ITER/GRGreece
What the record establishes for Greece: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.
Recipients
| Reached under | Body | Channel | Source |
|---|---|---|---|
| Data protection authorityGDPR, article 33 | Hellenic Data Protection Authority reported | — | edpb members |
| CSIRT or competent authorityNIS2, article 23 | The Εθνική Αρχή Κυβερνοασφάλειας, the National Cybersecurity Authority, to which paragraph 4 owes the submissions reported | Not set by the law, and there is no portal for it. The Authority publishes two forms, both dated 9 December 2025: a simple one for the twenty-four hour early warning, an analytical one for the seventy-two hour and the final report: and takes them by electronic mail at incident@cyber.gov.gr. Its page also links to the Hellenic CSIRT's own incident report page, which is a different team and is not recorded here as discharging this duty. | gr nomos 5160 2024 · cyber gov gr anafora |
| Financial supervisorDORA, article 19 | Bank of Greece reported | — | eba competent authorities |
| Market authorityMAR, article 17 | Επιτροπή Κεφαλαιαγοράς (HCMC) reported | — | esma mar nca |
Transposition of NIS2 binding
| Act | Νόμος 5160/2024, ΦΕΚ Α΄ 195 of 27 November 2024 |
|---|---|
| In force | not established in the text read |
| Recipient | The Εθνική Αρχή Κυβερνοασφάλειας, the National Cybersecurity Authority, to which paragraph 4 owes the submissions |
| Moves a term | No. None. The cascade is the Directive's, and the numbers are spelled out: a warning «εντός είκοσι τεσσάρων (24) ωρών από τη στιγμή που αντιλήφθηκαν το σημαντικό περιστατικό», the incident notification «εντός εβδομήντα δύο (72) ωρών» on the same anchor, an interim report at the Authority's request, and «τελική έκθεση το αργότερο εντός ενός (1) μηνός μετά από την υποβολή της κοινοποίησης περιστατικού». Where the incident is still running at that point, a progress report then and a final report within one month of the entity's handling of it. Trust service providers have their own derogation. |
| Standing | Read in the law as published in the Government Gazette. One thing is national rather than the Directive's default: the submissions are owed to the National Cybersecurity Authority itself, not to a CSIRT. This entry also settles something about the Cypriot one: the six hours in the Cypriot authority's guide are not a Greek-language convention. Greece, writing in the same language, says twenty-four. |
| Source | gr nomos 5160 2024 |
An event in Greece
The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.
