[codicts-css-switcher id=”346″]

Global Law Experts Logo
nis2 public procurement greece

NIS2 and Cybersecurity Requirements for Critical‑infrastructure Tenders in Greece (2026)

By Global Law Experts
– posted 1 hour ago

NIS2 public procurement Greece is the compliance challenge that contracting authorities, bidders and in‑house counsel cannot afford to get wrong in 2026, as the transposition of the NIS2 Directive reshapes the risk profile of every technology‑heavy public contract. From smart‑metering rollouts to national e‑ID platforms and electricity‑grid modernisation, procurement teams are rewriting technical specifications, exclusion grounds and contract clauses to reflect a legal regime that treats cybersecurity as a procurement‑critical requirement rather than an afterthought. This article sets out, in operational terms, exactly what awarding authorities and suppliers must do, with a decision framework, model clause language and an evidence checklist you can adapt directly.

It takes a clear position: for the highest‑risk critical infrastructure, strict pre‑qualification vetting beats flexible post‑award contracting, and we explain precisely when that rule flips.

Who this is for: contracting authorities, bidders and in‑house counsel evaluating procurement risk and tender drafting in Greece.

What you will learn: NIS2 scope and applicability, tender technical specifications, bidder evidence, exclusion grounds, model contract clauses, enforcement and remedies.

20‑second action list: confirm whether the contract touches an essential or important entity; choose a compliance pathway; embed proportionate cyber criteria; specify incident‑reporting SLAs; demand credible evidence; draft defensible exclusion and termination language.

Quick summary: what contracting authorities and bidders must do now (TL;DR)

The practical implications of nis2 public procurement greece can be reduced to a short list of immediate actions. If you read nothing else, act on these.

For contracting authorities:

  • Classify the contract. Determine whether the procurement relates to an essential or important entity, or to a supplier whose failure would compromise one, under Directive (EU) 2022/2555.
  • Choose a pathway. Decide between strict pre‑qualification vetting (Pathway A) and contractual monitoring (Pathway B) before drafting the tender.
  • Draft proportionate criteria. Anchor cyber requirements in an objective baseline so exclusion decisions survive challenge under the applicable Greek procurement legislation implementing Directive 2014/24/EU.
  • Specify incident reporting. Impose clear reporting timelines, cooperation duties and audit rights in the contract security annex.

For bidders:

  • Assemble an evidence pack. Have ISO 27001 certification, SOC reports, risk registers and cyber insurance ready to submit and redact.
  • Map obligations to subcontractors. Ensure flow‑down clauses cover any party touching security‑relevant functions.

See the comparison table below for the full decision matrix.

Scope: when and how NIS2 affects nis2 public procurement greece

The starting point for any analysis of nis2 public procurement greece is scope. NIS2 does not regulate procurement directly, but it redefines which organisations must meet stringent cybersecurity obligations, and those obligations then flow into how public bodies must specify, evaluate and contract for technology and infrastructure services. In Greece, the Directive is given effect through national transposition legislation, and the National Cybersecurity Authority is the competent body for cybersecurity supervision; practitioners should verify the current transposition instrument and any implementing decisions before relying on specific provisions.

NIS2 scope: essential and important entities

Directive (EU) 2022/2555 (NIS2) distinguishes between essential and important entities across sectors including energy, transport, digital infrastructure, public administration, water and health. Classification depends on the sector and on size thresholds set out in the Directive, with larger operators in high‑criticality sectors typically falling into the essential category and subject to the most intensive supervision. Both categories must implement risk‑management measures and incident‑reporting obligations; the difference lies principally in the intensity of supervisory oversight and the enforcement regime.

Crucially for procurement, an entity does not escape NIS2 simply because it supplies a public body rather than operating infrastructure itself. Where a supplier delivers ICT services, managed security services or digital infrastructure that underpins an essential entity, it may itself be caught, and it will in any event be subject to the supply‑chain security expectations that NIS2 places on its customers. Contracting authorities must therefore check both the direct classification of the supplier and the indirect obligations that attach because the authority, or the end user of the contract, is an essential or important entity.

Intersection with public procurement law

NIS2 operates alongside, not instead of, the procurement framework. In Greece, EU procurement rules (including Directive 2014/24/EU) are implemented principally through the national public procurement legislation, which governs procedures, award criteria, exclusion grounds and, critically, the principle of proportionality. Any cybersecurity requirement embedded in a tender must be linked to the subject matter of the contract and must not disproportionately restrict competition. This is the central tension in nis2 public procurement greece: authorities must be demanding enough to protect critical systems, yet restrained enough that their criteria withstand challenge. The remainder of this article is built around resolving that tension.

Common verticals: smart meters, e‑ID, grid and transport

Certain Greek verticals sit squarely at the intersection of NIS2 and procurement. Smart‑metering programmes involve very large numbers of connected endpoints and back‑office data platforms. National e‑ID and e‑government identity systems process sensitive personal data and underpin public trust. Grid modernisation touches operational technology whose compromise carries systemic and safety consequences. Transport control and ticketing systems combine safety‑critical operational technology with large personal‑data estates. In each of these, cybersecurity procurement requirements are not optional refinements, they are load‑bearing elements of the contract.

Two compliance pathways for contracting authorities

Contracting authorities broadly face a strategic choice between two compliance pathways. We recommend deciding this before drafting the tender, because the choice drives everything from evaluation criteria to the length of the security annex. The table below sets the two approaches side by side.

Dimension Pathway A, Pre‑qualification & exclusion focus (strict vetting) Pathway B, Contractual & monitoring focus (flexible contracting)
Legal basis Embed NIS2 expectations into selection criteria and exclusion grounds; rely on procurement law to exclude non‑compliant suppliers Rely on award criteria and robust contract clauses to secure compliance post‑award
Typical use case High‑risk critical infrastructure where supplier failure means systemic risk (grid control, national e‑ID) Lower‑risk or time‑sensitive procurements where the market is narrow (certain IT services)
Time and cost impact Longer timeline; more administrative burden up front; potentially fewer bidders Faster award; more contract‑drafting time; ongoing monitoring costs
Evidence required Formal certificates, NIS2 compliance statements, audit/SOC reports, risk registers, insurance evidence Security plans, incident response plan, contractual security SLAs, audit and monitoring rights
Enforceability High at pre‑award through clear exclusion decisions; risk of challenge if criteria are poorly drafted Enforceable via breach remedies; may require proof of breach and litigation to force change
Liability allocation Reduces post‑award enforcement risk but increases upfront procurement risk Authority retains contractual remedies; supplier bears ongoing compliance and insurance costs
Contract drafting focus Shorter security annex (compliance assumed pre‑award) plus termination for material cyber breach Detailed obligations, reporting, audits, step‑in, subcontractor flow‑downs, penalties
Procurement risk Contestation if criteria are disproportionate; may limit competition Supplier non‑performance post‑award and longer remediation
Best for Critical systems with low risk tolerance where public safety or national security is implicated Complex systems where innovation and market access matter and continuous oversight is feasible
Decision outcome Favours selecting only demonstrably compliant suppliers Preserves competition but demands stronger contract management

Our recommendation: for critical infrastructure where a supplier failure would create systemic or public‑safety consequences, Pathway A is the correct default. The cost of a longer, narrower procurement is small compared with the cost of managing a non‑compliant supplier into remediation while critical services are exposed. Reserve Pathway B for lower‑risk, innovation‑driven or genuinely time‑critical procurements where you have the resources to run active contract management.

Implementation checklist for Pathway A (strict pre‑qualification)

  • Define an objective, published minimum security baseline tied to the contract subject matter.
  • Require formal evidence at pre‑qualification: ISO 27001, SOC 2, audit summaries, risk registers.
  • Reserve a pre‑award audit or verification right and document how you will exercise it consistently.
  • Draft proportionate exclusion language that is directly linked to the baseline.
  • Record the reasoning behind each criterion to defend against challenge.

Implementation checklist for Pathway B (contractual and monitoring)

  • Use award criteria to score security maturity rather than excluding at the gate.
  • Draft a detailed security annex covering obligations, SLAs and reporting timelines.
  • Include periodic audit rights, step‑in rights and a security maturity roadmap with milestones.
  • Provide for penalties and a defined remediation process for breach.
  • Resource an internal or external team to monitor performance across the contract term.

Tender technical specifications and evaluation: minimum cybersecurity requirements

Whichever pathway you select, the tender must translate NIS2 principles into cybersecurity procurement requirements that suppliers can price and evaluators can score. Vague aspirations toward “good security” are unenforceable and legally fragile; specific, measurable requirements are both.

Baseline technical and organisational measures

NIS2 requires covered entities to implement appropriate and proportionate technical, operational and organisational risk‑management measures, and ENISA guidance elaborates these into practical controls. For tender specifications, a defensible baseline typically covers:

  • Security governance. Named accountability, a documented information security management system and senior‑management oversight.
  • Risk management. A maintained risk register with treatment plans and periodic review.
  • Technical controls. Access management, encryption in transit and at rest, network segmentation, secure configuration and vulnerability management.
  • Supply‑chain security. Assurance over the supplier’s own subcontractors and component sources.
  • Incident detection and response. Monitoring, a tested incident response plan and defined reporting timelines.
  • Business continuity. Backup, recovery and continuity arrangements proportionate to service criticality.

Example smart‑metering specification (short template)

SMART METERING, example spec (sample wording, adapt with local counsel):

“The Supplier shall implement end‑to‑end encryption between metering endpoints and the head‑end system, maintain ISO 27001 certification covering the metering data platform for the full contract term, segment operational technology networks from corporate networks, and detect and report security incidents affecting metering data or availability to the Authority within the timelines set out in the Security Annex.”

This kind of specification is enforceable because each element is measurable. It also reflects the reality that smart‑metering procurement cybersecurity risk spans both large endpoint estates and centralised data platforms.

Evaluation criteria and weighting

Where security is scored rather than gated, award criteria must be transparent and weighted in advance. We recommend assigning explicit points to demonstrable certification, the quality of the incident response plan, the maturity of supply‑chain controls and the credibility of the proposed security roadmap. Publish the scoring methodology so that unsuccessful bidders can understand, and, where necessary, lawfully challenge, the outcome. The proportionality principle under EU and Greek procurement law requires that the weighting reflect genuine contract risk rather than an arbitrary preference.

Bidder evidence: pre‑qualification documents and bid substantiation

For bidders, success in nis2 public procurement greece increasingly turns on the quality and readiness of the evidence pack. Authorities are entitled to demand substantiation, and the strongest bids treat evidence as a standing asset rather than a last‑minute scramble.

Supplier due diligence documents

  • Certifications. ISO 27001 is the most widely recognised anchor; sector‑specific certifications add weight.
  • Independent attestations. SOC 2 (or SOC 3 for a shareable summary) reports covering the relevant services.
  • Audit reports. Recent internal or external audit summaries evidencing control effectiveness.
  • Risk assessments. A current risk register showing identified risks and treatment.
  • Incident response plan. A documented, tested plan with defined roles and reporting timelines.
  • Insurance evidence. Proof of cyber insurance with limits aligned to contractual exposure.

Practical bidder checklist

BIDDER QUICK‑WIN, 48‑hour checklist:

  • Confirm ISO 27001 scope covers the exact services being tendered.
  • Locate the latest SOC report and check its coverage dates against the tender period.
  • Prepare a redacted risk register that demonstrates maturity without exposing sensitive detail.
  • Draft a NIS2 compliance statement mapping obligations to your controls.
  • Verify cyber insurance limits against the likely liability cap.

Using third‑party attestations and SOC reports

Third‑party attestations carry particular weight because they reduce the authority’s verification burden. When submitting SOC or audit reports, bidders should redact sensitive technical detail while preserving the scope, opinion and control summary that evaluators need. Supplier cyber due diligence is a two‑way process: authorities should specify in advance which attestations they will accept, and bidders should confirm their evidence maps precisely to those requirements rather than assuming a general certification will suffice.

Contract stage: model clauses for security, incident reporting, step‑in, liability and termination

The contract is where cybersecurity obligations become enforceable. Under Pathway B especially, the security annex does the heavy lifting; even under Pathway A, robust termination and incident clauses remain essential. The snippets below are illustrative starting points.

Minimum contract language (security obligations and SLAs)

Sample wording, adapt with local counsel:

“The Supplier shall maintain, throughout the Term, the technical and organisational security measures set out in the Security Annex to a standard no lower than that represented in its tender, and shall not degrade any material control without the Authority’s prior written consent.”

Incident reporting and cooperation clause

Sample wording, adapt with local counsel:

“The Supplier shall notify the Authority of any security incident affecting the Services without undue delay and in any event within the timeframe specified in the Security Annex, shall cooperate fully with the Authority’s and any competent authority’s investigation, and shall provide all information reasonably required to enable the Authority to meet its own regulatory reporting obligations.”

Note that the drafting deliberately anchors the internal contractual deadline to the Security Annex so it can be aligned with the authority’s own statutory reporting duties under the national transposition of NIS2. Those statutory reporting timelines are set out in NIS2 and the Greek transposing legislation and should be verified against the current text before the annex is finalised.

Step‑in rights and subcontracting

Sample wording, adapt with local counsel:

“On the occurrence of a material cyber breach that threatens the security or continuity of the Services, the Authority may exercise step‑in rights to procure remediation, and the Supplier shall ensure that all security obligations under this Contract are flowed down to any subcontractor performing security‑relevant functions, together with equivalent audit rights.”

Flow‑down is not optional for functions that affect security. Any subcontractor touching security‑relevant processing should be bound by equivalent obligations, and the prime supplier should remain liable to the authority for their performance.

Liability caps and insurance language

Sample wording, adapt with local counsel:

“The Supplier shall maintain cyber insurance with limits not less than those specified in the Contract, and the parties agree that liability arising from a cyber incident caused by the Supplier’s breach shall be subject to the enhanced cap set out in Schedule [X], which shall not be lower than the available insurance cover.”

Aligning contract cyber incident clauses with actual insurance cover avoids the common trap of a liability cap that is unenforceable in practice because it exceeds the supplier’s ability to pay.

Enforcement, exclusions, remedies and dispute risk

Understanding enforcement is central to nis2 public procurement greece, because it defines both the leverage authorities hold and the exposure bidders face.

Exclusion grounds and administrative sanctions

Procurement exclusion on cybersecurity grounds is lawful, but only where it is proportionate and clearly linked to the contract. EU and Greek procurement law prohibit disproportionate exclusion criteria, so an authority that excludes a bidder for failing an objective, published security baseline stands on solid ground, while one that applies vague or shifting standards invites successful challenge. Separately, NIS2 gives national supervisory authorities enforcement powers over covered entities, including the ability to impose administrative measures and, in defined circumstances, significant administrative fines, a regulatory exposure that sits alongside, and independently of, any contractual consequence.

Contract termination, damages and penalties

Where a supplier breaches cyber obligations after award, the contract should provide a graduated remedial ladder: notice and cure, contractual penalties, step‑in, and ultimately termination for material breach with damages. Building this ladder into the contract at drafting stage, rather than relying on general breach principles, gives the authority predictable, enforceable leverage and reduces the likelihood of protracted litigation.

Defending and challenging decisions

Both bidders and authorities must be alert to the procedural remedies available in Greece. Unsuccessful bidders may challenge award and exclusion decisions through the available pre‑contractual review and judicial routes, subject to strict time limits set out in the applicable Greek procurement legislation. Because these deadlines are short, authorities should document their evaluation reasoning contemporaneously, and bidders who intend to contest a decision must act promptly. A well‑drafted, well‑documented procurement is the single best defence against a successful challenge.

Practical annexes and next steps for authorities and bidders

The final step in operationalising nis2 public procurement greece is to convert the guidance above into repeatable checklists.

One‑page bidder checklist

  • Confirm certification scope matches the tender.
  • Prepare redacted SOC and audit evidence.
  • Draft a NIS2 compliance statement mapped to controls.
  • Verify subcontractor flow‑down and cyber insurance limits.
  • Note challenge deadlines in case of an adverse decision.

