Greece NIS2 competent authority NCSA supervisory framework diagram

Greece’s NIS2 Authority Is Both NCA and CSIRT: NCSA Registration, YASPE Obligations, and What No Other EU State Requires

When the Greek parliament enacted Law 5160/2024 in November 2024, it did not simply copy the NIS2 Directive into national law. It embedded two Greek-specific obligations that most generic NIS2 compliance guides miss entirely — and that every organisation operating in Greece needs to understand before it can claim compliance.

The first is structural. Greece designated a single body, the National Cybersecurity Authority (NCSA / Εθνική Αρχή Κυβερνοασφάλειας), as both its National Competent Authority (NCA) and its national CSIRT. Most EU member states split these functions between separate organisations. This consolidation means the authority overseeing your regulatory compliance is the same body coordinating the technical incident response if you suffer a breach.

The second is operational. Greek law mandates that essential and important entities appoint a dedicated cybersecurity officer called the YASPE (Υπεύθυνος Ασφάλειας Συστημάτων Πληροφορικής και Επικοινωνιών — Information and Communications Systems Security Officer). The YASPE must be registered with NCSA, hold documented qualifications, and — under an explicit incompatibility rule with no equivalent in most EU member states’ NIS2 transpositions — cannot simultaneously serve as your organisation’s Data Protection Officer.

This guide covers both obligations in full: the NCSA’s structure and mandate, the YASPE requirements, the registration process, and NCSA’s enforcement framework.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Who Is the NCSA? Greece’s Single Authority for NCA, CSIRT, and Cross-Border Coordination

The NCSA was established as a Legal Entity of Public Law under Law 5086/2024 and is supervised by the Minister of Digital Governance. Its Governor is Michael Bletsas, appointed in April 2024. Under Law 5160/2024, the NCSA holds three concurrent mandates that the NIS2 Directive permits — but does not require — to be consolidated under a single body:

  • National Competent Authority (NCA) — monitors and enforces compliance by essential and important entities across all sectors covered by Law 5160/2024
  • National CSIRT — coordinates the technical response to significant cybersecurity incidents affecting Greek entities and critical infrastructure
  • Single Point of Contact (SPOC) — represents Greece in the EU NIS Cooperation Group and handles cross-border incident coordination with authorities in other member states

This consolidation is significant because it changes the compliance dynamic compared to most EU member states. Germany, for instance, distributes the NCA function across sector-specific authorities — the Bundesnetzagentur for energy, the BaFin for financial services — while the BSI functions as the national CERT. France’s ANSSI similarly combines national cybersecurity authority and CERT-FR functions, making it one of the few EU analogues to Greece’s single-body model. Across the EU, however, the consolidated model remains the exception.

The operational consequence: when a Greek entity files the 24-hour early warning required after a significant incident, it reaches the same authority that oversees its regulatory compliance posture. In states with separate bodies, those two channels diverge. Designate a single internal point of contact — your YASPE (see Section 3) — who owns both the regulatory relationship and the incident coordination channel with NCSA. Splitting these responsibilities across different internal teams creates coordination risk under Greek law, because the YASPE is legally responsible for both functions.

NCSA’s official portal is cyber.gov.gr. Its dedicated NIS2 registration system operates at nis2register.cyber.gov.gr.

Does NIS2 Apply to Your Organisation in Greece?

The scope of Law 5160/2024 follows the NIS2 Directive’s sector-based framework, with entities classified as Essential or Important based on the combination of sector and size. Approximately 3,500 organisations in Greece are estimated to fall within the regulatory perimeter. The table below maps the key classifications:

Classification Sectors (examples) Size threshold Supervision model
Essential Entity Energy, transport, banking, healthcare, drinking water, wastewater, digital infrastructure, ICT services (B2B), public administration, space Large enterprises: 250+ employees OR €50M+ turnover / €43M+ balance sheet. DNS operators, TLD registries, cloud service providers: all sizes regardless of headcount. Ex-ante — proactive audits without requiring an incident trigger
Important Entity Postal and courier services, waste management, food production and distribution, chemicals, manufacturing (medical devices, electronics, machinery, motor vehicles), digital providers, research organisations Medium enterprises: 50–249 employees OR €10M–€50M turnover. Some digital service providers: all sizes. Ex-post — triggered by evidence of non-compliance, incident, or complaint

