NIS2 compliance checklist for postal and courier operators — cybersecurity network concept

Postal and Courier NIS2 Checklist: USP Designation, WMS/TMS Asset Register, and ICS2 EDI Security

Three questions decide whether NIS2 demands anything from your organisation: Do you perform any step in the postal delivery chain? Do you meet the medium-enterprise size threshold? Has your member state elevated your classification beyond the default? Answer all three before you build a single compliance document.

This checklist covers the four areas where postal and courier operators most often stall: confirming scope and Universal Service Provider (USP) status, building a WMS/TMS operational asset register, checking customs EDI exposure under ICS2, and mapping Article 21(2)(a)–(j) to postal-specific controls. For a broader overview of how Annex II applies to your sector, see our NIS2 compliance priorities for postal and courier services.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Who NIS2 Catches: Scope and Applicability

Directive (EU) 2022/2555 places postal and courier services in Annex II (“Other Critical Sectors”), making in-scope operators Important entities by default. Recital 12 of NIS2 sets the functional boundary: your organisation falls in scope if it provides at least one step in the postal delivery chain — clearance, sorting, transport, distribution, or pick-up of postal items. [1]

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Annex II covers “postal service providers as defined in Article 2, point (1a), of Directive 97/67/EC, including providers of courier services.” [4] That language is intentionally broad: a B2B parcel network, a last-mile courier aggregator, and a national postal incumbent all sit under the same heading if they meet the size test.

Operator type Activity Meets size threshold? NIS2 status
National postal incumbent (USP) Full delivery chain Almost always Important entity; may be elevated to Essential by member state
B2B parcel network (50–249 employees) Sorting + delivery Yes (medium enterprise) Important entity
Last-mile courier (under 50 employees) Delivery only No Out of scope (unless member state designates)
Pure freight haulier Transport only (not postal chain) Irrelevant Out of scope under NIS2 Annex II

Size thresholds (per Commission Recommendation 2003/361/EC): 50–249 employees or annual turnover €10M–50M = medium enterprise (Important entity). 250+ employees or €50M+ turnover = large enterprise (Important entity). Both tiers face the same Annex II obligations; size affects penalties and supervisory intensity rather than which measures apply.

Member state elevation: Several EU member states have used their national NIS2 transposition laws to designate individual operators as Essential entities, even where those operators would default to Important entity status under Annex II. This elevation is exercised more readily for USPs given the critical role of universal postal coverage. Check your national transposition and the published scope determinations of your national supervisory authority for the current criteria.

Penalties for Important entities: Article 34(5) sets the ceiling at €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher, for breaches of Articles 21 or 23. [3]

USP Designation Confirmation — 5-Item Checklist

If your organisation is the designated Universal Service Provider under national postal regulation (Directive 97/67/EC), your compliance posture carries additional weight: your NRA for postal services is often also your NIS2 supervisory authority, your network is critical to national communications infrastructure, and member states are more likely to exercise their national elevation powers for USPs than for commercial couriers. [9]

Run through these five checks before you classify your own risk exposure:

  1. Formal USP designation on file. Does your organisation hold a written designation as Universal Service Provider issued by the national postal regulatory authority? If yes, retain a copy and note the effective date — this document is evidence you provide a nationally critical service and should sit in your compliance register.
  2. Supervisory authority mapping. Which national authority supervises your NIS2 compliance? In several EU member states the postal NRA (the body that designated you as USP) serves dual roles — postal regulator and NIS2 competent authority for your sector. Confirm the authority name and whether you have completed registration or notification under the national NIS2 transposition.
  3. Essential entity check. Has your national authority notified you of an Essential entity designation under your national NIS2 transposition? Essential entities face proactive supervision (audits without a prior incident trigger) and stricter reporting timelines. If you are unsure, request written confirmation from your supervisory authority.
  4. Universal service geography. Your USP obligation requires coverage of the full national territory. That typically means more distributed infrastructure — regional depots, rural collection points, automated parcel lockers — each of which represents a network node that must appear in your NIS2 asset inventory.
  5. Regulatory reporting overlap. USPs already report service quality and continuity data to their postal NRA. Identify where NIS2 incident notification (Article 23, 24-hour initial notification to the national CSIRT) overlaps with existing USO reporting obligations, to avoid duplicate or contradictory disclosures to the same authority. See our postal sector incident reporting guide for the timeline breakdown.

WMS/TMS Operational Asset Register

Article 21(2)(i) of NIS2 requires asset management as part of human resources security and access control obligations. For postal and courier operators, that means building an inventory before you can do anything else — without it, your risk assessment has no input, your access control has no scope, and your incident response has no asset list to work from. [2]

Postal operations typically run three classes of operational technology not found in office-only environments, and each needs separate treatment in your register. [6]

Tier 1 — Mission-critical systems (full risk assessment + MFA required):

  • Warehouse Management System (WMS) — controls physical parcel flow, sort assignment, and depot inventory. A breach or availability failure directly disrupts delivery commitments and triggers reportable incidents.
  • Transport Management System (TMS) — route planning, driver dispatch, consignment tracking. Often cloud-hosted with API integrations to carrier partners and customers.
  • Customs EDI gateway — the interface between your systems and ICS2 / national customs authorities for Entry Summary Declaration (ENS) filing. Treat as Tier 1: a compromised EDI channel can generate fraudulent customs declarations under your EORI number.
  • Parcel tracking platform — customer-facing but shares data with WMS and TMS; a common attack surface for data theft and supply chain manipulation.

