac1,000,000<\/strong> may be imposed.<\/p>\n<p>Where an Important Entity breaches binding instructions or orders requiring the remediation of identified deficiencies, a fine of up to <strong>\u20ac700,000<\/strong> may be imposed (Article 26 \u00a76).<\/p>\n<p>The NIS2 Directive and its implementing legislation in Greece, Law 5160\/2024, reflect a clear shift away from a narrowly technical approach to cybersecurity towards a comprehensive framework of corporate governance.<\/p>\n<p>Supervision, the active involvement of senior management and the introduction of escalating penalties are interconnected elements of a framework designed to ensure a high level of resilience among Essential and Important Entities.<\/p>\n<p>Compliance with this framework cannot be reduced to the formal fulfilment of individual obligations. It requires systematic organisation, continuous assessment and the development of a cybersecurity culture throughout every level of the Entity.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/koumentakislaw.gr\/en\/the-team\/stavros-koumentakis\/\">Stavros Koumentakis<\/a><\/p>\n<p>Managing Partner<\/p>\n<p>Koumentakis and Associates Law Firm<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Note:<\/strong> This article forms part of a broader series published by our Law Firm on NIS2. In this series, we examine the relevant European and Greek legislation, always from a business-oriented perspective.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The effective implementation of the NIS2 Directive, as transposed into Greek law by Law 5160\/2024, requires not only the establishment of substantive cybersecurity obligations but also an effective framework for supervision, accountability and enforcement. Within this framework, the role of senior management assumes particular importance. Cybersecurity must now be embedded at the core of the [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5],"tags":[110,1683,1687,1689,1690,1684,1685,1691,1173,1688,1681,1679,1680,1682,1686],"class_list":["post-48841","post","type-post","status-publish","format-standard","hentry","category-articles","tag-corporate-governance","tag-cybersecurity","tag-cybersecurity-governance","tag-cybersecurity-officer","tag-cybersecurity-risk-management","tag-essential-entities","tag-important-entities","tag-law-5160-2024","tag-management-liability","tag-national-cybersecurity-authority","tag-nis2-compliance","tag-nis2-directive","tag-nis2-management-responsibility","tag-nis2-penalties","tag-senior-management"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NIS2 Management Responsibility, Supervision &amp; Penalties - Koumentakis &amp; Associates<\/title>\n<meta name=\"description\" content=\"NIS2 management responsibility explained: senior management duties, cybersecurity supervision, security officer requirements and penalties under Greek Law 5160\/2024.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIS2 Management Responsibility, Supervision &amp; Penalties - Koumentakis &amp; Associates\" \/>\n<meta property=\"og:description\" content=\"NIS2 management responsibility explained: senior management duties, cybersecurity supervision, security officer requirements and penalties under Greek Law 5160\/2024.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/\" \/>\n<meta property=\"og:site_name\" content=\"Koumentakis &amp; Associates\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-22T10:00:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-27T18:53:51+00:00\" \/>\n<meta name=\"author\" content=\"\u03a3\u03c4\u03b1\u03cd\u03c1\u03bf\u03c2 \u039a\u03bf\u03c5\u03bc\u03b5\u03bd\u03c4\u03ac\u03ba\u03b7\u03c2\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Stavros Koumentakis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/articles\\\/nis2-supervision-management-penalties\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/articles\\\/nis2-supervision-management-penalties\\\/\"},\"author\":{\"name\":\"\u03a3\u03c4\u03b1\u03cd\u03c1\u03bf\u03c2 \u039a\u03bf\u03c5\u03bc\u03b5\u03bd\u03c4\u03ac\u03ba\u03b7\u03c2\",\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/#\\\/schema\\\/person\\\/b79f628f61af179023579e7abf7f98c0\"},\"headline\":\"NIS2 Directive: Supervision, Management Responsibility &#038; Penalties\",\"datePublished\":\"2026-03-22T10:00:18+00:00\",\"dateModified\":\"2026-09-27T18:53:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/articles\\\/nis2-supervision-management-penalties\\\/\"},\"wordCount\":1644,\"publisher\":{\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/#organization\"},\"keywords\":[\"corporate governance\",\"Cybersecurity\",\"Cybersecurity Governance\",\"Cybersecurity Officer\",\"Cybersecurity Risk Management\",\"Essential Entities\",\"Important