Law / Greece

Law 5160/2024, Significant-Incident Reporting Obligations

Law 5160/2024 (Ν. 5160/2024), Art. 16

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 27 November 2024.

A vulnerability and incident reporting rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds an essential entity or an important entity drawn from Annex I or Annex II, on the same scope as this jurisdiction's companion risk-management row: Annex II's digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform, reached at the medium-enterprise threshold or above; the wider sector classes are not raised here for the same reason.
  • Notify the CSIRT of the National Cybersecurity Authority, without undue delay and in any case within 24 hours of becoming aware of a significant incident, with an early warning stating whether unlawful or malicious action is suspected and whether the incident may have cross-border effects.
  • Follow within 72 hours of becoming aware of the significant incident with an incident notification updating the early warning and adding an initial assessment of its severity and effects.
  • Submit an interim report if the National Cybersecurity Authority requests one.
  • Submit a final report no later than one month after the 72-hour notification, describing the incident in detail, its severity and effects, the likely threat or root cause, mitigating measures applied, and any cross-border impact; if the incident is still ongoing at that point, submit a progress report instead and the final report within one month of its resolution.
  • Without undue delay, notify the recipients of your services of a significant incident likely to adversely affect the services they receive, and inform any recipients affected by a significant cyber threat of the threat and of the measures they can take in response.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 26's own penalty provision for an Article 16 infringement is an administrative fine (διοικητικό πρόστιμο); no provision reviewed here makes the infringement itself a criminal offence. The mere act of notifying does not itself create liability for the notifying entity (Article 16(1)).

Penalty structure

Article 26(4) sets the maximum administrative fine for an essential entity's infringement of Article 15 or 16 at EUR 10,000,000 or 2 percent of the total worldwide annual turnover of the undertaking in the preceding financial year, whichever is higher. Article 26(5), the mirror provision for an important entity, sets the equivalent cap at EUR 7,000,000 or 1.4 percent of that turnover, whichever is higher. Both mirror NIS2 Directive Article 34(4) and (5). NOTE ON THE SOURCE TEXT: the official gazette text of both paragraph 4 and paragraph 5 closes with the identical clause "της επιχείρησης στην οποία ανήκει η σημαντική οντότητα" ("the undertaking to which the important entity belongs"), even though paragraph 4 opens by naming "τις βασικές οντότητες" (essential entities) as the entity bound by the EUR 10,000,000/2% cap. The entity classification is unambiguous from each paragraph's opening clause and from the figures themselves, which are the two figures NIS2 Article 34(4)-(5) prescribes for essential and important entities respectively; whether the shared closing clause is a drafting artifact of the published FEK text has not been confirmed against a second, independent rendering of the gazette page.

Rule
Higher of
As of
15 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Εθνική Αρχή Κυβερνοασφάλειας (National Cybersecurity Authority, EAK), whose CSIRT receives the notification; for the national-security, public-order, defence and law-enforcement entity class of Article 3(2)(στ), the CSIRT of the Εθνική Υπηρεσία Πληροφοριών (National Intelligence Service) with parallel notice to the EAK.

Settledness

As of
15 September 2026
Guidance link
https://cyber.gov.gr/nomothesia/elliniki-nomothesia-gia-tin-kyvernoasfaleia/
Guidance body
Εθνική Αρχή Κυβερνοασφάλειας (National Cybersecurity Authority)
Open questions
The fetched copy of Article 26 closes both paragraph 4 (essential entities, EUR 10,000,000/2%) and paragraph 5 (important entities, EUR 7,000,000/1.4%) with the same clause naming "η σημαντική οντότητα"; is that the published FEK text's own wording, or an artifact of this PDF's text extraction?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 16 requires an essential or important entity to notify, without delay, the CSIRT of the National Cybersecurity Authority of every incident that has a significant impact on the provision of its services (a 'significant incident' under paragraph 3, gated on serious operational disruption or financial loss to the entity, or material harm to other persons).

The notification follows a graduated clock: an early warning within 24 hours of becoming aware of the significant incident, stating whether unlawful or malicious action is suspected and whether the incident may have cross-border effects; an incident notification within 72 hours, updating and adding an initial assessment of severity and effects; an interim report if the National Cybersecurity Authority requests one; and a final report no later than one month after the 72-hour notification, covering a detailed description, the type of threat or root cause, mitigating measures, and any cross-border impact, or, for an incident still ongoing at that point, a progress report followed by a final report within one month of its resolution.

The entity must also, without undue delay, notify service recipients of a significant incident likely to adversely affect the services they receive, and must inform recipients affected by a significant cyber threat of the threat and of measures they can take in response. This law, Law 5160/2024 (FEK A' 195/27.11.2024), transposes NIS2 Directive Article 23.

When LexLint raises it

  • operates_social_platform

Read the law

Government Gazette (Εφημερίδα της Κυβερνήσεως)
FEK A' 195/27.11.2024, Law 5160/2024, official text as hosted by the National Cybersecurity Authority (Εθνική Αρχή Κυβερνοασφάλειας), cyber.gov.gr

Back to the example  ·  Lint your app