Law 5160/2024, Cybersecurity Risk-Management Measures and Governance
Law 5160/2024 (Ν. 5160/2024), Arts. 14-15
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 27 November 2024.
A sector security regimes rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds an essential entity or an important entity drawn from Annex I (high-criticality sectors) or Annex II (other critical sectors), which the law's own table of contents captions as corresponding directly to NIS2 Directive Annexes I and II; Annex II's digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform (each a defined term in Article 6), reached at the medium-enterprise threshold of Commission Recommendation 2003/361/EC or above (Article 3(1)); the wider sector classes Annexes I and II reach by designation (energy, transport, banking, health, drinking water, public administration and the rest) are not expressed in this vocabulary and are not raised here on that account.
- Within three months of this duty's entry into force, have your management body approve the cybersecurity risk-management measures you take to comply with the measures below, supervise their implementation, and ensure every board member receives training and that equivalent training reaches your staff at least annually.
- Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems you use for your activities or to provide your services, and to prevent or minimise the impact of an incident on the recipients of your services or on other services.
- Cover at minimum: risk analysis and information-system security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including your direct suppliers and service providers; security in the acquisition, development and maintenance of your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and staff training; cryptography and, where relevant, encryption policy; personnel security, access control and asset management; and, where appropriate, multi-factor or continuous authentication and secure voice, video, text and emergency communications.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 26's own penalty provision for an Article 15 infringement is an administrative fine (διοικητικό πρόστιμο); no provision reviewed here makes the infringement itself a criminal offence. A significant incident separately suspected to be criminal in nature triggers a referral to the prosecutorial authorities under Article 16(5), which is a fact about the incident rather than about this Article 15 duty.
Penalty structure
Article 26(4) sets the maximum administrative fine for an essential entity's infringement of Article 15 or 16 at EUR 10,000,000 or 2 percent of the total worldwide annual turnover of the undertaking in the preceding financial year, whichever is higher. Article 26(5), the mirror provision for an important entity, sets the equivalent cap at EUR 7,000,000 or 1.4 percent of that turnover, whichever is higher. Both mirror NIS2 Directive Article 34(4) and (5). NOTE ON THE SOURCE TEXT: the official gazette text of both paragraph 4 and paragraph 5 closes with the identical clause "της επιχείρησης στην οποία ανήκει η σημαντική οντότητα" ("the undertaking to which the important entity belongs"), even though paragraph 4 opens by naming "τις βασικές οντότητες" (essential entities) as the entity bound by the EUR 10,000,000/2% cap. The entity classification is unambiguous from each paragraph's opening clause and from the figures themselves, which are the two figures NIS2 Article 34(4)-(5) prescribes for essential and important entities respectively; whether the shared closing clause is a drafting artifact of the published FEK text has not been confirmed against a second, independent rendering of the gazette page.
- Rule
- Higher of
- As of
- 15 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Εθνική Αρχή Κυβερνοασφάλειας (National Cybersecurity Authority, EAK); for the national-security, public-order, defence and law-enforcement entity class of Article 3(2)(στ), the CSIRT of the Εθνική Υπηρεσία Πληροφοριών (National Intelligence Service) with parallel notice to the EAK.
Settledness
- As of
- 15 September 2026
- Guidance link
- https://cyber.gov.gr/nomothesia/elliniki-nomothesia-gia-tin-kyvernoasfaleia/
- Guidance body
- Εθνική Αρχή Κυβερνοασφάλειας (National Cybersecurity Authority)
- Open questions
- Does the Εθνικό Πλαίσιο Απαιτήσεων Κυβερνοασφάλειας Βασικών και Σημαντικών Οντοτήτων (National Cybersecurity Requirements Framework for essential and important entities), adopted by ΚΥΑ 1689/2025 (ΦΕΚ Β' 2186/06.05.2025), create any duty beyond what Articles 14 and 15 already state?
- The fetched copy of Article 26 closes both paragraph 4 (essential entities, EUR 10,000,000/2%) and paragraph 5 (important entities, EUR 7,000,000/1.4%) with the same clause naming "η σημαντική οντότητα"; is that the published FEK text's own wording, or an artifact of this PDF's text extraction?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 14 requires the management body of an essential or important entity to approve, within three months of this law's entry into force, the cybersecurity risk-management measures the entity takes to comply with Article 15, to supervise their implementation, and holds the management body responsible for the entity's breach of this duty; its members must undergo training and ensure the entity provides equivalent training to its staff at least annually.
Article 15 requires appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems the entity uses for its activities or to provide its services, and to prevent or minimise the impact of an incident on the recipients of its services or on other services, at a level of security proportionate to the risk, covering at minimum: risk-analysis and information-system security policy; incident handling; business continuity including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure; policies to assess the effectiveness of risk-management measures; basic cyber-hygiene practices and cybersecurity training; cryptography and, where relevant, encryption policy; human-resources security, access-control policy and asset management; and the use of multi-factor or continuous authentication, secure voice, video and text communications, and secure emergency-communications systems.
This law, Law 5160/2024 (FEK A' 195/27.11.2024), transposes NIS2 Directive Article 20 (Article 14) and Article 21 (Article 15).
When LexLint raises it
operates_social_platform
Read the law
Government Gazette (Εφημερίδα της Κυβερνήσεως)
FEK A' 195/27.11.2024, Law 5160/2024, official text as hosted by the National Cybersecurity Authority (Εθνική Αρχή Κυβερνοασφάλειας), cyber.gov.gr