Entities\",\"Law 5160\\\/2024\",\"Management Liability\",\"National Cybersecurity Authority\",\"NIS2 Compliance\",\"NIS2 Directive\",\"NIS2 Management Responsibility\",\"NIS2 Penalties\",\"Senior Management\"],\"articleSection\":[\"Articles\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/articles\\\/nis2-supervision-management-penalties\\\/\",\"url\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/articles\\\/nis2-supervision-management-penalties\\\/\",\"name\":\"NIS2 Management Responsibility, Supervision & Penalties - Koumentakis &amp; Associates\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/#website\"},\"datePublished\":\"2026-03-22T10:00:18+00:00\",\"dateModified\":\"2026-09-27T18:53:51+00:00\",\"description\":\"NIS2 management responsibility explained: senior management duties, cybersecurity supervision, security officer requirements and penalties under Greek Law 5160\\\/2024.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/articles\\\/nis2-supervision-management-penalties\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/articles\\\/nis2-supervision-management-penalties\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/articles\\\/nis2-supervision-management-penalties\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u0391\u03c1\u03c7\u03b9\u03ba\u03ae\",\"item\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NIS2 Directive: Supervision, Management Responsibility &#038; Penalties\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/\",\"name\":\"\u039a\u039f\u03a5\u039c\u0395\u039d\u03a4\u0391\u039a\u0397\u03a3 & \u03a3\u03a5\u039d\u0395\u03a1\u0393\u0391\u03a4\u0395\u03a3 \u0394\u03b9\u03ba\u03b7\u03b3\u03bf\u03c1\u03b9\u03ba\u03ae \u0395\u03c4\u03b1\u03b9\u03c1\u03b5\u03af\u03b1\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/#organization\",\"name\":\"\u039a\u039f\u03a5\u039c\u0395\u039d\u03a4\u0391\u039a\u0397\u03a3 & \u03a3\u03a5\u039d\u0395\u03a1\u0393\u0391\u03a4\u0395\u03a3 \u0394\u03b9\u03ba\u03b7\u03b3\u03bf\u03c1\u03b9\u03ba\u03ae \u0395\u03c4\u03b1\u03b9\u03c1\u03b5\u03af\u03b1\",\"url\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/koumentakislaw.gr\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/KOUMENTAKIS-ASSOCIATES.svg\",\"contentUrl\":\"https:\\\/\\\/koumentakislaw.gr\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/KOUMENTAKIS-ASSOCIATES.svg\",\"caption\":\"\u039a\u039f\u03a5\u039c\u0395\u039d\u03a4\u0391\u039a\u0397\u03a3 & \u03a3\u03a5\u039d\u0395\u03a1\u0393\u0391\u03a4\u0395\u03a3 \u0394\u03b9\u03ba\u03b7\u03b3\u03bf\u03c1\u03b9\u03ba\u03ae \u0395\u03c4\u03b1\u03b9\u03c1\u03b5\u03af\u03b1\"},\"image\":{\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/#\\\/schema\\\/person\\\/b79f628f61af179023579e7abf7f98c0\",\"name\":\"\u03a3\u03c4\u03b1\u03cd\u03c1\u03bf\u03c2 \u039a\u03bf\u03c5\u03bc\u03b5\u03bd\u03c4\u03ac\u03ba\u03b7\u03c2\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54d2ae0b1c284cc764f4a0f758e8333d1a47d6b2fc21b1c454f9964f907354ea?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54d2ae0b1c284cc764f4a0f758e8333d1a47d6b2fc21b1c454f9964f907354ea?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54d2ae0b1c284cc764f4a0f758e8333d1a47d6b2fc21b1c454f9964f907354ea?s=96&d=mm&r=g\",\"caption\":\"\u03a3\u03c4\u03b1\u03cd\u03c1\u03bf\u03c2 \u039a\u03bf\u03c5\u03bc\u03b5\u03bd\u03c4\u03ac\u03ba\u03b7\u03c2\"},\"url\":\"https:\\\/\\\/koumentakislaw.gr\\\/en\\\/author\\\/skoumentakis\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NIS2 Management Responsibility, Supervision & Penalties - Koumentakis &amp; Associates","description":"NIS2 management responsibility explained: senior management duties, cybersecurity supervision, security officer requirements and penalties under Greek Law 5160\/2024.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/","og_locale":"en_US","og_type":"article","og_title":"NIS2 Management Responsibility, Supervision & Penalties - Koumentakis &amp; Associates","og_description":"NIS2 management responsibility explained: senior management duties, cybersecurity supervision, security officer requirements and penalties under Greek Law 5160\/2024.","og_url":"https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/","og_site_name":"Koumentakis &amp; Associates","article_published_time":"2026-03-22T10:00:18+00:00","article_modified_time":"2026-09-27T18:53:51+00:00","author":"\u03a3\u03c4\u03b1\u03cd\u03c1\u03bf\u03c2 \u039a\u03bf\u03c5\u03bc\u03b5\u03bd\u03c4\u03ac\u03ba\u03b7\u03c2","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Stavros Koumentakis","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/#article","isPartOf":{"@id":"https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/"},"author":{"name":"\u03a3\u03c4\u03b1\u03cd\u03c1\u03bf\u03c2 \u039a\u03bf\u03c5\u03bc\u03b5\u03bd\u03c4\u03ac\u03ba\u03b7\u03c2","@id":"https:\/\/koumentakislaw.gr\/en\/#\/schema\/person\/b79f628f61af179023579e7abf7f98c0"},"headline":"NIS2 Directive: Supervision, Management Responsibility &#038; Penalties","datePublished":"2026-03-22T10:00:18+00:00","dateModified":"2026-09-27T18:53:51+00:00","mainEntityOfPage":{"@id":"https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/"},"wordCount":1644,"publisher":{"@id":"https:\/\/koumentakislaw.gr\/en\/#organization"},"keywords":["corporate governance","Cybersecurity","Cybersecurity Governance","Cybersecurity Officer","Cybersecurity Risk Management","Essential Entities","Important Entities","Law 5160\/2024","Management Liability","National Cybersecurity Authority","NIS2 Compliance","NIS2 Directive","NIS2 Management Responsibility","NIS2 Penalties","Senior Management"],"articleSection":["Articles"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/","url":"https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/","name":"NIS2 Management Responsibility, Supervision & Penalties - Koumentakis &amp; Associates","isPartOf":{"@id":"https:\/\/koumentakislaw.gr\/en\/#website"},"datePublished":"2026-03-22T10:00:18+00:00","dateModified":"2026-09-27T18:53:51+00:00","description":"NIS2 management responsibility explained: senior management duties, cybersecurity supervision, security officer requirements and penalties under Greek Law 5160\/2024.","breadcrumb":{"@id":"https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/koumentakislaw.gr\/en\/articles\/nis2-supervision-management-penalties\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u0391\u03c1\u03c7\u03b9\u03ba\u03ae","item":"https:\/\/koumentakislaw.gr\/en\/"},{"@type":"ListItem","position":2,"name":"NIS2 Directive: Supervision, Management Responsibility &#038; Penalties"}]},{"@type":"WebSite","@id":"https:\/\/koumentakislaw.gr\/en\/#website","url":"https:\/\/koumentakislaw.gr\/en\/","name":"\u039a\u039f\u03a5\u039c\u0395\u039d\u03a4\u0391\u039a\u0397\u03a3 & \u03a3\u03a5\u039d\u0395\u03a1\u0393\u0391\u03a4\u0395\u03a3 \u0394\u03b9\u03ba\u03b7\u03b3\u03bf\u03c1\u03b9\u03ba\u03ae \u0395\u03c4\u03b1\u03b9\u03c1\u03b5\u03af\u03b1","description":"","publisher":{"@id":"https:\/\/koumentakislaw.gr\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/koumentakislaw.gr\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/koumentakislaw.gr\/en\/#organization","name":"\u039a\u039f\u03a5\u039c\u0395\u039d\u03a4\u0391\u039a\u0397\u03a3 & \u03a3\u03a5\u039d\u0395\u03a1\u0393\u0391\u03a4\u0395\u03a3 \u0394\u03b9\u03ba\u03b7\u03b3\u03bf\u03c1\u03b9\u03ba\u03ae \u0395\u03c4\u03b1\u03b9\u03c1\u03b5\u03af\u03b1","url":"https:\/\/koumentakislaw.gr\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/koumentakislaw.gr\/en\/#\/schema\/logo\/image\/","url":"https:\/\/koumentakislaw.gr\/wp-content\/uploads\/2026\/06\/KOUMENTAKIS-ASSOCIATES.svg","contentUrl":"https:\/\/koumentakislaw.gr\/wp-content\/uploads\/2026\/06\/KOUMENTAKIS-ASSOCIATES.svg","caption":"\u039a\u039f\u03a5\u039c\u0395\u039d\u03a4\u0391\u039a\u0397\u03a3 & \u03a3\u03a5\u039d\u0395\u03a1\u0393\u0391\u03a4\u0395\u03a3 \u0394\u03b9\u03ba\u03b7\u03b3\u03bf\u03c1\u03b9\u03ba\u03ae \u0395\u03c4\u03b1\u03b9\u03c1\u03b5\u03af\u03b1"},"image":{"@id":"https:\/\/koumentakislaw.gr\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/koumentakislaw.gr\/en\/#\/schema\/person\/b79f628f61af179023579e7abf7f98c0","name":"\u03a3\u03c4\u03b1\u03cd\u03c1\u03bf\u03c2 \u039a\u03bf\u03c5\u03bc\u03b5\u03bd\u03c4\u03ac\u03ba\u03b7\u03c2","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/54d2ae0b1c284cc764f4a0f758e8333d1a47d6b2fc21b1c454f9964f907354ea?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54d2ae0b1c284cc764f4a0f758e8333d1a47d6b2fc21b1c454f9964f907354ea?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54d2ae0b1c284cc764f4a0f758e8333d1a47d6b2fc21b1c454f9964f907354ea?s=96&d=mm&r=g","caption":"\u03a3\u03c4\u03b1\u03cd\u03c1\u03bf\u03c2 \u039a\u03bf\u03c5\u03bc\u03b5\u03bd\u03c4\u03ac\u03ba\u03b7\u03c2"},"url":"https:\/\/koumentakislaw.gr\/en\/author\/skoumentakis\/"}]}},"_links":{"self":[{"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/posts\/48841","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/comments?post=48841"}],"version-history":[{"count":3,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/posts\/48841\/revisions"}],"predecessor-version":[{"id":48898,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/posts\/48841\/revisions\/48898"}],"wp:attachment":[{"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/media?parent=48841"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/categories?post=48841"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/tags?post=48841"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}