Who must comply with NIS2 in Greece
Published:
Short answer: NIS2 generally applies to medium-sized and large businesses and organisations that operate in specific sectors, such as energy, transport, health, digital infrastructure, managed service providers, food and manufacturing. Small and micro businesses are excluded, with a few exceptions. Below you can see how each case is assessed.
What NIS2 is
NIS2 is Directive (EU) 2022/2555 on a high common level of cybersecurity across the European Union. In Greece it was transposed by Law 5160/2024 (Government Gazette A 195/27.11.2024) and is supervised by the National Cybersecurity Authority. It requires in-scope entities to apply risk-management measures, report significant incidents and hold management accountable for security.
The specific measures that entities must apply in Greece are set out in Joint Ministerial Decision 1689/2025 (Government Gazette B 2186/06.05.2025), the "National Cybersecurity Requirements Framework for Essential and Important Entities" under Law 5160/2024.
Step 1: your sector
The Directive defines two lists of sectors. The first is the sectors of high criticality (Annex I):
- Energy, transport, banking and financial market infrastructure
- Health, drinking water and waste water
- Digital infrastructure: cloud, data centres, DNS, providers of electronic communications and trust services
- ICT service management for businesses: managed service and managed security service providers
- Public administration and space
The second is the other critical sectors (Annex II):
- Postal and courier services, waste management, chemicals
- Food: industrial production, processing and wholesale distribution
- Manufacturing: medical devices, electronics and optics, electrical equipment, machinery, vehicles
- Digital providers: online marketplaces, search engines, social networking platforms
- Research
Retail, hotels, accounting firms and general services are not included as sectors. A simple online shop selling its own products is usually not an "online marketplace" within the meaning of the Directive.
Step 2: your size
Size is assessed with the criteria of Recommendation 2003/361/EC. If you belong to a group, linked enterprises are counted as well.
| Category | Employees | Financial figures |
|---|---|---|
| Small or micro | Fewer than 50 | Turnover or balance sheet up to €10M |
| Medium-sized | Fewer than 250 | Turnover up to €50M or balance sheet up to €43M |
| Large | 250 or more | Or turnover over €50M and balance sheet over €43M |
Exceptions: in scope regardless of size
Some types of entity are in scope even if they are small:
- Qualified trust service providers, top-level domain (TLD) name registries and DNS service providers, which are always essential entities
- Providers of public electronic communications networks or services and non-qualified trust service providers
- Central government public administration
- The sole provider in the country of an essential service, or an entity whose disruption would significantly affect public safety
Essential or important entity
When you are in scope, you fall into one of two categories. The obligations are essentially the same, but supervision and fines differ.
| Category | Who | Maximum fine (Directive) |
|---|---|---|
| Essential | Large Annex I entities and certain types regardless of size | Up to €10M or 2% of worldwide annual turnover |
| Important | Medium-sized Annex I entities, medium-sized and large Annex II entities | Up to €7M or 1.4% of worldwide annual turnover |
The higher amount applies. The exact amounts and procedure are set by Law 5160/2024. Essential entities are supervised more strictly.
If you are not directly in scope
That does not mean it does not concern you. Your customers that are in scope must manage the security of their suppliers and may ask you for specific measures, such as multi-factor authentication, backups and staff training. In addition, the National Cybersecurity Authority may bring other entities into scope.
What to do now
- Check whether you are in scope, with our free tool. In four questions you see whether and as what.
- If you are in scope, assess your gaps against the Article 21 measures and the national framework of Decision 1689/2025, and register in the Entity Registry of the National Cybersecurity Authority.
- Set up an incident reporting procedure: early warning within 24 hours, notification within 72 hours and a final report within one month.
Frequently asked questions
Does a small business fall under NIS2?
As a rule, no. Small and micro businesses are excluded, apart from certain types of entity that are in scope regardless of size. They may, however, be asked for equivalent measures by customers that are in scope.
Does a hotel or an accounting firm fall under NIS2?
These sectors are not listed in Annexes I and II of the Directive. They may, however, have customers or partners that are in scope and who may ask them for security measures.
What is Decision 1689/2025?
It is Joint Ministerial Decision 1689/2025 (Government Gazette B 2186/06.05.2025), which establishes the National Cybersecurity Requirements Framework for Essential and Important Entities under Law 5160/2024, that is, the cybersecurity risk-management measures that in-scope entities must apply.
Where can I check whether I am in scope?
You can use ITHACA's free eligibility check. The result is indicative. The final decision rests with the National Cybersecurity Authority.