NIS2 Transport Compliance: What Aviation, Rail, Maritime, and Road Operators Each Owe Under Article 21
When a cyberattack hit a major European port’s terminal operating system, container handling stopped within hours. Three days later, trucks were backing up at border crossings hundreds of kilometres away. The European Union Agency for Cybersecurity (ENISA) has documented this type of cascading failure across multiple transport sectors — and it is precisely that systemic exposure that led lawmakers to place transport in Annex I of the NIS2 Directive, the highest-criticality tier alongside energy and digital infrastructure.
With the October 2024 transposition deadline passed and national competent authorities in implementing member states beginning supervision cycles in 2026, transport operators across aviation, rail, maritime, and road have moved from the “prepare” phase into the “demonstrate” phase. The question is no longer whether NIS2 applies — it is what each entity type in each transport mode specifically owes.
This guide maps exactly that: which entities qualify per sub-sector, what Article 21(2) demands across the board, and how each mode’s pre-existing regulatory framework (EASA Part-IS for aviation, IMO MSC-FAL.1/Circ.3 for maritime, the CER Directive for rail) aligns with — and falls short of — NIS2’s ten-measure security framework.
Which Transport Entities Fall Under NIS2 Annex I Section 2
NIS2 Directive (EU) 2022/2555 classifies transport under Annex I Section 2, covering four sub-sectors with distinct entity types. Within each sub-sector, size thresholds determine whether an organisation is essential or important — but several transport entity types carry essential classification regardless of company size.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
| Mode | Entity Type | Default Classification |
|---|---|---|
| Air | Air carriers used for commercial purposes | Essential |
| Air | Airport managing bodies (incl. ancillary installations) | Essential |
| Air | Traffic management control / ATC service providers | Essential |
| Rail | Infrastructure managers (IMs) | Essential |
| Rail | Railway undertakings (RUs) | Essential |
| Water | Inland, sea & coastal passenger/freight transport companies | Essential / Important |
| Water | Port managing bodies | Essential / Important |
| Water | Vessel traffic service (VTS) operators | Essential / Important |
| Road | Road authorities managing traffic control | Important |
| Road | Intelligent transport systems (ITS) operators | Important |
For water and road sub-sectors, size thresholds apply: Essential if 250 or more employees or €50 million or more in annual turnover; Important if 50 or more employees or €10 million or more in turnover. Aviation and rail entity types are essential by category — an air carrier with 60 staff is still an essential entity.
The sole-provider exception overrides size thresholds entirely: any transport entity that is the only provider of a service critical to social or economic continuity in a member state qualifies as essential regardless of employee count or revenue. A regional ferry company connecting an island community with 40 staff falls under this provision.
Cross-mode overlap is a practical reality for large logistics groups. An operator running a port terminal, a road haulage fleet, and inland waterway barges may qualify simultaneously under the water, road, and potentially other sub-sectors. NIS2 provides no group consolidation mechanism — each qualifying entity is assessed and registered separately with the relevant national competent authority.
Article 21(2): The Ten Security Measures That Apply to Every Transport Entity
Article 21(2) specifies ten cybersecurity risk-management measure categories that all essential and important entities — across all four transport modes — must implement. The directive frames these under an “all-hazards approach,” meaning they cover physical, cyber, and hybrid threat scenarios.
The ten measures are:
- (a) Policies on risk analysis and information system security
- (b) Incident handling
- (c) Business continuity, backup management, disaster recovery, and crisis management
- (d) Supply chain security, including security-related aspects of relationships with direct suppliers and service providers
- (e) Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure
- (f) Policies and procedures to assess the effectiveness of cybersecurity risk-management measures
- (g) Basic cyber hygiene practices and cybersecurity training
- (h) Policies and procedures regarding the use of cryptography and, where appropriate, encryption
- (i) Human resources security, access control policies, and asset management
- (j) Use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems
In a transport context, the all-hazards interpretation carries practical weight. Asset management under Art.21(2)(i) includes operational technology (OT), not only office IT. For an airport, that means SCADA systems controlling airfield lighting and fuel supply lines are in-scope assets. For a port, it includes cargo handling cranes with networked PLCs. For a rail infrastructure manager, it covers signalling interlocking units and ETCS (European Train Control System) components. The directive provides no transport-specific exemptions for OT that “cannot run modern security agents” — organisations document compensating controls and formal risk acceptance instead.
Article 20 adds a separate governance layer: the management body of every essential and important entity must formally approve the Art.21 risk-management measures, oversee their implementation, and undergo regular cybersecurity training. Failure to do so is independently enforceable — a transport company can have technically sound security controls and still face enforcement action if the board has not formally approved them.
Aviation: EASA Part-IS and the NIS2 Compliance Gap
Three entity types fall under the aviation sub-sector: air carriers used for commercial purposes, airport managing bodies including entities operating ancillary installations, and traffic management control operators providing air traffic control services. Air navigation service providers (ANSPs) and ATM data service providers are captured under the ATC category.
