NIS2 Directive

Directive (EU) 2022/2555 on the cybersecurity of critical infrastructure across the European Union. Transposed into Greek law by Law 5160/2024.

It imposes enhanced cybersecurity requirements on "essential" and "important" entities (such as hospitals, energy providers and digital infrastructure):

  • Article 21: 10 minimum cybersecurity risk-management measures
  • Article 23: Obligation to report significant incidents within 24 hours
  • Article 20: Accountability and training of management bodies
  • Article 24: Use of European certification schemes
  • Administrative penalties: up to €10 million or 2% of global annual turnover
Greek implementation: Law 5160/2024 designates the National Cybersecurity Authority as the competent authority and provides for specific Ministerial Decisions (such as Ministerial Decision 1689/2025 for the healthcare sector) that detail the measures per sector.

ISO/IEC 27001:2022

The international standard for Information Security Management Systems (ISMS). The 2022 edition significantly refreshed the controls in Annex A:

  • 93 controls organized into 4 themes: Organizational, People, Physical, Technological
  • 11 new controls covering threat intelligence, cloud security, ICT readiness, and secure development
  • 5 attributes per control (control type, information security properties, cybersecurity concepts, operational capabilities, security domains)
  • Certification by accredited bodies (Annex SL High-Level Structure)

ISO 27799:2016

A specialization of ISO 27002 exclusively for healthcare organizations. It provides guidance for protecting the confidentiality, integrity and availability of health information.

It particularly covers: electronic health records, medical devices, medical imaging, telemedicine services, and the cross-border transfer of health data.

GDPR — Regulation (EU) 2016/679

The General Data Protection Regulation, with Greek implementation through Law 4624/2019. Especially critical for healthcare organizations due to the processing of special-category data:

  • Article 9: Health data as a special category with stricter requirements
  • Article 32: Technical and organizational security measures
  • Articles 33-34: Breach notification within 72 hours
  • Article 35: Data Protection Impact Assessment (DPIA)
  • Article 37: Data Protection Officer (DPO)
  • Administrative fines: up to €20 million or 4% of global annual turnover

EU AI Act — Regulation (EU) 2024/1689

The world's first Regulation on Artificial Intelligence. It imposes graduated obligations depending on the risk level of the AI system:

  • Prohibited practices (Article 5): social scoring, manipulative AI, real-time biometric identification
  • High-risk systems (Annex III): many systems in healthcare, education and employment
  • Transparency obligations for limited-risk systems
  • General-Purpose AI Models: new obligations for foundation models
  • Administrative fines: up to €35 million or 7% of global annual turnover
⏰ AI Act application timeline: prohibitions from February 2025, GPAI obligations from August 2025, high-risk systems from August 2026, and full application in August 2027.

IEC 62443

The international standard for the security of industrial control systems (ICS/OT). It applies to SCADA, PLCs and industrial IoT systems. Critical for:

  • Industrial facilities
  • Energy infrastructure
  • Building Management Systems (BMS) in hospitals and hotels
  • IoMT devices using industrial protocols

MDR — Medical Device Regulation 2017/745

The European Regulation on medical devices. It significantly affects medical software (Software as a Medical Device, SaMD) and IoMT devices:

  • New risk classification for SaMD
  • Cybersecurity obligation as part of the design
  • Alignment with the FDA Premarket Cybersecurity Guidance 2023
  • UDI (Unique Device Identification) for traceability

ENISA Healthcare Cybersecurity Guidelines

The guidelines of the European Union Agency for Cybersecurity (ENISA) specifically for the healthcare sector:

  • Procurement Guidelines for Cybersecurity in Hospitals (2020)
  • Cloud Security for Healthcare Services (2021)
  • Cybersecurity Threat Landscape: Health Sector
  • Good practices for IoMT, electronic health records and medical imaging

HL7 FHIR & DICOM

International interoperability standards in healthcare with significant cybersecurity dimensions:

  • HL7 FHIR: a RESTful API standard for electronic health records with built-in security profiles (SMART on FHIR)
  • DICOM: a medical imaging standard with specific security requirements for PACS and RIS systems

NIST Cybersecurity Framework 2.0

The framework of the U.S. NIST, widely adopted internationally. Version 2.0 (2024) added a new Govern function alongside the existing Identify, Protect, Detect, Respond, and Recover.

NIST SP 800-66 Rev. 2

Implementing the HIPAA Security Rule — specialized guidance for cybersecurity in healthcare. Although HIPAA is a U.S. regulation, its technical guidance is used internationally as best practice.

A multi-framework compliance methodology

In most cases, organizations do not need to comply with a single framework, but with several at once. For example, a Greek hospital must simultaneously comply with NIS2/Law 5160, GDPR, ISO 27799, MDR (for devices) and the AI Act (for AI systems).

Our methodology follows a "unified controls framework" approach:

  1. Mapping the requirements of all frameworks to a common controls catalog
  2. Gap analysis against the unified catalog
  3. Priority-based implementation that covers multiple frameworks at once
  4. A single source of truth for audits and certifications

This approach saves significant time and resources compared with parallel, framework-by-framework compliance.

Need compliance with one or more frameworks?

We start with a current-state assessment and propose a targeted implementation plan.

Schedule an assessment →
Παρήχθη με τα εργαλεία του aegiscyber.gr. Η αφαίρεση της αναφοράς προέλευσης δεν επιτρέπεται.