Every few weeks we sit across from a competent management team that can recite the NIS2 timeline better than we can. They know the law, they know the Authority exists, they know fines are theoretical until they are not. Then we ask for the asset inventory and the room goes quiet. The gap in this country is not awareness any more. It is that nobody has written the first ninety days down.

So here they are. This is not a summary of the directive, and it is not a substitute for reading it. It is the plan we hand to a medium-sized Greek company that has done nothing and wants to be defensible by Christmas.

Where the Greek framework actually stands

Four things have happened, and they matter because an auditor will measure you against them and not against the directive text.

  • Law 5160/2024 transposed NIS2 into Greek law, published in the Government Gazette on 27 November 2024. It created the National Cybersecurity Authority as the competent supervisory body and single point of contact.
  • KYA 1689/2025 (Government Gazette B 2186, 6 May 2025) established the National Cybersecurity Requirements Framework for essential and important entities: twenty-two requirements expressed as technical, organisational and operational measures.
  • A gap-assessment tool was made available by the Authority in September 2025, with 169 control points organised into 24 thematic areas. It is offered as a practical instrument rather than a mandatory filing, and it is the closest thing you have to the auditor's own checklist.
  • Supervision starts in 2026. The Authority's Director General, Ioannis Alexakis, said publicly that audits begin this year once the audit regulation is issued, that inspections will be carried out by the Authority with private-sector assistance, and that fines are a compliance mechanism rather than an end in themselves.

Read that last point twice, because it is the one that changes the calculus. An organisation with a dated, funded, partially executed plan is in a different conversation from an organisation with nothing. The Authority has said it is looking for realistic roadmaps. It has not said it will accept an empty folder.

Days 1 to 10: find out whether this is even your problem

Run the scope test. The Authority publishes one at cyber.gov.gr. It walks through size, jurisdiction, sector and entity type, and tells you whether you are likely to be an essential or an important entity. The result is explicitly indicative and does not bind the Authority, so treat it as a strong signal, not a certificate. Save the output with the date. It is evidence that you asked the question.

The broad rule is that you are in scope if you are at least a medium-sized enterprise under the EU definition and you operate in one of the sectors listed in the annexes. Some entities are caught regardless of size, including DNS and top-level domain providers, trust service providers and parts of public administration.

If the test says you are out of scope, do not close the file. The single most common way a small Greek company meets NIS2 is through somebody else's supply chain. Your customer is in scope, supply-chain security is one of the required measures, and the obligation lands on you as a contract clause and a questionnaire. Out of scope legally is not out of scope commercially.

Confirm your registration. Obliged entities register through the Authority's register. Registration opened with a deadline that was extended to 11 April 2025 and closed in September 2025. If you discovered you were in scope after that, you register late rather than not at all, and you document when and why you discovered it.

Name the security officer, in writing, by decision of the board. Greek practice calls this role the Information and Communication Systems Security Officer, and the framework is specific that the role reports directly to the top management body. This is the cheapest control on the list and the one whose absence is most visible. A dated board minute naming a person, describing the reporting line and approving a budget takes one meeting. Skipping it means every later document has no owner.

Days 11 to 45: the two inventories and the policy set

Nothing downstream works without two lists, and almost nobody has them.

The asset inventory. Systems, applications, data stores, who owns each one, what it would cost you to lose it for a day. It does not need a tool. It needs to be complete and current, which is harder than it sounds and is the reason most organisations quietly skip it. Every risk assessment you write without it is fiction.

The supplier inventory. Every third party with access to your systems or your data, what access they have, and what your contract with them says about security and incident notification. Supply-chain security is an explicit requirement, and this is the list an auditor uses to test whether your risk management is real or ceremonial.

Then the policies. The Greek framework expects a set of thematic security policies, at least eleven of them, covering ground such as access control, cryptography, asset management, human resources security and supplier relationships. Two warnings from experience. First, a policy your staff have never read is worse than no policy, because it proves in writing that you knew what you were supposed to do. Second, a downloaded template with another company's name search-replaced is recognisable at fifty paces and damages your credibility for the rest of the audit.

