All member states

Greece · EU member state

Greece: NIS2, the CRA, the GDPR and ISO 27001, from the registers

Every register row StandardOS holds for Greece, each with the day it was read, and the two scope tools with the state filled in. Nothing on this page is typed; it is the registers, joined by state.

NIS2

The NIS2 law, as communicated to the Commission

Ενσωμάτωση της Οδηγίας (ΕΕ) 2022/2555 του Ευ- ρωπαϊκού Κοινοβουλίου και του Συμβουλίου, της 14ης Δεκεμβρίου 2022, σχετικά με μέτρα για υψη- λό κοινό επίπεδο κυβερνοασφάλειας σε ολόκλη- ρη την Ένωση, την τροποποίηση του Κανονισμού (ΕΕ) 910/2014 και της Οδηγίας (ΕΕ) 2018/1972, και την κατάργηση της Οδηγίας (ΕΕ) 2016/1148 (Οδη- γία NIS 2) και άλλες διατάξεις.

Νόμος · dated 27 November 2024 · in force 27 November 2024 · Εφημερίς της Κυβερνήσεως (ΦΕΚ) (Τεύχος Α)195

all 3 measures on the register · read on 12 September 2026

The national CSIRT

EL-CSIRT · National Cyber Security Authority CSIRT · cyber.gov.gr/el-csirt

Receives the Article 23 notifications, unless the state's act routes them to its competent authority, and the CRA's Article 14 notifications where it is also the coordinator.

Is your company under NIS2 in Greece?

The Cyber Resilience Act

The CSIRT designated as coordinator

EL-CSIRT · National Cyber Security Authority CSIRT

cyber.gov.gr/el-csirt

From ENISA's list of coordinators, dated 10 September 2026. A manufacturer with its main establishment in the state files its Article 14 notifications here, on ENISA's single reporting platform.

The authorities registered for the CRA

Market surveillance authority: none registered

Notifying authority: none registered

As registered in the Commission's Single Market Compliance Space on 11 September 2026. Designations are expected to fill in before full application on 11 December 2027.

Is your product in scope of the CRA, from Greece?The Article 14 deadline calculator

GDPR

Supervisory authority (Article 51)

Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)

www.dpa.gr

The authority of a company's main establishment leads for its cross-border processing (Article 56(1)) and receives its Article 33 breach notification. As the European Data Protection Board lists its members, read on 12 September 2026.

Which authority is yours: the main establishment and the lead authority of Article 56

ISO 27001

The national accreditation body

ESYD · Hellenic Accreditation System

esyd.gr

The one body under Regulation (EC) 765/2008 whose register says which certifiers are accredited for ISO 27001 here. Checked 11 August 2026.

Public tenders mentioning ISO 27001

213

Of 10,318 notices the state's buyers published on TED in 365 days, 2.06 % mention ISO 27001, 558 mention ISO 9001 and 4 mention NIS2. Observed 12 September 2026; mentions, not requirements.

How to check a certifier on the registerISO 27001 in EU public tenders, by countryISO 9001 in EU public tenders, by country

One workspace for what the state asks and what the buyer asks

StandardOS keeps the ISO 27001 records that answer most of NIS2's Article 21 measures, the incident record the Article 23 and Article 14 clocks run from, and the evidence a supervisor, a coordinator or an auditor asks for, in six languages.

Every row on this page is a register's, read on the day shown; the registers change and the read dates say how old each answer is. This is not legal advice.