Decision logic to determine your scope:

  1. Is your organisation’s primary activity listed in Annex I (essential sectors) or Annex II (important sectors) of Law 5160/2024?
  2. If yes, do you meet the applicable size threshold — or operate as a cloud service provider, DNS resolver, TLD registry, or similar digital infrastructure provider that is exempt from size thresholds?
  3. Do you provide services to recipients in Greece, regardless of where your organisation is established in the EU?

If all three conditions apply, registration with NCSA is mandatory. For a full scope determination covering your specific sector and entity type, the NIS2 scope guide covers the entity classification logic in full. Multinationals established in another EU member state but providing services in Greece may be subject to joint supervision — NCSA coordinates with the member state authority where the entity is primarily established.

YASPE — Greece’s Mandatory Cybersecurity Officer Role

Article 20 of the NIS2 Directive requires governing bodies of essential and important entities to approve cybersecurity risk management measures and ensure their members receive training. It does not require member states to mandate a named, individually registered cybersecurity officer. That obligation is a deliberate Greek addition in Law 5160/2024, elaborated in detail through Joint Ministerial Decision 1899/2025, which entered into force on 1 November 2025.

Every essential and important entity covered by Law 5160/2024 must appoint a YASPE. The role carries no size-based exemption within the entity classifications — if your organisation is in scope, you need a YASPE.

Qualification Requirements

Per JMD 1899/2025, a YASPE candidate must satisfy one of two qualification tracks:

Track Required credentials Minimum experience
Academic Relevant undergraduate or postgraduate degree in computer science, information security, telecommunications, or a related technical field 5 years of practical cybersecurity experience
Certified professional Recognised professional certification — CISSP, CISM, or an equivalent accepted by NCSA 2 years of practical cybersecurity experience

In both cases, the appointment requires a criminal record extract. Law 5160/2024 specifies that individuals with irrevocable convictions for offences involving computer systems, information security, or related categories are ineligible. The candidate must also demonstrate sufficient knowledge of the entity’s business operations and technical environment — not only generic cybersecurity competence.

The YASPE must ordinarily be a staff member of the obliged entity. Exceptionally, the role may be filled by a person from another undertaking within the same corporate group, but it cannot be fully outsourced to an unrelated external provider.

Core YASPE Responsibilities

Once appointed and registered, the YASPE is responsible for:

  • Overseeing implementation of the cybersecurity risk management measures required under Article 21 of the NIS2 Directive — covering risk analysis, incident handling, business continuity, supply chain security, network security, access control, cryptography, and staff training
  • Serving as the primary contact for all NCSA interactions — regulatory, supervisory, and incident-related
  • Coordinating incident notification to NCSA: 24-hour early warning, 72-hour detailed notification, and one-month comprehensive report, as required under Article 23 of the NIS2 Directive
  • Developing the entity’s unified cybersecurity policy and securing Board of Directors approval for it
  • Ensuring ICT supply chain security requirements are met under Article 21(2)(d)
  • Providing cybersecurity training to governing body members and all staff

The YASPE reports directly to the entity’s highest administrative level — the same level that bears personal liability for NIS2 compliance under Law 5160/2024.

The YASPE/DPO Incompatibility: Why Greece Separated These Roles

Law 5160/2024, as elaborated by JMD 1899/2025, establishes explicit incompatibilities between the YASPE role and other positions within the same organisation. The same individual cannot simultaneously hold:

  • The role of Data Protection Officer (DPO) as defined under Article 37 of GDPR (Regulation (EU) 2016/679)
  • The role of Head of IT or Chief Information Officer (operational responsibility for IT/ICT management)
  • For public sector bodies: the role of Data Usage Officer

The DPO/YASPE separation reflects deliberate governance logic. The DPO’s statutory function under GDPR is grounded in independence: the DPO monitors data protection compliance, reports to the national supervisory authority (in Greece, the HDPA), and is explicitly protected from receiving instructions that would compromise their independent oversight role. The YASPE, by contrast, is an operational position — implementing security measures, holding authority over cybersecurity policy execution, and reporting directly to both the governing body and NCSA.

