CRITICAL ENTITIES RESILIENCE

What Law 5236/2025 changes

Law 5236/2025, published in Government Gazette A΄ 175 of 10 October 2025, transposes Directive (EU) 2022/2557 on the resilience of critical entities into Greek law. It covers twelve sectors, the eleven of the Directive plus municipal waste management, added nationally. The competent authority and single point of contact is the General Secretariat for the Protection of Critical Entities of the Ministry of Citizen Protection.

An entity is identified as critical by the authority, against criteria set out in the law, and is then notified. The deadlines run from the date of that notification. Nine months for the entity’s own risk assessment, updated at least every four years. Ten months for the remaining obligations to apply, namely the resilience measures, the plan, the point of contact with the authority and the incident notification procedure.

Preparation done before notification is not wasted. Mapping the essential services, the dependencies and the weak points of a facility is the same work that will be required afterwards, with the difference that it is done with time to spare.

Where the law stands today

Who it applies to

The law covers twelve sectors.

  • Energy. Network operators, generation plants, oil, gas and hydrogen facilities, district heating
  • Transport. Ports, airports, rail, urban transport operators, road authorities
  • Banking. Credit institutions
  • Financial market infrastructures. Trading venues, central counterparties
  • Health. Hospitals and primary care providers, manufacture and wholesale of medicines, medical devices
  • Drinking water. Water utilities, suppliers and distributors
  • Waste water. Collection, disposal and treatment operators
  • Municipal waste. Waste management facilities
  • Digital infrastructure. Providers of electronic communications networks and services, data centres, trust services
  • Public administration. Central government bodies
  • Space. Ground infrastructure operators
  • Food. Industrial production and processing, supply chain, wholesale

Municipalities and regions are not a separate sector. They fall within scope through the services they provide, mainly water, waste water and municipal waste.

Not every entity in a sector is critical. The law sets three conditions that must all be met. The entity provides one or more essential services, its critical infrastructure is located on Greek territory, and an incident would cause significant disruption to the provision of that service.

To determine how significant a disruption is, the law lists six criteria. The number of users relying on the service. The extent to which other sectors depend on it. The scale and duration of the impact on economic and social activities, the environment, public safety and health. The entity’s market share. The geographical area that would be affected, taking into account the degree of isolation, that is whether the area is insular, mountainous or remote. And the availability of alternative means of providing the same service.

Three sectors are treated differently. Banking, financial market infrastructures and digital infrastructure are identified as critical entities, but they do not carry the obligations described below, as they are covered by other frameworks.

What the law requires

Risk assessment. Within nine months of notification, and at least every four years thereafter. It covers all relevant natural and man-made risks, from natural disasters and accidents to hybrid threats and terrorism, as well as risks arising from technological developments and from changing climatic or socio-economic conditions. It works in both directions, which sectors depend on your service and which services of others you depend on, including neighbouring states and third countries where relevant. Existing assessments produced for other obligations may be used. Article 13.

Resilience measures and plan. Appropriate and proportionate technical, organisational and security measures across six areas:

  • preventing incidents, including climate change adaptation
  • adequate physical protection of facilities and critical infrastructure, where the law expressly names fences, barriers, perimeter monitoring, detection equipment and access controls
  • responding to and mitigating the consequences of incidents, with crisis management and early warning procedures
  • recovery and business continuity, with alternative supply chains
  • personnel security management, with categories of critical roles, access rights and qualification requirements
  • staff familiarisation with the above, through training, awareness material and exercises

All of it documented in a resilience plan. Article 14.

Point of contact. A representative or authorised officer with appropriate qualifications and expertise, handling communication with the authority and internal coordination of compliance. Article 14.

Background checks on personnel. For individuals in sensitive roles or with access, physical or remote, to facilities and systems. Requests are submitted to the competent Directorate of Hellenic Police Headquarters. Article 15.

Incident notification. Without undue delay for any incident that significantly disrupts the provision of essential services, with an initial notification no later than twenty-four hours from the moment the entity becomes aware, and a detailed report within one month. Article 16.

