On 20 January 2026, the European Commission proposed targeted amendments to the NIS2 Directive as part of a broader cybersecurity simplification package. The proposal arrived alongside the Digital Omnibus Package — a separate but related initiative aimed at streamlining reporting obligations across multiple EU frameworks. Most commentary since has focused on the technical and procedural changes at the EU level. That is useful, but insufficient for anyone actually running a business in Greece and trying to understand what they need to do differently.
This article focuses on the practical implications — specifically for Greek SMEs that are already navigating compliance with Law 5160/2024, Greece's transposition of NIS2, and the implementing measures that followed it. The amendments are genuinely positive. They are also proposals, not law. The distinction matters more than most analysis acknowledges.
What Actually Changed
The January 2026 proposal introduces several meaningful adjustments to NIS2's scope, supervision model, and technical requirements. Some of these will materially affect how Greek organisations experience compliance. Others are forward-looking commitments that won't produce operational changes for years.
The most immediately relevant change is the introduction of a "small mid-cap" category. Entities with fewer than 750 employees and annual turnover not exceeding €150 million would be classified as "important" rather than "essential," regardless of the sector they operate in. This matters because the supervision regime for important entities is reactive — authorities investigate after an incident or report — rather than the proactive audits and inspections that essential entities face. For a mid-sized Greek company that currently falls into the essential category purely because of its sector classification, this reclassification could significantly reduce the regulatory burden.
The scope adjustments are surgical rather than sweeping:
- Micro and small DNS service providers are excluded from scope entirely — a recognition that applying the full NIS2 framework to a two-person DNS operation was disproportionate
- Electricity producers with generation capacity under 1 MW are excluded
- Chemical distribution — previously captured under the manufacturing of chemicals sector — has been removed from scope
- Submarine cable operators and EU Digital Identity Wallet providers are brought into scope, with wallet providers classified as essential regardless of their size
More structurally significant is the harmonisation ceiling. Once the European Commission adopts implementing acts specifying cybersecurity risk-management measures for a given sector, Member States will be prohibited from imposing additional national requirements on top. This is explicitly designed to eliminate "gold-plating" — the practice of individual countries layering extra obligations onto EU baseline requirements. For organisations operating across multiple EU jurisdictions, this is substantial. For those operating solely in Greece, it provides assurance that compliance with the EU baseline will be sufficient, without the risk of Greece introducing additional mandates later.
The proposal also introduces an EU cyber-posture certificate. Entities holding a valid certification under the EU Cybersecurity Certification Framework would be exempt from additional NIS2 security requirement audits in the areas covered by the certificate. The intent is clear: avoid subjecting organisations to redundant assessments when they have already demonstrated compliance through a recognised certification scheme. The practical value will depend entirely on which certification schemes the Commission recognises and how broadly they map to NIS2's requirement categories — details that remain to be defined.
Two forward-looking provisions deserve mention even though their operational impact is years away. First, the amendments establish post-quantum cryptography transition timelines: 2030 for critical use cases and 2035 for medium and low-risk applications. These dates are aspirational anchors rather than immediate compliance triggers, but they signal clearly that organisations should be factoring quantum readiness into their technology roadmaps now. Second, supply chain security receives enhanced treatment through EU-level coordinated risk assessments of critical ICT supply chains, standardised supplier security questionnaires, and — notably — authority for regulators to prohibit the use of components from suppliers deemed to pose unacceptable security risks.
Finally, ransomware incident reporting has been standardised. Reports must now include attack vector details, ransom demands received, and — if applicable — payment information. This is less about changing what organisations do during an incident and more about giving authorities and ENISA a consistent dataset for understanding the ransomware landscape across the Union.
The "Report Once, Share Many" Promise
Alongside the NIS2 amendments, the Digital Omnibus Package proposes what the Commission calls a "Single Entry Point" for incident reporting. Operated by ENISA, this portal would allow organisations to submit one incident report that is then automatically routed to all relevant national authorities across multiple regulatory frameworks — NIS2, GDPR, DORA, the Critical Entities Resilience Directive, and eIDAS.
