Greece completed its NIS2 transposition through Law 5160/2024 (Ν. 5160/2024), «Ενσωμάτωση της Οδηγίας (ΕΕ) 2022/2555 ... (Οδηγία NIS 2) και άλλες διατάξεις» (Incorporation of Directive (EU) 2022/2555 ...
(NIS 2 Directive) and other provisions), published in the Government Gazette as FEK A' 195 of 27 November 2024 and in force from that same publication date under the law's own Article 45(1), with a one-year delay under Article 45(2) for a single narrow subprovision (Article 3(2)(στ)(στβ)) that is outside this topic's scope.
Chapter Δ' binds an essential or an important entity drawn from Annex I (high-criticality sectors) or Annex II (other critical sectors), each captioned in the law's own table of contents as corresponding directly to the Directive's own Annex I and Annex II, at the medium-enterprise threshold of Commission Recommendation 2003/361/EC or above (Article 3(1)), with trust service providers, top-level-domain registries and DNS service providers bound regardless of size (Article 4(1)(β)).
Article 14 requires the entity's management body to approve its cybersecurity risk-management measures within three months of the law's entry into force, supervise their implementation, and take annual cybersecurity training; Article 15 requires appropriate and proportionate technical, operational and organisational measures covering, at minimum, risk analysis and information-system security policy, incident handling, business continuity, supply-chain security, security in system acquisition and maintenance including vulnerability handling and disclosure, effectiveness-assessment policy, basic cyber hygiene and training, cryptography policy, personnel and access-management security and asset management, and multi-factor or continuous authentication and secure communications.
Article 16 sets a graduated significant-incident notification clock to the CSIRT of the National Cybersecurity Authority (Εθνική Αρχή Κυβερνοασφάλειας, EAK): a 24-hour early warning, a 72-hour incident notification, an interim report on request, and a final report within one month of the 72-hour notification (or a progress report plus a final report within one month of resolution for an incident still ongoing at that point).
Article 26 caps the administrative fine for an Article 15 or 16 violation at EUR 10,000,000 or 2% of worldwide annual turnover for an essential entity, and EUR 7,000,000 or 1.4% for an important entity, whichever is higher in each case, with smaller fixed caps for narrower violations (paragraphs 6, 8 and 9); no provision in Articles 15, 16 or 26 makes the infringement itself a criminal offence.
The EAK, established by Law 5086/2024 (FEK A' 23/14.02.2024), is the competent authority for supervision and enforcement here and, per legal commentary not confirmed against Law 5086/2024's own text, also coordinates Greece's market-surveillance role under the directly applicable EU Cyber Resilience Act, which is documented at the European Union level and is not restated here.
Where a significant incident under Articles 15 or 16 also amounts to a personal-data breach, Article 27 (transposing NIS2 Article 35) brings in the Hellenic Data Protection Authority; that breach-notification duty itself sits in the privacy topic under General Data Protection Regulation (GDPR) Articles 33-34 and Law 4624/2019, not here. The Greek Penal Code's computer-intrusion offences (Articles 370B, 370C and 370D) bind the intruder rather than the operator or manufacturer and already sit in the scraping topic, not here.
No instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the Cyber Resilience Act.