In the same window, close the control that produces the highest return per euro: multi-factor authentication on everything that faces the outside world. Mail, VPN, remote desktop, administrative consoles, the cloud tenant. Multi-factor authentication is named in the risk-management measures, and more importantly it is the single measure that most often turns a breach into an incident report about a failed login.

Days 46 to 75: the incident procedure, and one rehearsal

The reporting clocks are the part of NIS2 that catches competent organisations out, because they are shorter than any internal process that has not been rehearsed. For a significant incident you owe the Authority an early warning within 24 hours, a fuller incident notification within 72 hours, and a final report within one month.

Twenty-four hours sounds generous until you place it against reality. The incident starts at 18:40 on a Friday. The person who notices is a junior administrator who is not sure it is real. The person who can authorise a notification to a regulator is on a plane. Meanwhile the clock is running from the moment you became aware, not from the moment your management woke up.

So write the procedure as a call tree with names and mobile numbers, a single decision-maker and a named deputy, and a pre-drafted early-warning template with the fields the Authority asks for. Then rehearse it once, on a Tuesday afternoon, with a scenario nobody has seen. A two-hour tabletop exercise, minuted, is worth more in an audit than a forty-page plan that has never been opened, and it will find the gap in your call tree while the gap is still free.

Days 76 to 90: measure yourself against the auditor's own list

Now take the Authority's gap-assessment tool and work through all 169 control points honestly. Honestly is the operative word. The purpose of this exercise is not to produce a good score. It is to produce a defensible one, which is a different thing: a document that says here is where we are, here is where we are not, here is the dated plan and the budget line for each gap, approved by the board.

Finish the quarter with a management review: the board formally approves the risk-management programme, the residual risks are listed and accepted by name, and the next review date is in the minutes. Under Greek law the management body approves the cybersecurity risk-management programme and oversees its implementation. Board members can be held personally accountable, and administrative sanctions include temporary prohibition from management duties. That provision exists precisely to stop the board delegating the problem to IT and looking away.

What this costs, and what it costs not to

For a Greek company of eighty to two hundred people with a normal Microsoft 365 estate, the ninety days above are mostly internal time: we typically see thirty to sixty person-days spread across IT, legal, HR and operations, plus external help for the gap assessment and the policy set. The technical spend that usually cannot be avoided is multi-factor authentication licensing, centralised logging and a backup arrangement that has actually been restore-tested.

Against that, the ceiling for administrative fines is ten million euro or two per cent of worldwide annual turnover, whichever is higher, for essential entities, and seven million euro or 1.4 per cent for important ones. We do not think fear of the maximum fine is a good reason to do any of this, and the Authority's own framing supports that. The better reason is that every item on the ninety-day list is something you would want on the morning of a real incident, regulator or no regulator.

The honest summary

Ninety days does not make you compliant. It makes you defensible, which in 2026 is the realistic target: a scope determination on file, a registration, a named officer with a reporting line, two inventories, a policy set your people have read, multi-factor authentication, an incident procedure that has been rehearsed once, a self-assessment against the Authority's own control points, and a board that has approved the gaps and the money to close them.

An organisation that can put those nine things on the table is having a conversation about a roadmap. An organisation that cannot is having a different conversation entirely. The difference between the two is about a quarter of deliberate work, and the quarter starts whenever you decide it does.


Related reading: NIS2 Implementation for Greek Organizations for how the Greek framework was built, the January 2026 amendments for what the Commission proposed to simplify, and What Auditors Actually Look For. Sources: Law 5160/2024 (Government Gazette A 199, 27 November 2024); KYA 1689/2025, National Cybersecurity Requirements Framework (Government Gazette B 2186, 6 May 2025); the Authority's scope test; and public statements by the Authority's Director General on the 2026 supervision regime.