Combining both roles in a single person would mean the same individual both implements cybersecurity decisions and independently monitors their compliance impact. Greek law treats this as a structural conflict, not a manageable tension.

The YASPE/CIO incompatibility follows the same logic: the head of IT cannot objectively assess the cybersecurity risks of systems they are operationally responsible for building and maintaining. Greek law requires the cybersecurity oversight function to sit outside the IT management line.

What this means if your organisation currently combines these roles: If the same person holds DPO responsibilities and manages IT security or cybersecurity oversight, Greek law requires structural separation before you register your YASPE with NCSA. There is no grandfathering provision. The JMD 1899/2025 obligation applied from 1 November 2025. Entities that have not separated these roles are already non-compliant, not prospectively non-compliant.

This two-role separation — YASPE from DPO, YASPE from CIO — is operationally more demanding than what NIS2 requires on its own. Medium-sized organisations that previously relied on a single senior person for both data protection oversight and security operations now need distinct governance appointments, each with its own registration trail at NCSA.

Registering with NCSA: Platform, Required Data, and Deadlines

NCSA’s NIS2 registration platform is accessible at nis2register.cyber.gov.gr. Authentication uses Taxisnet credentials — Greece’s national tax identification portal. The entity registration obligations under NIS2 require all in-scope organisations to self-identify; there is no exemption for entities that have not yet determined their scope.

The registration submission must include:

  • Organisation name, legal form, and registered address
  • Sector and subsector classification under Annex I or II of Law 5160/2024
  • Contact details for the entity and its legal representative
  • NIS2 point of contact information — this is typically your YASPE
  • List of EU member states where your organisation provides services
  • IP address ranges and domain names used in service delivery
  • YASPE details: full name, qualifications held, professional contact information
  • SME status declaration where applicable

Deadline: The registration deadline was extended to 30 September 2025 under Ministerial Decision 1645/2025. Entities that did not meet this date are non-compliant from the date their original obligation arose — the extension was an administrative accommodation, not a liability reset. NCSA has authority to initiate supervisory and enforcement action against non-registering entities at any point after the obligation applied.

If technical obstacles prevent use of the online platform, registration by email to register.ncsa@cyber.gov.gr is permitted as an exception. NCSA registration queries can also be directed by phone: +30 210 4802034 or +30 210 4802725, weekdays 08:00–15:00 local time.

NCSA’s Supervisory Powers and Penalty Framework

Law 5160/2024 implements the NIS2 Directive’s two-tier supervision model, which applies different oversight intensities depending on entity classification:

Entity type Supervision model NCSA trigger Maximum administrative fine
Essential Ex-ante (proactive) Scheduled, risk-based, or ad hoc audits — no incident or complaint required as a precondition €10,000,000 or 2% of global annual turnover, whichever is higher
Important Ex-post (reactive) Triggered by incident evidence, third-party complaint, or findings from NCSA-initiated review €7,000,000 or 1.4% of global annual turnover, whichever is higher

NCSA’s enforcement toolkit — applied at its discretion depending on severity and recurrence — includes binding instructions (with immediate effect and no implementation grace period), written warnings, recommendations, orders for public disclosure of infringements, and suspension of certifications or service authorisations. The authority may conduct regular audits, targeted security assessments, and security scans of exposed systems, with or without advance notice depending on the audit type.

Incident reporting obligations carry independent enforcement exposure. Failure to submit the 24-hour early warning, 72-hour detailed notification, or one-month comprehensive report — required under Article 23 of the NIS2 Directive as transposed in Law 5160/2024 — is a distinct compliance failure from broader risk management non-compliance. Both can be pursued simultaneously.

