NIS2 space sector compliance — satellite ground station dish antennas and mission control facility

Your Ground Station Fell Under NIS2 in October 2024 — Your Satellite Didn’t

On the morning of 24 February 2022, as Russian tanks crossed into Ukraine, a cyberattack struck the KA-SAT satellite network operated by Viasat. The attack — later attributed to AcidRain, a wiper malware with Russian origins — did not affect a single satellite. It hit the ground segment: the terrestrial infrastructure managing KA-SAT’s modem fleet. Within hours, 5,800 Enercon wind turbines in Germany lost their remote monitoring and control connections, disrupting an estimated 11 GW of generating capacity across Europe. A cyberattack on space ground infrastructure had cascaded directly into the European energy grid.

That incident is the founding argument for NIS2 Annex I Section 11. The space sector — specifically, operators of ground-based infrastructure supporting space-based services — is classified as a sector of high criticality under Directive (EU) 2022/2555. Essential entities in this category face the full weight of Article 21 risk management obligations and Article 23 incident reporting requirements, with penalties reaching €10 million or 2% of global annual turnover for non-compliance.

The most persistent misconception in the sector is that NIS2 space compliance means securing satellites. It doesn’t. NIS2 has no jurisdiction over objects in orbit. What it regulates is the terrestrial infrastructure that makes space-based services possible: ground control stations, mission control centres, telemetry and tracking facilities, satellite data processing centres, and the command link infrastructure connecting them. Your Galileo receiver is not in scope. The ground station network keeping Galileo’s atomic clocks synchronised is.

This guide covers who Annex I Section 11 applies to and who it excludes, how Article 21 obligations translate to space-specific contexts, the three threat vectors regulators focus on, what Article 23 incident reporting means for ground segment operations, and how the proposed EU Space Act will reshape the compliance architecture ahead.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Who Does NIS2 Annex I Section 11 Cover?

Annex I Section 11 of the NIS2 Directive defines the space sector’s in-scope entities as: operators of ground-based infrastructure, owned, managed and operated by Member States or by private parties, that support the provision of space-based services.

Three scope limits follow directly from that definition. Ground stations, mission control centres, telemetry and tracking facilities, and satellite data processing centres owned and operated by private companies fall inside the scope — provided they meet the size thresholds below. The satellites themselves sit outside NIS2’s reach. Infrastructure owned, managed, or operated by or on behalf of the European Union as part of the EU Space Programme is explicitly excluded by the Directive’s recital text.

For an overview of how entity classification works across all Annex I and II sectors, see the NIS2 scope guidance.

Criterion Essential Entity Important Entity Out of Scope
Size threshold 250+ employees OR €50M+ annual turnover AND €43M+ balance sheet 50–250 employees OR €10M–€50M annual turnover Under 50 employees AND under €10M turnover — unless designated critical under Article 2(2) regardless of size
Ground segment examples Commercial satellite operators running European TT&C networks; large gateway earth station operators; major Earth observation data processors Regional satellite data downlink stations; mid-size ground station service providers; navigation infrastructure operators Micro-businesses providing ancillary ground services without direct operational control of satellite infrastructure
Supervision model Ex-ante: proactive audits, security assessments, on-site inspections by national competent authority Ex-post: supervision triggered by incidents or complaints
Maximum penalty €10 million or 2% of global annual turnover €7 million or 1.4% of global annual turnover

Decision logic: does this apply to your organisation? Your organisation falls under Annex I Section 11 if it meets all three conditions: (1) it operates ground-based infrastructure located in an EU member state; (2) that infrastructure directly supports the provision of a satellite-based service — navigation, Earth observation, satellite communications, or similar; and (3) it meets the medium enterprise threshold (50+ employees or €10M+ revenue). Smaller operators may still be in scope if critical to national security-relevant space infrastructure. Member states were required to transpose NIS2 by 17 October 2024; transposition remains ongoing in several jurisdictions, and national laws should be checked to confirm when obligations took effect locally.