On paper, this is exactly what regulated organisations have been asking for. The reality of a financial services firm that suffers a data breach involving personal data and service disruption is that they currently need to file separate reports to their NIS2 authority, their data protection authority, and their DORA supervisor — each with different formats, different timelines, and different submission mechanisms. A single portal that accepts one submission and handles the routing is a genuine improvement.
There are, however, several qualifications that the headlines tend to omit.
The underlying reporting requirements are not being harmonised. Each framework retains its own timelines and content expectations. NIS2 requires a 24-hour early warning. DORA demands an initial report within 4 hours. The GDPR's breach notification window — currently 72 hours — is proposed to extend to 96 hours under the Omnibus amendments. The Single Entry Point simplifies submission, not substance. You still need to understand which frameworks apply to your organisation, what each one requires, and how to meet each set of obligations within its specific timeframe.
The timeline for the SEP becoming operational is also worth examining honestly. The Digital Omnibus Package is a legislative proposal. It requires negotiation and adoption through the ordinary legislative procedure — trilogue between the Commission, Parliament, and Council. Optimistic estimates place political agreement in the second half of 2027. ENISA would then need to build, test, and deploy the portal, with an estimated 18 to 24 months for technical implementation. A realistic operational date is late 2028 at the earliest, with 2029 more probable.
None of this diminishes the value of the proposal. It is a meaningful step toward reducing reporting friction for multi-regulated entities. But organisations making compliance decisions today should plan on the basis of current reporting channels and timelines, not on a portal that is still in the proposal stage.
Where Greece Stands
Greece is among the more advanced EU Member States in terms of NIS2 transposition. The European Commission's maturity assessment places Greece at level 4 — ahead of several larger Member States that are still finalising their national legislation. This is not accidental; Greece moved relatively quickly on the legislative and regulatory framework, even if operational implementation across the economy remains uneven.
Law 5160/2024, adopted on 27 November 2024, transposed NIS2 into Greek national law. It established the National Cybersecurity Authority (NCSA), housed within the Ministry of Digital Governance, as the competent authority for both essential and important entities. The law defines scope, classification criteria, governance obligations, incident reporting requirements, and the penalty framework.
The implementing measures followed in 2025. Joint Ministerial Decision 1689/2025, published on 6 May 2025, established the National Cybersecurity Requirements Framework — a structured set of 14 primary requirement categories covering technical, organisational, and operational security measures. These categories span access control, cryptography, network security, vulnerability management, incident handling, business continuity, supply chain security, and governance, among others. This framework is effectively the compliance baseline that Greek entities must meet.
Entity registration with the NCSA was mandated with initial deadlines that were subsequently extended to September 2025. Entities were required to self-classify as essential or important based on the criteria in Law 5160/2024 and register accordingly. Those that missed the extended deadline face a straightforward calculation: late registration is a compliance deficiency, but non-registration is a more serious matter entirely.
The appointment of a YASPE — an Information and Communication Systems Security Officer — is mandatory for entities in scope. The YASPE serves as the designated point of contact for the NCSA and bears responsibility for overseeing the entity's cybersecurity posture. Qualification requirements were further specified in JMD 1899/2025. This is not a role that can be filled retroactively or treated as a paper exercise; the NCSA expects a named, qualified individual with documented authority within the organisation.
Incident reporting follows the NIS2 three-stage model:
- 24-hour early warning to the NCSA upon becoming aware of a significant incident
- 72-hour detailed notification with initial assessment, severity, and impact
- One-month final report with root cause analysis, mitigation measures, and cross-border impact if applicable
The penalty framework in Law 5160/2024 mirrors NIS2's maximum thresholds: up to €10 million or 2% of global annual turnover for essential entities, and up to €7 million or 1.4% of global turnover for important entities, whichever is higher. What distinguishes the Greek implementation — and what should concentrate the attention of every board member and managing director — is the explicit codification of personal liability for management body members. This is not theoretical. Law 5160/2024 makes clear that the management body is responsible for approving and overseeing the implementation of cybersecurity risk-management measures, and that individuals can be held personally liable for failures in that oversight.
The proportionality principle is embedded throughout: requirements scale based on entity size, the nature and complexity of their operations, and the potential impact of incidents on the services they provide. A 50-person logistics company is not expected to implement the same controls as a national energy provider. But proportionality is not a defence for inaction — it defines the scale of the response, not whether a response is required.
What This Means for Greek SMEs in Practice
The first practical question for any Greek SME is whether the proposed amendments will change their classification. If your organisation has fewer than 750 employees and annual turnover under €150 million, the small mid-cap category would reclassify you as "important" rather than "essential" — assuming you were previously classified as essential based on your sector. The difference is meaningful: important entities face reactive supervision rather than proactive oversight, which translates to fewer scheduled audits and inspections. You are still required to meet the same baseline security measures, but the enforcement mechanism is less intrusive.
The harmonisation ceiling provides a different kind of protection. Once EU implementing acts define the cybersecurity measures for your sector, Greece cannot impose additional requirements beyond that baseline. For organisations that have been uncertain about whether their current compliance efforts might prove insufficient if Greece decides to layer on extra obligations, this ceiling offers planning certainty. You can invest in meeting a defined standard with confidence that the goalposts will not move at the national level.
The cyber-posture certification pathway is potentially valuable but remains undefined in its details. If your organisation already holds an ISO 27001 certification or is working toward one, it is worth tracking whether that certification will be recognised under the EU framework. If it is, the exemption from additional NIS2 security audits in certified areas would eliminate meaningful compliance overhead.
However — and this is the point that requires the most emphasis — these are all proposals. The January 2026 amendments must navigate the EU legislative process. Political agreement is unlikely before early 2027. Member States would then have a transposition period — typically 12 to 18 months — to incorporate the changes into national law. Greece would need to amend Law 5160/2024 and potentially update its implementing JMDs. Realistically, the amendments will not alter Greek compliance obligations before 2028 at the earliest.
In the interim, Law 5160/2024 is fully in force. The NCSA has the authority to conduct oversight activities, request information, and impose penalties. The registration deadline has passed. The YASPE appointment requirement is active. The 14 requirement categories in JMD 1689/2025 define the compliance baseline you are expected to meet now.
Supply chain requirements deserve particular attention because they are significant under the existing framework, not only under the proposed amendments. Law 5160/2024 already requires entities to assess and manage cybersecurity risks in their ICT supply chain. Among the organisations we work with at IWH, supply chain assessment is consistently the area where the gap between obligation and practice is widest. Many SMEs have no documented process for evaluating their technology providers' security posture — despite relying on those providers for critical infrastructure and services.
The management liability provisions should not be treated as abstract legal risk. Greek law explicitly requires the management body to approve cybersecurity measures and to undergo appropriate training. If an incident occurs and the investigation reveals that the board never formally approved a cybersecurity policy, never received a briefing on the organisation's risk posture, and never allocated budget for security measures, the personal liability exposure is real and documentable.
What You Should Be Doing Now
The amendments will eventually make compliance lighter for mid-sized organisations. That is welcome. But the compliance obligations that are enforceable today — under Law 5160/2024 and JMD 1689/2025 — are the ones that matter for any decision you make in the next 12 to 18 months. Here is what that looks like in practice:
1. Confirm your NIS2 scope status under Law 5160/2024. Determine whether your organisation is classified as essential or important based on the sector criteria and size thresholds in the law. If you believe the proposed small mid-cap category would reclassify you, note that for future planning — but comply with your current classification now.
2. Register with the NCSA if you have not already done so. The deadline has passed. Late registration is a compliance deficiency; non-registration is a more serious matter that compounds with every month of inaction. The registration process is administrative, not technically complex. There is no defensible reason to delay further.
