NIS2 in Greece: Law 5160/2024 requires documented, demonstrable security.

In-scope organisations must appoint a security officer and evidence their compliance — not just assert it. InfosecAgent supports the full path from no documentation to an assessed, evidenced security programme.

What the law expects

Organisations in scope must, among other obligations, designate a security officer (ICSECO/YASPE), implement documented security measures, and be able to demonstrate compliance to the competent authority.

Non-compliance has consequences: the law provides for supervisory measures and administrative fines, and places responsibility for overseeing these obligations with management.

Are you in scope? A quick indication.

As a rule of thumb, the law covers medium and large organisations — around 50+ employees or over €10M annual turnover — operating in sectors including:

  • Energy
  • Transport
  • Banking & financial market infrastructure
  • Health
  • Drinking & waste water
  • Digital infrastructure & ICT service management
  • Public administration
  • Space

Also covered: postal & courier services, waste management, chemicals, food, manufacturing (including medical devices and electronics), digital platforms, and research.

Certain entities — for example critical digital-infrastructure providers — are in scope regardless of size. This list is an indication, not legal advice; final classification follows the law's registration process.

The path

1

Structured discovery.

A guided interview captures how the organisation actually operates. No existing documents needed.

2

Documentation, drafted.

The platform generates a tailored ISMS policy pack and Statement of Applicability from the interview — reviewed and finalised by your consultant.

3

Evidence-based assessment.

Every ISO 27001 and NIS2 control scored against real evidence, with a gap report and prioritised remediation plan. Where practice is stated but not documented, the report says so — you know where you stand before an auditor does.

The security officer requirement

The ICSECO/YASPE role can be fulfilled through an external provider. InfosecAgent partners deliver the role as a service, with the platform handling assessment, documentation, and evidence tracking.

FAQ

Check where you stand.