The Viasat Precedent: Why NIS2 Treats Space as High Criticality

The Viasat attack demonstrates, concretely, what NIS2 Recital 37 describes abstractly: space sector incidents rarely stay in the space sector. On 24 February 2022, attackers deployed AcidRain — a destructive wiper malware — against the KA-SAT satellite network through its ground segment management infrastructure. Tens of thousands of modems were wiped. For Enercon, Germany’s largest wind turbine manufacturer, 5,800 turbines with satellite-connected remote monitoring lost their command links. The turbines continued generating power but could not be monitored or controlled remotely, forcing manual intervention at hundreds of sites across Germany.

NIS2 space sector cascade diagram showing the 2022 Viasat attack disrupting 5,800 German wind turbines
A single ground-segment attack cascaded into 11 GW of lost capacity – space incidents never stay in space.

The ENISA Space Threat Landscape 2025 report, published in March 2025, cites the Viasat case when explaining why space ground infrastructure is classified as high-criticality under NIS2. The mechanism is cross-sector cascade: a single attack on a ground segment facility can propagate disruption into energy, transport, financial services, or emergency services simultaneously — without touching a single satellite.

For ground segment operators, this shapes Article 23 expectations directly. Regulators will assess whether your incident response plans account for downstream impact on NIS2-regulated entities in other sectors depending on your satellite services.

Three Types of Ground Segment Operator in NIS2 Scope

Annex I Section 11 does not subdivide ground infrastructure — but compliance obligations and risk surfaces differ significantly by facility type. Three categories emerge from the Directive’s scope definition, each with distinct primary vulnerabilities.

NIS2 ground segment architecture comparison: mission control, ground station networks, and satellite data processing risks
Each ground segment architecture carries a distinct primary risk, from telecommand injection to GNSS spoofing and supply-chain compromise.
Facility Type Examples Primary Risk Surface Key Article 21(2) Obligations
Mission Control Centres Satellite TT&C (telemetry, tracking, command) facilities; orbit determination centres; launch and early operations phase control Unauthorised telecommand injection; command link interception; operational sabotage causing satellite loss or orbital disruption Cryptographic protection of telecommands (h); Privileged access control and MFA (i)(j); Business continuity for continuous operations (c)
Ground Station Networks Commercial gateway earth stations; uplink facilities for satellite communications; VSAT network gateways; routing nodes connecting user terminals to satellite capacity Network infiltration cascading to end-user disruption; modem firmware attacks of the Viasat type; denial-of-service targeting gateway routing Network segmentation and security monitoring (e); Firmware update and vulnerability management (e); Incident detection and 24h/72h reporting (b)
Satellite Data Processing Centres Earth observation downlink and processing stations; Copernicus data reception (privately operated under contract); GNSS signal processing facilities; satellite data resellers with terrestrial processing chains Data integrity manipulation; denial of data availability; supply chain compromise in processing pipelines; GNSS spoofing affecting data outputs Supply chain security for processing software and COTS components (d); Cryptographic integrity verification of data outputs (h); Risk assessment covering data manipulation and spoofing scenarios (a)

Most commercial ground segment operators combine multiple facility types. A medium-size commercial satellite operator typically runs both a mission control function and a gateway ground station network — meaning all three risk surfaces apply concurrently. The Article 21(2)(a) risk assessment must identify which facility types are in scope and document the threat scenarios relevant to each.

The EU Space Programme Exclusion — and What Private Operators Often Miss

The NIS2 Directive explicitly excludes infrastructure owned, managed, or operated by or on behalf of the European Union as part of the EU Space Programme. The practical scope of this exclusion is narrower than some operators assume.

NIS2 space sector scope flowchart showing when ground operators stay in scope despite Programme exclusions
Private contractors running Copernicus or Galileo downlinks remain fully in scope, supervised by national authorities.

Excluded: Ground segment facilities operated under direct EUSPA or ESA mandate as part of the EU Space Programme. This covers the Galileo Control Centres, the Galileo Sensor Station network, Copernicus ground infrastructure operated under ESA mandate, and the GOVSATCOM Hub — a secure operational ground segment facility built under a €107 million EUSPA contract awarded in 2024. These assets fall under EUSPA’s internal cybersecurity governance framework, not NIS2.

Not excluded: Private companies providing ground segment services to the EU Space Programme under contract. An operator running a data downlink station for Copernicus under a European Commission service contract is still a private party operating private infrastructure. That operator meets the Annex I Section 11 definition and is in NIS2 scope if it meets size thresholds.

EUSPA does not function as the NIS2 competent authority for private ground segment operators. Its role is security accreditation and oversight of EU-owned space assets — specifically Galileo, EGNOS, GOVSATCOM, Copernicus, and IRIS2. Private operators are supervised by their national NIS2 competent authority. For the full text of the Directive and Annex I sector classifications, see the NIS2 Directive explained.

Article 21 Obligations for Ground Segment Operators

Article 21(2) requires all essential and important entities to implement at minimum 10 categories of technical, operational, and organisational measures. For ground segment operators, several require space-specific interpretation that general-purpose frameworks miss.

NIS2 Article 21 compliance matrix mapping space sector obligations to lead departments and implementation effort
Article 21 obligations map to specific owners – CISO, IT security, operations, procurement, and engineering each lead.

The practical summary: you need a risk assessment covering your ground-to-satellite interface, a supply chain programme accounting for satellite hardware and software components, encrypted and authenticated telecommands, and incident detection capable of identifying attacks at the ground-space link level. Effort scales with entity size and risk exposure — but the obligation is categorical for all in-scope operators.

Article 21(2) Measure Space Ground Segment Interpretation Effort Lead Role
(a) Risk analysis and security policies Risk assessment must model space-specific scenarios: GNSS spoofing affecting ground timing infrastructure, telecommand injection via compromised uplink, ground station physical compromise, and cross-sector cascade impact on dependent NIS2 entities in energy, transport, and communications High CISO / Risk Manager
(b) Incident handling Incident playbooks must address satellite service disruption scenarios, cross-sector cascade containment, and forensic evidence preservation from TT&C logs and ground-to-space link records Medium IT Security / SOC
(c) Business continuity and crisis management Continuity plans must address satellite operational dependencies, ground station fallback capabilities, and recovery time objectives for dependent downstream NIS2-regulated operators High Operations / Legal
(d) Supply chain security Software Bill of Materials (SBOMs) for COTS satellite components; contractual security requirements for satellite manufacturers, launch providers, and ground system integrators; quarterly supplier reviews; pre-deployment testing of COTS before introduction into ground operations High Procurement / CISO
(e) Network and information systems security Segmentation between ground station control networks and corporate IT; monitored DMZ architecture for ground-to-space link interfaces; documented remote access governance for vendor maintenance windows; vulnerability management covering ground control software Medium–High IT / Engineering
(h) Cryptography and encryption Authenticated and encrypted telecommands to prevent injection attacks; key management for ground-to-space link encryption; post-quantum readiness assessment for programmes with operational lifetimes beyond 2030 High CISO / Engineering
(i) Access control and asset management Privileged access management for mission control workstations; physical security for ground station facilities as primary assets; complete asset register covering ground segment hardware, software, and communication links Medium IT / Facilities
(j) Multi-factor authentication MFA mandatory for all access to satellite command systems, TT&C infrastructure, and ground control networks; no single-factor authentication for remote access to mission-critical systems under any circumstances Low–Medium IT

CIR 2024/2690 — the Commission Implementing Regulation on NIS2 technical requirements — provides granular implementation criteria for each measure. Compliance documentation must be audit-ready: regulators expect exportable, timestamped artefacts, not policy binders. For the full NIS2 Article 21 requirements with CIR 2024/2690 cross-mapping, see the requirements reference.

Space-Specific Threat Vectors: GNSS Spoofing, Command Hijacking, and Ground Station Attacks

Ground segment risk assessments must model three threat categories that general-purpose cybersecurity frameworks rarely treat as primary concerns. Each has direct Article 21 mapping and documented real-world precedent.

GNSS Spoofing and Its Cross-Sector Cascade

GNSS jamming and spoofing are now critical infrastructure threats — not just aviation hazards. Power grids, financial market infrastructure, and 5G networks synchronise timing using GPS signals. A precision spoofing attack corrupting GNSS timing data can cascade failures across multiple NIS2-regulated sectors simultaneously: a power grid operator receiving falsified time data risks synchronisation instability; timestamped financial transactions become unverifiable; telecoms base stations lose coordination timing.