Supervision and sanctions. The authority carries out on-site inspections of infrastructure and facilities, exercises local and remote supervision of the measures, and conducts or commissions audits. It requests information and evidence demonstrating the actual implementation of the measures. Administrative sanctions are provided for. Articles 22 and 23.

What we do

Scope assessment
We establish whether the entity falls within scope, through which essential service and on what grounds, against the three conditions and six criteria of the law. We deliver a file of supporting evidence, so that the organisation is ready when the authority asks for information.

Critical entity risk assessment
Field work. Mapping of essential services and their tolerance to interruption, a risk register covering the full range of threats the law requires, analysis of dependencies and suppliers, identification of the points where one failure pulls the rest down with it. Where studies already exist from other obligations, we assess and use them rather than rewrite them.

Resilience Plan
Structured according to the six areas of measures in the law, with names, timings and owners. Action cards per role, degraded-mode protocols, alternative supply chains, a crisis communication plan. In the personnel security chapter we define the categories of critical roles, the access rights and the procedure for background check requests to the Hellenic Police.

Implementation of physical protection measures
Perimeter, access control, detection, remote monitoring, image reception centre. These are the measures the law names expressly, and we install and support them.

Early warning and evidence with DEDALUS
Our platform brings the facility’s measurements into a single picture and tracks margins, not only instantaneous values. The law requires early warning procedures and evidence demonstrating the actual implementation of the measures.

It also requires an initial notification of an incident within twenty-four hours from the moment the entity becomes aware. That moment is not neutral. When awareness arrives by telephone, the clock has already been running. When it arrives from your own system, it starts at the beginning and with data in hand.

DEDALUS provides both, the procedure in operation and the record that substantiates it in front of an auditor.

Point of contact and notification procedure
Definition of the role and its qualifications, notification thresholds tailored to your service, reporting templates for the initial notification and for the one-month report, and an internal definition of the moment the entity becomes aware, so that the timing cannot be disputed.

Exercises and inspection readiness
Exercises based on scenarios drawn from your own facility, with measurable outcomes, and an evidence register that answers an auditor’s question without a search.

For wider staff training, see Strategic Security.

How we work

We start in the field. We measure the actual load pick-up time of the generator set. We look at which circuit the critical supplies sit on. We find where the utility cables enter the building, because that is usually where the second route turns out to be the first one. We record the height of the electrical panel above floor level, against the flood line. The plans that hold up are the ones built on measurements.

Our methodological framework is the Daedalic Methodology. It works on the logic of two international standards, ISO 31000 for risk management and ISO 22301 for business continuity, and concentrates on three things. Reading slow change while it is still change and has not yet become an event. Setting action thresholds before the crisis rather than inside it. And protecting the capacity to decide when time is short. The reference to the standards is methodological.

Since 2010 we have designed and implemented security and resilience solutions for organisations, urban transport operators, municipalities and regions. In 2019 we received first prize at the 3rd Innovation Marathon for Smart Cities of the Central Union of Municipalities of Greece, for the development of a Holistic Security Model for Cities.

How a project runs

1. First conversation. One hour. We establish whether and how this affects you.

2. Field survey. Site visit, measurements, interviews, collection of evidence.

3. Risk assessment. Risk register, dependencies, thresholds.

4. Resilience Plan. A deliverable ready for management approval and for review by the authority.

5. Implementation. Installation of measures and systems, with DEDALUS where continuous monitoring is needed, activation of procedures, staff training.

6. Maintaining compliance. Exercises, updates, inspection readiness.

You can join at any stage. If you already have studies, we assess them rather than rewrite them.


Let’s talk

Tell us which service you provide and who stops being served if it is interrupted. We will tell you whether you are likely to be identified as a critical entity, what will be asked of you and where it is worth starting.

info@securitydefence.gr | +30 210 244 2560 | +30 693 683 3270

This text is for information only and does not constitute legal advice.

Κρίσιμη υποδομή με περίφραξη ασφαλείας, υδατόπυργος, πυλώνας μεταφοράς και δεξαμενές
Menu