Tier 2 — Supporting systems (standard risk assessment + access controls):

  • Fleet telematics and GPS tracking systems
  • Last-mile delivery driver apps (particularly relevant where gig-economy contractors use personal devices)
  • Automated parcel lockers and their management consoles
  • HR and payroll platforms (relevant to Article 21(2)(i) HR security)

Tier 3 — Peripheral and OT assets (inventory + basic controls):

  • Sorting line PLCs and SCADA systems in automated depots
  • Barcode scanners, RFID readers, and handheld terminal devices
  • Depot CCTV and access control hardware
  • Wi-Fi networks serving warehouse floor scanning operations

For each asset, capture the fields required by Article 21(2)(i): asset identifier, category (hardware/software/cloud/OT), owner (named individual or team), physical or logical location, criticality tier, and the key risk associated with loss of availability or confidentiality. [8] Review our dedicated NIS2 asset management guide for the full data model and asset register structure.

Network segmentation applies across all three tiers. Warehouse floor OT (sorting lines, PLCs) must be isolated from the corporate IT network, and WMS/TMS systems with external API connections should sit in a DMZ or behind dedicated firewall rules rather than on a flat enterprise network. [6]

Customs EDI Security — ICS2 and Your ENS Filing Surface

The EU’s Import Control System 2 (ICS2) creates a direct security obligation that most NIS2 compliance guides for the postal sector overlook. Since 1 September 2025, ICS2 has been mandatory across all transport modes — air, maritime, road, and rail — and Release 1 of the system was specifically scoped to postal and express consignments. [5] If your organisation files Entry Summary Declarations (ENS) for inbound shipments, your customs EDI integration is now a regulated interface with two separate compliance dimensions.

ICS2 as a security surface under NIS2: The EDI connection between your TMS or customs platform and the ICS2 Shared Trader Interface (STI) must be treated as a critical external integration. A compromise of this interface — whether via credential theft, API injection, or a supply chain attack on your customs software vendor — could result in fraudulent ENS submissions under your Economic Operator Registration and Identification (EORI) number, triggering customs enforcement action against your organisation.

Four checks for your ICS2/EDI security:

  1. Credential isolation. Are the credentials used to authenticate your organisation to the ICS2 STI stored separately from general IT credentials? EORI-related API keys and certificates must be in a secrets management system, not in application configuration files or shared developer accounts.
  2. Vendor assessment. If you file ENS through a third-party customs broker or freight forwarding software, that vendor is a direct supplier under Article 21(2)(d). Your supply chain security documentation must include a security assessment of that vendor’s data handling and access controls. See our NIS2 supply chain security guide for the vendor assessment framework.
  3. Anomaly monitoring. Your SOC or network monitoring must cover ENS submission volumes and patterns. Unexpected spikes in declaration volume, off-hours submissions, or declarations for consignment types you do not handle are early indicators of a compromised EDI channel.
  4. Incident classification. A confirmed compromise of your ICS2 EDI integration qualifies as a significant incident under Article 23 of NIS2 — it disrupts an essential service (movement of postal items through customs) and involves unauthorised access to a critical system. The 24-hour early warning timeline applies from the moment you detect the compromise, not when customs authorities notify you.

Article 21(2)(a)–(j) Applied to Postal Operations

Article 21(2) of NIS2 lists ten categories of cybersecurity risk-management measures that Important entities must implement, applying an all-hazards approach proportionate to risk. [2] The following checklist translates each measure into postal-sector terms. Note that CIR 2024/2690 — the implementing regulation that adds technical specification to Article 21 — applies directly only to digital infrastructure providers (DNS registries, cloud services, managed service providers, and trust service providers). Postal operators are not directly bound by CIR 2024/2690 but can use it as a technical benchmark, particularly for access control and cryptography requirements. [7]