The scale is quantifiable. According to data cited by the International Air Transport Association, GPS signal loss events increased by approximately 220% between 2021 and 2024. In 2024 alone, European aviation authorities documented more than 80 major GNSS interference events traced to Russian electronic warfare activity. In April 2024, falsified GNSS signals caused 117 vessels to simultaneously appear co-located at Beirut Airport on maritime tracking systems — a documented demonstration of position spoofing at operational scale.

For NIS2 ground segment operators: if your facilities include GNSS timing receivers — which virtually all do for network synchronisation — your Article 21(2)(a) risk assessment must include GNSS spoofing as a credible threat vector. Documented mitigation must address GNSS signal authentication, independent timing backup, and anomaly detection. Operators whose satellite services distribute timing or positioning data to other NIS2 essential entities carry elevated responsibility: a GNSS compromise at your facility becomes your downstream clients’ incident.

Satellite Command Hijacking

The ENISA Space Threat Landscape 2025 report identifies command link interception as a primary threat to satellite operations. Exposed telemetry links, inadequate firmware update procedures, and insufficiently segmented ground networks are the documented entry vectors. A successful command injection attack can cause mission disruption, uncontrolled orbital manoeuvres, or permanent satellite damage. The relevant NIS2 obligations are Article 21(2)(h) — cryptographic authentication of all telecommands — and Article 21(2)(e) — network segmentation isolating mission control from lower-security networks.

ENISA recommends validated, end-to-end cryptographic mechanisms for ground-to-space command links, with post-quantum readiness assessment for satellite programmes that will remain operational after 2030. The EU Space Act proposal makes encrypted telecommands an explicit baseline requirement — signalling that the current regulatory direction will tighten, not relax.

Ground Station Physical and Cyber Attacks

Ground stations are geographically fixed, publicly documented, and function as critical single points of failure for satellite services. Physical security is an explicit Article 21(2)(i) requirement: access control, perimeter security, and personnel screening for mission-critical facilities. Cyber attacks on ground station management software — the AcidRain-type wiper deployed in the Viasat case being the primary documented example — represent the highest-consequence scenario: ground-to-space command capability destroyed, with service disruption cascading to all downstream operators. The ENISA 2025 guidance recommends security by design and by default for all ground segment systems, and pre-deployment testing of all COTS components before introduction into production environments.

Article 23 Incident Reporting: What Qualifies as a Space Sector Incident?

Ground segment operators face the same three-stage reporting timeline as all NIS2 essential entities — but the threshold for a “significant incident” requires space-specific interpretation.

NIS2 Article 23 incident reporting timeline: 24-hour early warning, 72-hour notification, one-month final report
Space sector operators must notify their national CSIRT at 24 hours, 72 hours, and one month after an incident.
Report Type Deadline Required Content Recipient
Early warning 24 hours from awareness Whether the incident is suspected to be malicious; whether it may have cross-border impact National CSIRT and/or national competent authority
Incident notification 72 hours from awareness Initial severity assessment; indicators of compromise; preliminary impact evaluation including affected downstream services National CSIRT and/or national competent authority
Final report 1 month from notification Detailed description, root cause, corrective measures taken, cross-border and cross-sector impact assessment National CSIRT and/or national competent authority

What triggers reporting for ground segment operators? An incident is significant — and therefore reportable — if it causes or is capable of causing severe operational disruption, financial loss, or significant harm to others. For space sector operators this includes: loss of mission control capability for a satellite providing services to essential entities in energy, transport, or communications; ground station compromise disrupting satellite communications for multiple downstream operators; GNSS spoofing incidents affecting timing integrity for infrastructure operators dependent on your signal distribution. Failure to meet Article 23 reporting obligations falls within the overall Article 21 enforcement regime — up to €10 million or 2% of turnover for essential entities.

The cross-sector dimension adds procedural complexity. Where an incident at your facility causes measurable disruption to NIS2-regulated entities in other sectors, those entities may independently report the same incident from their own perspective, and regulators may cross-reference. Ground segment operators should pre-agree communication protocols with key NIS2-regulated customers — knowing who depends on your services and having cascade notification procedures ready before an incident occurs.

