Get in touch
NIS2 compliance

NIS2: is your business in scope and what to do about it

NIS2 is the EU cybersecurity directive. In Greece it applies through Law 5160/2024. We help you understand whether it concerns you and how to comply without unnecessary paperwork.

Directive (EU) 2022/2555 requires in-scope entities to apply risk-management measures, report significant incidents and hold management accountable for security. Many small businesses are not directly in scope, but their customers may ask them for equivalent measures.

Start with our free tool: in four questions you see whether you are in scope and as an essential or important entity.

NIS2 eligibility check
What is included
  • Eligibility check and classification as essential or important entity
  • Gap assessment against the Article 21 measures and the national framework of Decision 1689/2025
  • Action plan, policies and documentation
  • Incident reporting procedure (24 hours, 72 hours, 1 month)
  • Support with registration in the National Cybersecurity Authority entity registry
  • Briefing and training for management

Frequently asked questions

What is the NIS2 Directive?

NIS2 is the EU Directive (EU) 2022/2555 on a high common level of cybersecurity across the Union. In Greece it was transposed by Law 5160/2024 (Government Gazette A 195/2024) and is supervised by the National Cybersecurity Authority.

Which businesses fall under NIS2?

As a rule, medium-sized and large entities operating in the sectors of Annexes I and II of the Directive, such as energy, transport, health, digital infrastructure, managed service providers, food and manufacturing. Some types of entities are in scope regardless of size. Small and micro businesses are generally excluded.

What is Decision 1689/2025?

It is Joint Ministerial Decision 1689/2025 (Government Gazette B 2186/06.05.2025), which establishes the National Cybersecurity Requirements Framework for Essential and Important Entities under Law 5160/2024, that is, the cybersecurity risk-management measures that in-scope entities must apply.

What is the difference between essential and important entities?

Essential entities are mainly large entities in Annex I sectors and face stricter supervision. Important entities are medium-sized Annex I entities and medium-sized and large Annex II entities. The Directive sets maximum fines of up to EUR 10 million or 2% of worldwide annual turnover for essential entities and up to EUR 7 million or 1.4% for important entities; the exact amounts are set by Law 5160/2024.

How quickly must a security incident be reported?

Under Article 23 of the Directive, an early warning is due within 24 hours, an incident notification within 72 hours and a final report within one month.

How does a business register as an essential or important entity?

Registration is done in the Entity Registry of the National Cybersecurity Authority through the Authority's digital platform. ITHACA offers a free online eligibility check to see whether and as what type of entity you are in scope.