Article 21(2) Measure Postal/courier application Status
(a) Risk analysis and information security policies Annual risk assessment covering WMS, TMS, EDI gateways, OT sorting systems, and driver apps. Policy must be approved at management level (Article 20 management accountability). □ In place / □ Gap
(b) Incident handling Documented procedure for detecting, containing, and reporting incidents on parcel tracking, depot OT, and EDI systems. 24-hour early warning to national CSIRT per Article 23. See Article 21(2)(i) detail for postal operations. □ In place / □ Gap
(c) Business continuity, backup, disaster recovery WMS and TMS failure scenarios must have documented recovery procedures with tested RTO/RPO targets. USPs additionally need plans for prolonged outages that affect universal service delivery commitments. □ In place / □ Gap
(d) Supply chain security Security requirements for: customs software vendors (ICS2/EDI), last-mile subcontractors with access to parcel data, WMS/TMS cloud providers, and GPS/telematics vendors. Written security clauses required in contracts. □ In place / □ Gap
(e) Security in system acquisition, development, and maintenance Security requirements included in tenders for WMS/TMS upgrades. Vulnerability patching schedule documented. Penetration testing of customer portals and EDI interfaces before major changes. □ In place / □ Gap
(f) Assessment of cybersecurity measure effectiveness Annual internal audit or third-party review of controls. KPIs tracked: mean time to detect incidents, patch compliance rate, access review completion rate. □ In place / □ Gap
(g) Cyber hygiene and training Security awareness training covering phishing (parcel delivery notification lures are a well-documented social engineering vector targeting both postal staff and recipients), password management, and BYOD policy for delivery drivers. □ In place / □ Gap
(h) Cryptography and encryption Encryption at rest for parcel recipient data in WMS databases. TLS 1.2+ for all customer-facing portals and EDI connections. Key management documented with rotation schedule. □ In place / □ Gap
(i) Human resources security, access control, asset management Background checks for staff with privileged WMS/TMS access. Seasonal worker credential lifecycle: provisioned before first shift, reviewed monthly, deprovisioned within 24 hours of departure. Asset register per the Tier 1–3 framework above. □ In place / □ Gap
(j) MFA, secured communications, emergency systems MFA mandatory for all remote access to WMS, TMS, and depot management consoles. Gig-economy drivers accessing delivery apps via personal devices: enforce MFA + mobile device management (MDM) as a minimum. □ In place / □ Gap

Who Owns What: Role Matrix for Postal NIS2 Compliance

Article 20 of NIS2 places personal accountability on management bodies: they must approve, oversee, and be trained on cybersecurity risk-management measures. For postal and courier operators, four roles typically share compliance ownership:

Role Primary NIS2 ownership Key actions
CISO / IT Security Manager Article 21(2) implementation; asset register; incident detection Build Tier 1–3 asset register; configure monitoring for WMS/TMS and EDI; run Article 21 gap analysis
COO / Operations Director Business continuity (Art. 21(2)(c)); WMS/TMS availability; driver/contractor security Approve RTO/RPO targets; ensure gig-economy driver device policy is enforced; sign off depot OT security measures
Compliance / Legal Registration with supervisory authority; USP designation file; incident notification to CSIRT and NRA Confirm authority identity; maintain designation documents; prepare Article 23 notification templates
Board / Management body Article 20 accountability; policy approval; training completion Approve risk management policy; attend NIS2 management training; receive quarterly security KPI report

Frequently Asked Questions

Does NIS2 apply to a courier operating only in one EU member state?
Yes, if you meet the size thresholds (50+ employees or €10M+ annual turnover) and perform at least one step in the postal delivery chain, NIS2 applies regardless of whether your operations cross borders. The directive applies at the member state level — your obligations are to the national supervisory authority in the country where you are established.

Are parcel lockers in scope as NIS2 assets?
Yes. Automated parcel locker networks are operational technology connected to your WMS and customer portal. Each locker management console and its communication channel to your central systems must appear in your asset register. A ransomware attack that locks parcel locker access across your network would likely qualify as a significant incident under Article 23(3) — causing severe operational disruption to your services.

What is the timeline for incident notification?
Article 23 of NIS2 establishes a three-stage notification timeline: early warning to the national CSIRT within 24 hours of becoming aware of a significant incident; a more detailed notification within 72 hours; and a final report within one month. For postal operators, “significant” means an incident with substantial impact on the delivery of your services or on the data of recipients. See our Article 23 incident notification guide for the full assessment framework.

Does CIR 2024/2690 apply to our postal operator?
No. CIR 2024/2690 (Commission Implementing Regulation (EU) 2024/2690) directly applies only to DNS service providers, TLD registries, cloud computing providers, managed service providers, managed security service providers, online marketplace providers, social networking platforms, and trust service providers. Postal and courier operators are not named in Article 1 of CIR 2024/2690. However, its technical specifications for access control and incident handling are a useful voluntary benchmark for your Article 21 implementation.

Sources

  1. Directive (EU) 2022/2555 (NIS2 Directive) — EUR-Lex, European Parliament and of the Council
  2. NIS 2 Directive, Article 21: Cybersecurity risk-management measures — nis-2-directive.com
  3. NIS 2 Directive, Article 34: Administrative fines relating to important entities — nis-2-directive.com
  4. NIS2 Annex II — Other Critical Sectors — LuxGAP
  5. Import Control System 2 (ICS2) — European Commission, Taxation and Customs Union
  6. NIS2 for Logistics and Transportation — nFlo
  7. CIR 2024/2690 — NIS2 Technical Measures — NISD2.eu
  8. NIS2 Asset Inventory Requirements — Trout Software
  9. Directive 97/67/EC (Postal Services Directive) — EUR-Lex, European Parliament and of the Council. Available at: https://eur-lex.europa.eu/eli/dir/1997/67/oj/eng
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: