Greece’s 2026–2030 cybersecurity strategy and SMEs
Published:
Short answer: the National Cybersecurity Strategy 2026–2030 is a policy document, not a law. It was approved by decision of the Minister of Digital Governance on 16 December 2025 and shows where policy is heading: more guidance for small businesses, but also stricter compliance and an emphasis on the supply chain. The binding obligations of businesses are set by Law 5160/2024 and other legislation.
The four strategic objectives
- Capacity building and awareness
- Strengthening national, European and international cooperation
- A cybersecurity governance system for society as a whole
- Strengthening regulatory compliance and upgrading cybersecurity policies and measures
Under these objectives the Strategy contains 19 specific objectives and an Action Plan. Under the first strategic objective, Specific Objective 1.A concerns strengthening the cyber resilience and cyber hygiene of the private sector and of small and medium-sized enterprises.
What concerns small and medium businesses
- Support and guidance: the Strategy mentions activities for small organisations and businesses with a heightened need for guidance (Specific Objective 1.A).
- Supply chain: Specific Objective 4.B concerns strengthening supply chain cybersecurity. For an SME this often means questionnaires and requirements from larger customers.
- Incident reporting and risk-management measures: Specific Objectives 3.F and 3.E.
- Coordinated vulnerability disclosure: Specific Objective 4.D provides for a national policy (CVD).
In the public consultation (10 October to 10 November 2025) participants asked, among other things, for a national SME support programme with tiered support, subsidies and maturity tools. That was a proposal of the consultation, not a decision: we have not verified a specific active subsidy programme, so check the Authority’s announcements.
What the Strategy says about threats
- Phishing remains the dominant way in, at 60% across Europe, according to the ENISA data the Strategy cites.
- DDoS attacks and ransomware incidents are rising in number and complexity. Supply chain attacks increased by 20% within a year (2023 to 2024), according to ENISA.
- The Authority’s Governor notes that most incidents start with human error, which is why the Strategy stresses knowledge and skills.
What to do (our own practical advice)
- Check whether you are in scope of NIS2 and Law 5160/2024, with our tool and the Authority’s official test.
- Even if you are not in scope, prepare for customer requests. The Authority points out that a business in the supply chain of an in-scope organisation may be contractually required to apply cybersecurity measures.
- Prioritise the basics: multi-factor authentication, tested backups, updates and staff phishing training.
- Follow the Authority’s announcements. On 29 September 2026 the Authority announced an invitation to free certified online cybersecurity courses through the European Cadmus project.
Frequently asked questions
Is the Strategy a law?
No. It is a policy document approved by decision of the Minister of Digital Governance under Article 7 of Law 5160/2024. Businesses’ obligations come from the law and its implementing acts.
What period does it cover?
The period 2026–2030. It replaces the National Cybersecurity Strategy 2020–2025.
Are there subsidies for small businesses?
The public consultation asked for a national SME support programme with subsidies, but that was a proposal by participants. We have not verified a specific active programme. Check the Authority’s announcements.