Table of Contents
YASPE on NIS2 Directive
On August 5, 2025, Ministerial Decision 1899/2025 was published in the Government Gazette (FΕΚ B’ 4250), which clearly and authoritatively defines the role of the Information and Communications Systems Security Officer (Y.A.S.P.E.) under the implementation of Law 5160/2024 – the Greek transposition of the EU NIS2 Directive. This decision represents a pivotal moment for Basic and Significant Entities, turning the Y.A.S.P.E. role from a “formal compliance task” into a central pillar of cybersecurity governance.
Which companies does it concern
The Government Gazette applies as of November 1, 2025 to both Basic Entities and Significant Entities as defined in Article 4 of Law 5160/2024 (NIS2). Practically, this includes organizations in critical sectors such as energy, transport, healthcare, digital infrastructures, ICT providers, cloud services, managed services, and selected central government bodies
Who can be appointed as Y.A.S.P.E.
The Y.A.S.P.E. must be an executive or staff member of the entity (or, in exceptional cases, a staff member of another company within the same corporate group), possessing:
sufficient understanding of the entity’s business processes, and
demonstrable experience or training in information security and cybersecurity.
Minimum qualifications include one of the following:
a university or postgraduate degree in a relevant field, or
at least 5 years’ experience in cybersecurity, or
professional certifications and at least 2 years of experience.
Additionally, a mandatory background check is required, including a criminal record and evaluation of professional ethics and integrity, conducted with proportionality and in accordance with data protection and ethical standards.
Role Incompatibilities
The decision explicitly states that the Y.A.S.P.E. cannot simultaneously hold the roles of:
Data Protection Officer (DPO), or
Head of IT / Chief Information Officer.
This restriction is critical to ensure independence and avoid conflicts of interest, enabling effective oversight of cybersecurity.
Core Duties and Responsibilities
The strategic role of the Y.A.S.P.E. includes:
Supervising risk management measures under Article 15 of Law 5160/2024.
Serving as the primary point of contact with the National Cybersecurity Authority.
Coordinating incident reporting and communications with the CSIRT.
Developing and securing approval for the entity’s unified cybersecurity policy.
Participating in inspections and audits.
Ensuring security of the ICT supply chain.
Providing training to management and personnel.
Direct reporting to the highest administrative level.
Additionally, the Y.A.S.P.E. must monitor technological developments and security tools to keep the organization resilient against emerging threats.
Declaration and Oversight
The appointment of the Y.A.S.P.E. must be formally declared via the digital platform of the Ministry of Digital Governance. The National Cybersecurity Authority retains enhanced oversight, control, and evaluation powers over the suitability of the role.
What it means in practice for Companies
Compliance with Government Gazette 4250/2025 requires:
Organizational redesign.
Clear separation between IT, Security, and Privacy functions.
Documented registries, processes, and policies.
Ongoing reporting to management and the regulatory authority.
Importantly, the Y.A.S.P.E. is not a decorative role. The organization’s accountability for securing critical systems runs through this officer.
How we can support you
Ministerial Decision 1899/2025 makes it clear that cybersecurity is no longer optional. It is a regulatory obligation with defined roles, responsibilities, and consequences. We support organizations in preparing early and effectively for compliance.
Timely preparation includes:
Gap analysis against the NIS2 Directive and the National Cybersecurity Requirements Framework.
Support in appointing and strengthening the Y.A.S.P.E. role, ensuring independence and governance alignment.
Design and implementation of policies, procedures, and security registries.
Executive and staff training to ensure awareness, accountability, and regulatory compliance.
Preparation for supervisory authority oversight and inspections.
Security assessments, including IT Security Audits and Penetration Testing.
Greek Government Gazette 4250/Β/05.08.2025: https://search.et.gr/el/fek/?fekId=785302