NIS2 in Greece: Law 5160/2024 requires documented, demonstrable security.
In-scope organisations must appoint a security officer and evidence their compliance — not just assert it. InfosecAgent supports the full path from no documentation to an assessed, evidenced security programme.
What the law expects
Organisations in scope must, among other obligations, designate a security officer (ICSECO/YASPE), implement documented security measures, and be able to demonstrate compliance to the competent authority.
Non-compliance has consequences: the law provides for supervisory measures and administrative fines, and places responsibility for overseeing these obligations with management.
Are you in scope? A quick indication.
As a rule of thumb, the law covers medium and large organisations — around 50+ employees or over €10M annual turnover — operating in sectors including:
- Energy
- Transport
- Banking & financial market infrastructure
- Health
- Drinking & waste water
- Digital infrastructure & ICT service management
- Public administration
- Space
Also covered: postal & courier services, waste management, chemicals, food, manufacturing (including medical devices and electronics), digital platforms, and research.
Certain entities — for example critical digital-infrastructure providers — are in scope regardless of size. This list is an indication, not legal advice; final classification follows the law's registration process.
The path
Structured discovery.
A guided interview captures how the organisation actually operates. No existing documents needed.
Documentation, drafted.
The platform generates a tailored ISMS policy pack and Statement of Applicability from the interview — reviewed and finalised by your consultant.
Evidence-based assessment.
Every ISO 27001 and NIS2 control scored against real evidence, with a gap report and prioritised remediation plan. Where practice is stated but not documented, the report says so — you know where you stand before an auditor does.
The security officer requirement
The ICSECO/YASPE role can be fulfilled through an external provider. InfosecAgent partners deliver the role as a service, with the platform handling assessment, documentation, and evidence tracking.