Personal liability for management is explicit. Members of the governing body responsible for ensuring NIS2 compliance may face individual monetary penalties. For serious or repeated breaches, NCSA may impose a temporary prohibition on exercising managerial functions at the CEO or legal representative level, following the framework in Articles 32 and 33 of the NIS2 Directive.

Compliance Action Steps for Greek Entities

Step Action required Owner Status / Deadline
1 Confirm scope: verify your sector (Annex I or II) and size threshold under Law 5160/2024 Legal / Compliance Immediate — obligation retroactive to November 2024
2 Appoint a YASPE meeting the qualification requirements of JMD 1899/2025 (degree + 5 years OR certification + 2 years) HR + Board Now — JMD 1899/2025 applies from 1 November 2025
3 Verify role separation: confirm no individual simultaneously holds YASPE + DPO or YASPE + CIO responsibilities Legal / HR Immediate — if currently combined, separation is already required
4 Register on the NCSA platform at nis2register.cyber.gov.gr using Taxisnet credentials, including YASPE details YASPE / Legal Extended deadline was 30 September 2025 — if not yet registered, file immediately
5 Implement risk management measures across all 10 NIS2 Article 21 categories CISO / YASPE Within 3 months of Law 5160/2024 entry into force (February 2025 — now overdue if not completed)
6 Develop unified cybersecurity policy and secure Board of Directors approval YASPE + Board Required at time of YASPE appointment — ongoing annual review
7 Establish incident reporting procedures: 24h early warning → 72h detailed notification → 1-month comprehensive report to NCSA YASPE / IT Operations Before any significant incident — procedures must pre-exist the event
8 Deliver cybersecurity training to governing body members and all staff YASPE Ongoing requirement under NIS2 Article 20 and Law 5160/2024

Key Takeaways

  • NCSA holds three concurrent roles — National Competent Authority, national CSIRT, and Single Point of Contact — making it one of the few EU member state authorities to consolidate all three NIS2 supervisory functions under one body.
  • YASPE is a Greek addition beyond what the directive requires. Every essential and important entity must appoint a qualified, individually registered cybersecurity officer. The NIS2 Directive’s Article 20 governance requirements do not mandate this by name — Law 5160/2024 does.
  • The YASPE/DPO incompatibility is explicit and applies from 1 November 2025. If your organisation previously combined these roles, structural separation is already required — there is no grandfathering. The YASPE/CIO incompatibility applies on the same basis.
  • Registration at nis2register.cyber.gov.gr is mandatory using Taxisnet credentials. The extended deadline was 30 September 2025; non-registration does not remove you from scope, it makes you immediately non-compliant.
  • Essential entities face proactive ex-ante supervision — NCSA can audit without waiting for an incident. Important entities face ex-post supervision, activated by evidence of non-compliance.
  • Fines reach €10 million or 2% of global turnover for essential entities; €7 million or 1.4% for important entities. Personal liability for management, including temporary prohibition from managerial roles for serious breaches, is explicit in Law 5160/2024.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. National Cybersecurity Authority of Greece (NCSA) — Official Website. cyber.gov.gr. Accessed June 2026.
  2. Directive (EU) 2022/2555 of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union (NIS2). EUR-Lex, OJ L 333, 27 December 2022.
  3. EY Greece. “L.5160/2024: Transposition of Directive NIS 2 on measures for a high common level of cybersecurity across the Union.” ey.com. Published February 2025.
  4. Bernitsas Law. “Greece enters the NIS2 era: decoding the latest cybersecurity rules.” bernitsaslaw.com. Published November 2024.
  5. Bernitsas Law. “Greek Cybersecurity Law: New Rules for Entity Registration and ICSSO Appointment and Role.” bernitsaslaw.com. Published September 2025.
  6. SIMA Security. “The Strategic Role of the Information and Communications Systems Security Officer (Y.A.S.P.E.) — Based on Greek Government Gazette 4250/Β/05.08.2025.” simasecurity.gr. Published August 2025.
  7. Copla. “NIS2 Greece Guide: Compliance, Deadlines & Fines.” copla.com. Updated January 2026.
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: