Our Expert in Greece
No results available
NIS2 public procurement Greece is the compliance challenge that contracting authorities, bidders and in‑house counsel cannot afford to get wrong in 2026, as the transposition of the NIS2 Directive reshapes the risk profile of every technology‑heavy public contract. From smart‑metering rollouts to national e‑ID platforms and electricity‑grid modernisation, procurement teams are rewriting technical specifications, exclusion grounds and contract clauses to reflect a legal regime that treats cybersecurity as a procurement‑critical requirement rather than an afterthought. This article sets out, in operational terms, exactly what awarding authorities and suppliers must do, with a decision framework, model clause language and an evidence checklist you can adapt directly.
It takes a clear position: for the highest‑risk critical infrastructure, strict pre‑qualification vetting beats flexible post‑award contracting, and we explain precisely when that rule flips.
Who this is for: contracting authorities, bidders and in‑house counsel evaluating procurement risk and tender drafting in Greece.
What you will learn: NIS2 scope and applicability, tender technical specifications, bidder evidence, exclusion grounds, model contract clauses, enforcement and remedies.
20‑second action list: confirm whether the contract touches an essential or important entity; choose a compliance pathway; embed proportionate cyber criteria; specify incident‑reporting SLAs; demand credible evidence; draft defensible exclusion and termination language.
The practical implications of nis2 public procurement greece can be reduced to a short list of immediate actions. If you read nothing else, act on these.
For contracting authorities:
For bidders:
See the comparison table below for the full decision matrix.
The starting point for any analysis of nis2 public procurement greece is scope. NIS2 does not regulate procurement directly, but it redefines which organisations must meet stringent cybersecurity obligations, and those obligations then flow into how public bodies must specify, evaluate and contract for technology and infrastructure services. In Greece, the Directive is given effect through national transposition legislation, and the National Cybersecurity Authority is the competent body for cybersecurity supervision; practitioners should verify the current transposition instrument and any implementing decisions before relying on specific provisions.
Directive (EU) 2022/2555 (NIS2) distinguishes between essential and important entities across sectors including energy, transport, digital infrastructure, public administration, water and health. Classification depends on the sector and on size thresholds set out in the Directive, with larger operators in high‑criticality sectors typically falling into the essential category and subject to the most intensive supervision. Both categories must implement risk‑management measures and incident‑reporting obligations; the difference lies principally in the intensity of supervisory oversight and the enforcement regime.
Crucially for procurement, an entity does not escape NIS2 simply because it supplies a public body rather than operating infrastructure itself. Where a supplier delivers ICT services, managed security services or digital infrastructure that underpins an essential entity, it may itself be caught, and it will in any event be subject to the supply‑chain security expectations that NIS2 places on its customers. Contracting authorities must therefore check both the direct classification of the supplier and the indirect obligations that attach because the authority, or the end user of the contract, is an essential or important entity.
NIS2 operates alongside, not instead of, the procurement framework. In Greece, EU procurement rules (including Directive 2014/24/EU) are implemented principally through the national public procurement legislation, which governs procedures, award criteria, exclusion grounds and, critically, the principle of proportionality. Any cybersecurity requirement embedded in a tender must be linked to the subject matter of the contract and must not disproportionately restrict competition. This is the central tension in nis2 public procurement greece: authorities must be demanding enough to protect critical systems, yet restrained enough that their criteria withstand challenge. The remainder of this article is built around resolving that tension.
Certain Greek verticals sit squarely at the intersection of NIS2 and procurement. Smart‑metering programmes involve very large numbers of connected endpoints and back‑office data platforms. National e‑ID and e‑government identity systems process sensitive personal data and underpin public trust. Grid modernisation touches operational technology whose compromise carries systemic and safety consequences. Transport control and ticketing systems combine safety‑critical operational technology with large personal‑data estates. In each of these, cybersecurity procurement requirements are not optional refinements, they are load‑bearing elements of the contract.
Contracting authorities broadly face a strategic choice between two compliance pathways. We recommend deciding this before drafting the tender, because the choice drives everything from evaluation criteria to the length of the security annex. The table below sets the two approaches side by side.
| Dimension | Pathway A, Pre‑qualification & exclusion focus (strict vetting) | Pathway B, Contractual & monitoring focus (flexible contracting) |
|---|---|---|
| Legal basis | Embed NIS2 expectations into selection criteria and exclusion grounds; rely on procurement law to exclude non‑compliant suppliers | Rely on award criteria and robust contract clauses to secure compliance post‑award |
| Typical use case | High‑risk critical infrastructure where supplier failure means systemic risk (grid control, national e‑ID) | Lower‑risk or time‑sensitive procurements where the market is narrow (certain IT services) |
| Time and cost impact | Longer timeline; more administrative burden up front; potentially fewer bidders | Faster award; more contract‑drafting time; ongoing monitoring costs |
| Evidence required | Formal certificates, NIS2 compliance statements, audit/SOC reports, risk registers, insurance evidence | Security plans, incident response plan, contractual security SLAs, audit and monitoring rights |
| Enforceability | High at pre‑award through clear exclusion decisions; risk of challenge if criteria are poorly drafted | Enforceable via breach remedies; may require proof of breach and litigation to force change |
| Liability allocation | Reduces post‑award enforcement risk but increases upfront procurement risk | Authority retains contractual remedies; supplier bears ongoing compliance and insurance costs |
| Contract drafting focus | Shorter security annex (compliance assumed pre‑award) plus termination for material cyber breach | Detailed obligations, reporting, audits, step‑in, subcontractor flow‑downs, penalties |
| Procurement risk | Contestation if criteria are disproportionate; may limit competition | Supplier non‑performance post‑award and longer remediation |
| Best for | Critical systems with low risk tolerance where public safety or national security is implicated | Complex systems where innovation and market access matter and continuous oversight is feasible |
| Decision outcome | Favours selecting only demonstrably compliant suppliers | Preserves competition but demands stronger contract management |
Our recommendation: for critical infrastructure where a supplier failure would create systemic or public‑safety consequences, Pathway A is the correct default. The cost of a longer, narrower procurement is small compared with the cost of managing a non‑compliant supplier into remediation while critical services are exposed. Reserve Pathway B for lower‑risk, innovation‑driven or genuinely time‑critical procurements where you have the resources to run active contract management.
Whichever pathway you select, the tender must translate NIS2 principles into cybersecurity procurement requirements that suppliers can price and evaluators can score. Vague aspirations toward “good security” are unenforceable and legally fragile; specific, measurable requirements are both.
NIS2 requires covered entities to implement appropriate and proportionate technical, operational and organisational risk‑management measures, and ENISA guidance elaborates these into practical controls. For tender specifications, a defensible baseline typically covers:
SMART METERING, example spec (sample wording, adapt with local counsel):
“The Supplier shall implement end‑to‑end encryption between metering endpoints and the head‑end system, maintain ISO 27001 certification covering the metering data platform for the full contract term, segment operational technology networks from corporate networks, and detect and report security incidents affecting metering data or availability to the Authority within the timelines set out in the Security Annex.”
This kind of specification is enforceable because each element is measurable. It also reflects the reality that smart‑metering procurement cybersecurity risk spans both large endpoint estates and centralised data platforms.
Where security is scored rather than gated, award criteria must be transparent and weighted in advance. We recommend assigning explicit points to demonstrable certification, the quality of the incident response plan, the maturity of supply‑chain controls and the credibility of the proposed security roadmap. Publish the scoring methodology so that unsuccessful bidders can understand, and, where necessary, lawfully challenge, the outcome. The proportionality principle under EU and Greek procurement law requires that the weighting reflect genuine contract risk rather than an arbitrary preference.
For bidders, success in nis2 public procurement greece increasingly turns on the quality and readiness of the evidence pack. Authorities are entitled to demand substantiation, and the strongest bids treat evidence as a standing asset rather than a last‑minute scramble.
BIDDER QUICK‑WIN, 48‑hour checklist:
Third‑party attestations carry particular weight because they reduce the authority’s verification burden. When submitting SOC or audit reports, bidders should redact sensitive technical detail while preserving the scope, opinion and control summary that evaluators need. Supplier cyber due diligence is a two‑way process: authorities should specify in advance which attestations they will accept, and bidders should confirm their evidence maps precisely to those requirements rather than assuming a general certification will suffice.
The contract is where cybersecurity obligations become enforceable. Under Pathway B especially, the security annex does the heavy lifting; even under Pathway A, robust termination and incident clauses remain essential. The snippets below are illustrative starting points.
Sample wording, adapt with local counsel:
“The Supplier shall maintain, throughout the Term, the technical and organisational security measures set out in the Security Annex to a standard no lower than that represented in its tender, and shall not degrade any material control without the Authority’s prior written consent.”
Sample wording, adapt with local counsel:
“The Supplier shall notify the Authority of any security incident affecting the Services without undue delay and in any event within the timeframe specified in the Security Annex, shall cooperate fully with the Authority’s and any competent authority’s investigation, and shall provide all information reasonably required to enable the Authority to meet its own regulatory reporting obligations.”
Note that the drafting deliberately anchors the internal contractual deadline to the Security Annex so it can be aligned with the authority’s own statutory reporting duties under the national transposition of NIS2. Those statutory reporting timelines are set out in NIS2 and the Greek transposing legislation and should be verified against the current text before the annex is finalised.
Sample wording, adapt with local counsel:
“On the occurrence of a material cyber breach that threatens the security or continuity of the Services, the Authority may exercise step‑in rights to procure remediation, and the Supplier shall ensure that all security obligations under this Contract are flowed down to any subcontractor performing security‑relevant functions, together with equivalent audit rights.”
Flow‑down is not optional for functions that affect security. Any subcontractor touching security‑relevant processing should be bound by equivalent obligations, and the prime supplier should remain liable to the authority for their performance.
Sample wording, adapt with local counsel:
“The Supplier shall maintain cyber insurance with limits not less than those specified in the Contract, and the parties agree that liability arising from a cyber incident caused by the Supplier’s breach shall be subject to the enhanced cap set out in Schedule [X], which shall not be lower than the available insurance cover.”
Aligning contract cyber incident clauses with actual insurance cover avoids the common trap of a liability cap that is unenforceable in practice because it exceeds the supplier’s ability to pay.
Understanding enforcement is central to nis2 public procurement greece, because it defines both the leverage authorities hold and the exposure bidders face.
Procurement exclusion on cybersecurity grounds is lawful, but only where it is proportionate and clearly linked to the contract. EU and Greek procurement law prohibit disproportionate exclusion criteria, so an authority that excludes a bidder for failing an objective, published security baseline stands on solid ground, while one that applies vague or shifting standards invites successful challenge. Separately, NIS2 gives national supervisory authorities enforcement powers over covered entities, including the ability to impose administrative measures and, in defined circumstances, significant administrative fines, a regulatory exposure that sits alongside, and independently of, any contractual consequence.
Where a supplier breaches cyber obligations after award, the contract should provide a graduated remedial ladder: notice and cure, contractual penalties, step‑in, and ultimately termination for material breach with damages. Building this ladder into the contract at drafting stage, rather than relying on general breach principles, gives the authority predictable, enforceable leverage and reduces the likelihood of protracted litigation.
Both bidders and authorities must be alert to the procedural remedies available in Greece. Unsuccessful bidders may challenge award and exclusion decisions through the available pre‑contractual review and judicial routes, subject to strict time limits set out in the applicable Greek procurement legislation. Because these deadlines are short, authorities should document their evaluation reasoning contemporaneously, and bidders who intend to contest a decision must act promptly. A well‑drafted, well‑documented procurement is the single best defence against a successful challenge.
The final step in operationalising nis2 public procurement greece is to convert the guidance above into repeatable checklists.
For jurisdiction‑specific drafting and dispute strategy, review the Public procurement, Greece practice area, or use the Find a procurement lawyer in Greece directory. Because the Greek transposition of NIS2 and the national procurement rules continue to evolve, always confirm the current instruments before finalising any tender.
The decisive lesson of nis2 public procurement greece in 2026 is that cybersecurity has become a procurement‑critical variable, not a technical footnote. Contracting authorities should classify each contract early, choose strict pre‑qualification vetting for genuinely critical infrastructure and reserve flexible contractual monitoring for lower‑risk or innovation‑led procurements, and in every case draft proportionate, measurable and defensible requirements. Bidders should treat their evidence pack as a standing competitive asset. Handled well, nis2 public procurement greece protects public services and reduces dispute risk; handled poorly, it exposes authorities to challenge and suppliers to exclusion, penalties and termination. This guidance is general in nature; seek local counsel for transaction‑specific advice, and verify the current Greek transposition instruments before finalising any tender.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Nikolas Avgouleas at Fortsakis Diakopoulos & Associates, a member of the Global Law Experts network.
Image alt: Greek public procurement team reviewing NIS2 cybersecurity tender requirements for nis2 public procurement greece.
posted 4 seconds ago
posted 22 minutes ago
posted 31 minutes ago
posted 44 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message