3. Appoint your YASPE with documented qualifications per JMD 1899/2025. This individual must have the technical competence, organisational authority, and documented mandate to fulfil the role. If your current IT manager lacks the formal qualifications specified in the JMD, consider external appointment or supplementary training. The NCSA expects a named individual, not a vague organisational commitment.
4. Conduct a cybersecurity risk assessment aligned to the 14 requirement categories in JMD 1689/2025. This is not a generic risk assessment — it must address the specific categories defined in the national framework: governance, risk management, asset management, access control, cryptography, communications security, network security, information system acquisition and development, supplier relationships, incident management, business continuity, vulnerability management, security assessment and testing, and human resource security. Identify your gaps against each category and prioritise based on risk and impact.
5. Document your incident response procedures against the three-stage NIS2 timeline. You need a defined process for detecting a significant incident, submitting a 24-hour early warning to the NCSA, preparing a 72-hour detailed notification, and delivering a one-month final report. This process must be documented, tested, and understood by the people who would actually execute it during an incident. An incident response plan that exists only as a PDF on a shared drive and has never been exercised is not a plan — it is a liability.
6. Map your critical ICT supply chain and assess their security posture. Identify every provider that delivers or supports technology critical to your operations: cloud infrastructure, managed services, software platforms, telecommunications. For each, determine what security measures they have in place, what contractual obligations govern their cybersecurity practices, and what your exposure would be if they experienced a significant incident. The proposed amendments will introduce standardised supplier questionnaires — but the obligation to assess supply chain risk exists now under Law 5160/2024.
7. Implement proportionate technical measures. The word "proportionate" does not mean "minimal." It means scaled to your organisation's size, complexity, and risk profile. At a minimum, this includes:
- Identity and access management with the principle of least privilege
- Encryption for data in transit and at rest, particularly for sensitive or personal data
- Vulnerability management — regular scanning, documented patching processes, and defined remediation timelines
- Network security controls — segmentation, monitoring, and documented firewall policies
- Endpoint protection and security monitoring appropriate to your environment
- Backup and recovery procedures that are tested, not merely documented
8. Brief your management body on their NIS2 governance obligations and personal liability exposure. This is not optional and it is not delegable. The board or management body must formally approve the organisation's cybersecurity risk-management measures, receive regular reporting on cybersecurity posture and incidents, and undertake appropriate training. Document every briefing, every decision, and every budget allocation. If an incident occurs, the quality of your governance documentation will be as important as the quality of your technical controls.
9. Do not wait for the amendments to take effect before acting. The logic is straightforward: if you comply with the current, more demanding framework, you will automatically satisfy the lighter requirements that the amendments introduce. Organisations that delay compliance in anticipation of favourable changes are making a bet that the NCSA will not exercise its enforcement authority in the interim. Given that Greece has invested significant political capital in being among the NIS2 transposition leaders, that is not a bet with favourable odds.
The Bottom Line
The January 2026 amendments are genuinely good news for Greek SMEs. Lighter classification for mid-sized companies, a ceiling on national gold-plating, certification-based audit exemptions, and eventually a unified reporting portal — these are meaningful improvements that will reduce compliance friction once they become law.
But "once they become law" is doing significant work in that sentence. The EU legislative process will take at least 18 months. National transposition will take another 12 to 18 months after that. The Single Entry Point is even further out. None of these proposals alter what is enforceable today.
Law 5160/2024 is in force. JMD 1689/2025 defines the compliance baseline. The NCSA is operational. The penalties — up to €10 million or 2% of global turnover — are real. Personal liability for management body members is explicitly codified. And for most Greek SMEs in scope, the compliance clock started in late 2024.
The amendments will make the journey smoother. They will not make the destination optional.
Disclaimer: This article provides general information on the NIS2 Directive and its proposed amendments. It does not constitute legal advice. Organisations should consult qualified legal and cybersecurity professionals for guidance specific to their circumstances and regulatory obligations.