Build a NIS2 readiness programme for Greece around scope, accountable owners, tested controls and incident reporting. Start with evidence, not a checklist.
Establish scope before buying controls
Greece transposed NIS2 through Law 5160/2024. Determine which legal entities and services fall within scope, considering the sector, size rules, exceptions and applicable national requirements. Record the reasoning and obtain appropriate legal input where classification is uncertain. A supplier may also face contractual security obligations even when it is not directly regulated. Do not infer scope from employee count alone.

Turn requirements into an evidence register
For each applicable requirement, record the accountable owner, affected systems, current control, evidence location and unresolved gap. Separate a written policy from proof that a control operates. For example, a backup policy does not demonstrate recovery: retain the restore test, measured duration, missing dependencies and corrective actions. Give management a prioritised view of business interruption, exposure and the decisions requiring funding.

Test the paths that could interrupt essential services
Map critical services to identities, applications, infrastructure and suppliers. Examine administrative access, remote support, segmentation, patching and recovery dependencies. A controlled assessment should use an agreed scope, operational safeguards and a rollback plan. Prioritise findings by plausible business impact and exposure rather than severity labels alone. Retest the remediation and retain the results alongside the original finding.

Rehearse incident reporting and escalation
The Greek National Cybersecurity Authority provides reporting routes for significant incidents, including the early warning within 24 hours and the notification within 72 hours of awareness, subject to the applicable rules. Define who evaluates significance, who approves submission and who acts when the primary contact is unavailable. Record when the organisation became aware, what is confirmed and what remains uncertain. Consult the authority’s current instructions for follow-up and final reports; reporting to a customer or insurer does not replace a regulatory submission.
Make the programme repeatable
Use an initial assessment to agree scope, establish the evidence register and sequence remediation. Then exercise a realistic incident, test recovery and review supplier access. Assign a review cadence to changes in services, ownership and architecture. NIS2 readiness is an ongoing governance and security programme; purchasing a product or holding an ISO certificate does not by itself establish compliance. TRUST-IT can support assessment, technical validation and remediation planning within an agreed engagement.
Build a working readiness register
Use one register to connect each applicable requirement or control objective to an accountable owner, an affected service, evidence and the next decision. A policy document is evidence of an intended approach; it does not by itself show that access is reviewed, backups restore or suppliers meet the agreed expectations. Record a test or operating record where effectiveness matters.
The examples below are a starting structure for an assessment, not an exhaustive statement of NIS2 obligations or a certification checklist. Confirm applicability and current Greek requirements with the responsible legal and compliance advisers. Mark an item not applicable only with a recorded rationale and approval; missing evidence should remain visible as a gap.
On a small screen, scroll the table sideways to compare all columns.
| Workstream and example owner | Evidence to request | Gap to resolve |
|---|---|---|
| Governance — management sponsor | Approved scope, decision responsibilities, risk priorities and review minutes. | Unclear accountability or risks without an explicit decision. |
| Assets and access — IT / service owners | Critical-service dependencies, privileged access reviews and joiner/leaver records. | Unowned systems, stale privileges or unmanaged remote access. |
| Incidents — response lead | Escalation plan, current authority contacts and exercise observations. | No tested route to assess significance and coordinate reporting. |
| Continuity — operations / recovery owner | Restore-test records, recovery dependencies and lessons from exercises. | Backups exist but recovery objectives have not been demonstrated. |
| Suppliers — procurement / service owner | Critical-provider inventory, assurance evidence and incident-notification arrangements. | A critical dependency has no accountable owner or agreed escalation. |
| Effectiveness — security / assurance owner | Vulnerability follow-up, selected control tests and remediation verification. | Findings are closed administratively without evidence of correction. |
Separate assessment, remediation and ongoing assurance
- Assess
Confirm scope, inventory the evidence and identify uncertainties.
- Prioritise
Assign owners, dependencies, effort and management decisions.
- Remediate
Implement the agreed changes and preserve completion evidence.
- Verify
Retest material gaps and record residual risk acceptance.
- Maintain
Review changes, exercise response and refresh evidence.
What management should receive
The assessment brief should show the services at risk, material gaps, missing evidence and the decisions required from management. A remediation plan should name the owner, expected evidence, dependency and acceptance criterion for each action. Ongoing assurance should focus on whether controls still work after changes, not simply repeat the original document inventory.
For incident readiness, exercise the decision process as well as the technical response. Record when the organisation became aware of an event, how significance was assessed, who can approve communications and how information will be updated as facts develop. Use the current National Cybersecurity Authority reporting process and coordinate any separate obligations with the responsible advisers.