The EU Space Act: What Changes After NIS2

In May 2025, the European Commission published a proposal for the first EU Space Act. Article 75 of the proposal establishes the Space Act as lex specialis: for space operators classified as essential or important entities under NIS2, the Space Act’s specific cybersecurity requirements would displace — not supplement — NIS2 Article 21 obligations.

The proposed Space Act measures for ground segment operators extend beyond NIS2 in several areas: Threat-Led Penetration Testing mandatory before launch and every three years thereafter; explicit baseline requirement for encrypted, authenticated telecommands between ground control centres and space assets; documented inventories of critical non-EU-origin components in ground systems; post-quantum cryptography assessment for programmes with lifetimes beyond 2030. Article 93 adds EUSPA as a mandatory incident reporting recipient alongside national NIS2 authorities.

Three institutional positions remain in negotiation. The Commission proposes full displacement of NIS2 Article 21 by Space Act requirements. The Council prefers synchronised obligations — same requirements expressed across both frameworks. The European Parliament’s ITRE Committee proposes amending NIS2 directly to incorporate space-specific provisions, eliminating a separate Space Act cybersecurity regime. The trilogue outcome is not expected to resolve quickly.

The practical recommendation: implement NIS2 fully now. The Space Act’s baseline requirements are substantively aligned with NIS2 Article 21 under all three institutional positions. Organisations that achieve NIS2 compliance will need limited additional remediation under any likely Space Act outcome. Deferring implementation while the trilogue proceeds creates enforcement exposure today — national competent authorities are actively applying NIS2 to the space sector, and the October 2024 transposition deadline has passed in most EU member states.

Frequently Asked Questions

Does my satellite operations team need NIS2 cybersecurity training under Article 21(2)(g)? Yes. Article 21(2)(g) requires training and awareness for all personnel whose activities bear on the organisation’s cybersecurity risk. Ground-based satellite operations staff — controllers, telemetry engineers, network administrators — fall squarely within this obligation. Training must cover space-specific scenarios: GNSS anomaly recognition, telecommand authentication failures, and cross-sector cascade incident reporting procedures.

Our ground station provides contracted services to an EU Space Programme mission. Are we excluded from NIS2? No. The EU Space Programme exclusion covers infrastructure owned, managed, and operated on behalf of the EU — not private operators providing contracted services to EU programmes. Your facility is private infrastructure meeting the Annex I Section 11 definition, regardless of who your customer is.

What is the maximum penalty for a ground segment operator that fails to implement Article 21 measures? For essential entities: €10 million or 2% of global annual turnover, whichever is higher. Under Article 20, NIS2 holds management bodies directly accountable — executives and board members carry personal liability for ensuring Article 21 compliance, with national competent authorities having the power to impose temporary management bans for persistent non-compliance.

Does the EU Space Act make current NIS2 compliance work irrelevant? No. Under all three institutional positions in negotiation, the Space Act’s cybersecurity baseline is substantively equivalent to NIS2 Article 21. Organisations compliant with NIS2 will face minimal additional work under any Space Act outcome. The more significant risk is delay: the trilogue may take several years to resolve, while NIS2 national enforcement is active now.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

For a complete step-by-step walkthrough, see NIS2 space sector compliance checklist.

Sources

  1. European Union, Directive (EU) 2022/2555 (NIS2 Directive), Official Journal of the European Union, January 2023 — cited inline above (EUR-Lex)
  2. ENISA, “Space Threat Landscape 2025,” March 2025. ENISA.europa.eu
  3. ENISA, “From Cyber to Outer Space: A Guide to Securing Commercial Satellite Operations.” ENISA.europa.eu
  4. Wikipedia, “Viasat Hack,” 2022. Wikipedia
  5. Traficom / SpaceFinland, “NIS2 and Earth Stations — 10 Statements.” SpaceFinland.fi
  6. Hannes Snellman, “Beyond NIS 2: The EU Space Act and the Coming of Age of Space Cybersecurity,” 2025. HannesSnellman.com
  7. European Commission, Proposed EU Space Act (COM/2025/335), May 2025. EUR-Lex
  8. EUSPA, “EU Space and Security.” EUSPA.europa.eu
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: