IT security intelligence. Since 2006.Cloudflare services
TRUST-IT / Published article

NIS2 compliance in Greece: a readiness guide

Reviewing risk assessments and security controls
About 5 min read

Build a NIS2 readiness programme for Greece around scope, accountable owners, tested controls and incident reporting. Start with evidence, not a checklist.

Establish scope before buying controls

Greece transposed NIS2 through Law 5160/2024. Determine which legal entities and services fall within scope, considering the sector, size rules, exceptions and applicable national requirements. Record the reasoning and obtain appropriate legal input where classification is uncertain. A supplier may also face contractual security obligations even when it is not directly regulated. Do not infer scope from employee count alone.

Risk adviser mapping essential business services for a medium sized industrial company.
Risk adviser mapping essential business services for a medium sized industrial company.

Turn requirements into an evidence register

For each applicable requirement, record the accountable owner, affected systems, current control, evidence location and unresolved gap. Separate a written policy from proof that a control operates. For example, a backup policy does not demonstrate recovery: retain the restore test, measured duration, missing dependencies and corrective actions. Give management a prioritised view of business interruption, exposure and the decisions requiring funding.

Management committee reviewing cyber accountability and response responsibilities in a modest boardroom.
Management committee reviewing cyber accountability and response responsibilities in a modest boardroom.

Test the paths that could interrupt essential services

Map critical services to identities, applications, infrastructure and suppliers. Examine administrative access, remote support, segmentation, patching and recovery dependencies. A controlled assessment should use an agreed scope, operational safeguards and a rollback plan. Prioritise findings by plausible business impact and exposure rather than severity labels alone. Retest the remediation and retain the results alongside the original finding.

Engineer implementing network segmentation with neatly separated patch cables and a deployment checklist.
Engineer implementing network segmentation with neatly separated patch cables and a deployment checklist.

Rehearse incident reporting and escalation

The Greek National Cybersecurity Authority provides reporting routes for significant incidents, including the early warning within 24 hours and the notification within 72 hours of awareness, subject to the applicable rules. Define who evaluates significance, who approves submission and who acts when the primary contact is unavailable. Record when the organisation became aware, what is confirmed and what remains uncertain. Consult the authority’s current instructions for follow-up and final reports; reporting to a customer or insurer does not replace a regulatory submission.

Make the programme repeatable

Use an initial assessment to agree scope, establish the evidence register and sequence remediation. Then exercise a realistic incident, test recovery and review supplier access. Assign a review cadence to changes in services, ownership and architecture. NIS2 readiness is an ongoing governance and security programme; purchasing a product or holding an ISO certificate does not by itself establish compliance. TRUST-IT can support assessment, technical validation and remediation planning within an agreed engagement.

Build a working readiness register

Use one register to connect each applicable requirement or control objective to an accountable owner, an affected service, evidence and the next decision. A policy document is evidence of an intended approach; it does not by itself show that access is reviewed, backups restore or suppliers meet the agreed expectations. Record a test or operating record where effectiveness matters.

The examples below are a starting structure for an assessment, not an exhaustive statement of NIS2 obligations or a certification checklist. Confirm applicability and current Greek requirements with the responsible legal and compliance advisers. Mark an item not applicable only with a recorded rationale and approval; missing evidence should remain visible as a gap.

On a small screen, scroll the table sideways to compare all columns.

Build a working readiness register
Workstream and example ownerEvidence to requestGap to resolve
Governance — management sponsorApproved scope, decision responsibilities, risk priorities and review minutes.Unclear accountability or risks without an explicit decision.
Assets and access — IT / service ownersCritical-service dependencies, privileged access reviews and joiner/leaver records.Unowned systems, stale privileges or unmanaged remote access.
Incidents — response leadEscalation plan, current authority contacts and exercise observations.No tested route to assess significance and coordinate reporting.
Continuity — operations / recovery ownerRestore-test records, recovery dependencies and lessons from exercises.Backups exist but recovery objectives have not been demonstrated.
Suppliers — procurement / service ownerCritical-provider inventory, assurance evidence and incident-notification arrangements.A critical dependency has no accountable owner or agreed escalation.
Effectiveness — security / assurance ownerVulnerability follow-up, selected control tests and remediation verification.Findings are closed administratively without evidence of correction.

Separate assessment, remediation and ongoing assurance

  1. Assess

    Confirm scope, inventory the evidence and identify uncertainties.

  2. Prioritise

    Assign owners, dependencies, effort and management decisions.

  3. Remediate

    Implement the agreed changes and preserve completion evidence.

  4. Verify

    Retest material gaps and record residual risk acceptance.

  5. Maintain

    Review changes, exercise response and refresh evidence.

What management should receive

The assessment brief should show the services at risk, material gaps, missing evidence and the decisions required from management. A remediation plan should name the owner, expected evidence, dependency and acceptance criterion for each action. Ongoing assurance should focus on whether controls still work after changes, not simply repeat the original document inventory.

For incident readiness, exercise the decision process as well as the technical response. Record when the organisation became aware of an event, how significance was assessed, who can approve communications and how information will be updated as facts develop. Use the current National Cybersecurity Authority reporting process and coordinate any separate obligations with the responsible advisers.

What’s your next
technology challenge?

TRUST-IT / FIND YOUR NEXT STEP

How can we help?

Popular topics

Search the public TRUST-IT website.

    TRUST-IT · AI assistant
    TRUST-IT

    How can we help?

    Explore our services, ask a question or tell us what you need. You will be speaking with our AI assistant.

    When you continue, Ultimo-Bots loads the chat. Your name, email and conversation are recorded so TRUST-IT can respond, and our team receives enquiry notifications. Phone, company and role are optional.

    Please do not share passwords, evidence files or sensitive information.

    Read our privacy notice

    Prefer to speak with our team? Contact TRUST-IT