One‑page tender drafter checklist

  • Classify the contract and choose Pathway A or B.
  • Publish an objective security baseline linked to subject matter.
  • Specify incident‑reporting SLAs and audit rights.
  • Draft proportionate exclusion and defensible evaluation criteria.
  • Include step‑in, flow‑down, penalty and termination language.

Contact counsel

For jurisdiction‑specific drafting and dispute strategy, review the Public procurement, Greece practice area, or use the Find a procurement lawyer in Greece directory. Because the Greek transposition of NIS2 and the national procurement rules continue to evolve, always confirm the current instruments before finalising any tender.

Conclusion

The decisive lesson of nis2 public procurement greece in 2026 is that cybersecurity has become a procurement‑critical variable, not a technical footnote. Contracting authorities should classify each contract early, choose strict pre‑qualification vetting for genuinely critical infrastructure and reserve flexible contractual monitoring for lower‑risk or innovation‑led procurements, and in every case draft proportionate, measurable and defensible requirements. Bidders should treat their evidence pack as a standing competitive asset. Handled well, nis2 public procurement greece protects public services and reduces dispute risk; handled poorly, it exposes authorities to challenge and suppliers to exclusion, penalties and termination. This guidance is general in nature; seek local counsel for transaction‑specific advice, and verify the current Greek transposition instruments before finalising any tender.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Nikolas Avgouleas at Fortsakis Diakopoulos & Associates, a member of the Global Law Experts network.

Sources

  1. Directive (EU) 2022/2555 (NIS2), Official Journal
  2. Directive 2014/24/EU on public procurement (consolidated text)
  3. European Commission, NIS2 overview and implementation
  4. ENISA, NIS Directive resources and guidance
  5. ENISA, Publications

Image alt: Greek public procurement team reviewing NIS2 cybersecurity tender requirements for nis2 public procurement greece.

FAQs

Does NIS2 apply to suppliers bidding for smart‑metering, e‑ID or critical infrastructure contracts in Greece?
Yes, frequently. Directive (EU) 2022/2555 classifies covered organisations as essential or important entities based on sector and size thresholds. A supplier of ICT, managed security or digital infrastructure services can be caught directly, and will in any event be subject to the supply‑chain security expectations that apply to the essential or important entity it serves. Contracting authorities should check both the supplier’s direct classification under national transposition and the relevant sector lists before finalising the tender.
Include security governance and accountability, documented risk management, a technical control baseline (access control, encryption, segmentation, vulnerability management), defined incident‑reporting timelines, and audit and testing rights. Each requirement should be measurable and linked to the contract subject matter so it remains proportionate under EU and Greek procurement law. An example smart‑metering spec appears above.
Acceptable evidence typically includes a NIS2 compliance statement, ISO 27001 certification, SOC 2 or SOC 3 reports, audit summaries, a current risk register and cyber insurance evidence. Redact sensitive technical detail while preserving scope, opinion and control summaries, and confirm that certification scope matches the exact services tendered.
Yes, provided the exclusion is proportionate and clearly linked to an objective, published security baseline. EU and Greek procurement law prohibit disproportionate exclusion criteria, so authorities should document the rationale for each requirement and apply it consistently to withstand challenge.
Contractual remedies include notice and cure, penalties, step‑in and termination for material breach with damages. Separately, national supervisory authorities may impose administrative measures on covered entities under NIS2. Procurement decisions themselves may be contested through the Greek pre‑contractual review and judicial review routes, subject to strict time limits.
Flow‑down should be mandatory for any function that affects security. Bind subcontractors to equivalent security obligations and audit rights, and keep the prime supplier liable to the authority for their performance.
Bidders should carry cyber insurance with limits aligned to the contractual liability cap, and should check exclusions carefully. Because cover and caps must work together, bespoke insurance advice is recommended for high‑value critical‑infrastructure contracts.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

NIS2 and Cybersecurity Requirements for Critical‑infrastructure Tenders in Greece (2026)

Send welcome message

Custom Message