Aviation is the only transport mode with a comprehensive sector-specific cybersecurity regulation already in force: EASA’s Part-IS framework, introduced under Regulation (EU) 2023/203. Part-IS applies progressively — aerodrome operators and design organisations from October 2025; air carriers, maintenance organisations, and ANSPs from February 2026. The framework builds an Information Security Management System (ISMS) requirement into existing safety oversight structures.
Part-IS does not exempt organisations from NIS2. The Jones Day analysis of the framework (February 2026) is explicit: “Part-IS compliance does not exempt organisations classified as essential or important under NIS2 from NIS2 requirements.” Aviation entities operating under Part-IS carry dual compliance obligations — separate reporting to EASA under IS.I.OR.230 and separate notification to the national NIS2 competent authority under Article 23, with different timelines and different recipient authorities.
Where Part-IS provides partial coverage, the gaps are documented and measurable:
| Art.21(2) Measure | Part-IS Coverage | Gap Status |
|---|---|---|
| (a) Risk analysis | IS.I.OR.205/210 — safety-impact scope only | Partial: NIS2 requires all cyber risks, not only safety-impacting ones |
| (b) Incident handling | IS.I.OR.220 | Partial: Part-IS 72h EASA report vs. NIS2 24h early warning to national NCA |
| (c) Business continuity | No standalone BCP mandate | Gap: BCP/DRP policy required separately for NIS2 |
| (h) Cryptography | No cryptography requirement | Primary gap: policy must be built from scratch |
| (j) MFA | No MFA requirement | Primary gap: MFA implementation and policy required |
The reporting conflict is an operational issue requiring a documented procedure: a significant cyber incident triggering NIS2 Article 23 requires an early warning to the national competent authority within 24 hours of becoming aware. Part-IS IS.I.OR.230 requires a different notification to EASA within 72 hours. Aviation entities need dual-notification procedures with distinct clock-start criteria, separate recipient contacts, and different content requirements — built into the incident response plan before the first incident occurs.
→ For the full Article 21(2) control mapping against Part-IS, see our dedicated aviation cybersecurity compliance guide.
Rail: Infrastructure Managers, Railway Undertakings, and the CER Directive
Rail transport covers two entity types under Annex I: infrastructure managers (IMs), who build and maintain the railway network and manage traffic control and signalling, and railway undertakings (RUs), who operate passenger and freight services on that infrastructure.
The most significant scoping rule for rail is the cross-reference between NIS2 and the Critical Entities Resilience (CER) Directive (EU) 2022/2557. Entities already designated as critical under CER are automatically classified as essential under NIS2 — regardless of employee count or turnover. Most major IMs operating national rail networks already meet CER criteria. An IM that falls under CER starts NIS2 at the Article 34(4) penalty tier from day one, with no size-threshold route out of the essential entity classification.
The IT-OT convergence challenge in rail is more acute than in any other transport mode. Rail infrastructure operates on safety-critical OT developed decades before cybersecurity was a design consideration: ETCS (European Train Control System) components, relay and electronic signalling systems, interlocking units, level crossing automation, and overhead power supply control. These systems run lifecycle periods measured in decades and were designed for availability and safety, not confidentiality or integrity.
For Art.21(2)(i) asset management, an IM must catalogue OT systems, assign criticality tiers, and document access controls at the IT-OT boundary. For Art.21(2)(e) vulnerability management, the standard patch cadence used for IT systems is not directly transferable — a signalling component update typically requires formal safety assessment under EN 50129, extending the remediation window significantly. The NIS2 response is not to require impossible patch currency, but to require documented vulnerability handling: a register of known vulnerabilities, risk acceptance records, and compensating control documentation.
Cross-border governance fragmentation is a compliance challenge unique to multi-country rail operators. A single international freight corridor can cross seven national regulatory jurisdictions, each with its own transposition of NIS2 and its own designated national competent authority. An IM covering three countries needs three separate incident notification contact lists, three separate registration processes, and a clear internal procedure for which NCA receives notification for which incident, based on which infrastructure segment was affected.
Maritime: How IMO MSC-FAL.1/Circ.3 Rev.3 Compares to Article 21(2)
Three entity types fall under the water transport sub-sector: inland waterway, sea, and coastal passenger and freight transport companies; port managing bodies; and vessel traffic service (VTS) operators. Individual vessels operated by those companies are explicitly excluded from NIS2 scope — the compliance obligation sits with the shore-based legal entity.
The maritime sector’s most commonly used cyber risk management framework is IMO MSC-FAL.1/Circ.3, updated as Rev.3 in April 2025. It organises maritime cyber risk management around five functional elements: Identify, Protect, Detect, Respond, Recover — language that maps broadly to ISO 31000 and NIST CSF. Many shipping companies and port operators have used Circ.3 as their baseline, supported by IACS Unified Requirements UR E26 and UR E27, which apply cybersecurity requirements to ships contracted for construction from 1 July 2024.
Three structural gaps exist between IMO MSC-FAL.1/Circ.3 and NIS2 Article 21(2) where maritime operators relying solely on IMO compliance are exposed:
- Article 21(2)(d) — Supply chain contractual security: IMO Circ.3 identifies third-party dependencies and recommends risk assessment, but it does not mandate enforceable security clauses in supplier contracts. NIS2 requires that supply chain security obligations be contractually documented with direct suppliers. For a shipping company, this extends to voyage data recorder (VDR) suppliers, vessel management software providers, classification societies with remote system access, and P&I clubs whose IT systems interact with operational data.
- Article 21(2)(h) — Cryptography: IMO guidelines are technology-neutral and do not address encryption. NIS2 requires a documented cryptography policy. For maritime operators, this means specifying encryption standards for AIS data handling, ECDIS chart update protocols, VTS communications, and data-at-rest on shore-based vessel management servers.
- Article 21(2)(j) — Multi-factor authentication: No IMO guidance addresses MFA. NIS2 requires MFA for access to systems processing critical operational data — particularly remote access to vessel management systems and port terminal operating systems.
Legacy maritime OT requires a compensating controls approach. ECDIS units running Windows XP or Windows 7, AIS transceivers without authentication, and ballast water management systems on proprietary firmware cannot be conventionally patched. Art.21(2)(e) does not require patch currency — it requires documented vulnerability handling. For unpatchable systems, compliance is demonstrated through zone-based network segmentation (Global Ship Zone, Ship Control Zone, Ship System Zone), device whitelisting, behavioural anomaly monitoring, and formal risk acceptance records signed by the management body.
→ For the full Article 21(2) control mapping against IMO and IACS standards, see our maritime cybersecurity compliance guide.
Road Transport and Intelligent Transport Systems: OT Networks in Scope
Road transport is the most scope-limited of the four NIS2 transport modes — and the most frequently misunderstood in commercial guidance. Two entity types are in scope under Annex I Section 2:
- Road authorities responsible for traffic management control: national and regional highway authorities that operate adaptive traffic management systems, dynamic message sign networks, tunnel automation, and motorway control infrastructure
- Operators of intelligent transport systems (ITS): entities providing services based on real-time traffic data, connected vehicle infrastructure (V2X roadside units), smart tolling automation, and cooperative ITS deployments
Standard freight hauliers, courier fleets, long-distance coach operators, and logistics companies that do not operate traffic management infrastructure are not in scope under the road transport sub-sector. A large road freight company with 3,000 trucks running a TMS and fleet telematics is almost certainly not an Annex I road transport entity. It may qualify separately under Annex II (postal/courier services) if it meets the size thresholds, but that is a distinct classification path. The road transport category captures the OT-heavy systems controlling public road infrastructure — not the commercial transport industry broadly.
ITS-specific threats map directly to Article 21(2) obligations in ways that IT-focused guidance typically misses:
- GPS spoofing attacks compromise location-based routing for connected vehicles, toll calculation accuracy, and the geofencing used by some ITS platforms — Art.21(2)(a) risk analysis must include GNSS dependency assessment and spoofing countermeasures as documented threat scenarios
- Adaptive traffic signal controller compromise could introduce deliberate congestion, disrupt emergency vehicle response corridors, or create conditions for physical collisions — Art.21(2)(i) access control for remote maintenance connections to field controllers is a critical control
- V2X infrastructure attacks targeting roadside units that communicate directly with connected vehicles create a unique supply chain vector — Art.21(2)(d) obligations extend to V2X equipment manufacturers and the firmware update channels they use
Road authorities operating ITS infrastructure typically have shallower IT security resources than aviation or maritime entities, but carry Article 21 obligations equivalent to any other important entity. The remediation gap — between what a national roads authority has historically provided for its OT and what NIS2 Art.21(2)(e) requires — is often larger than compliance teams initially estimate, particularly for legacy field equipment deployed before cybersecurity requirements existed in transport procurement standards.
Article 23 Incident Reporting, Enforcement, and Director Liability
NIS2 incident reporting operates on a three-step cascade that starts at a precise moment: when the entity becomes aware of a significant incident — not when root cause is confirmed, not when financial loss is quantified.
The three-step Article 23 timeline:
- Within 24 hours of awareness: early warning to the national competent authority (and CSIRT). This does not need to be a complete report, but it must notify that a significant incident is underway and give an initial indication of the incident type.
- Within 72 hours of awareness: full incident notification with an initial assessment of severity, scope, and indicators of compromise if available.
- Within one month of awareness: final report with detailed description, threat actor attribution (where established), mitigation measures applied, and cross-border impact assessment.
For transport operators, the awareness threshold arrives earlier than many compliance teams assume. A port’s terminal operating system going offline is operational disruption visible within hours — Article 23, which defines significant incidents to include severe operational disruption, is satisfied without waiting for a financial impact calculation. The 24-hour clock starts when IT confirms the system is down due to a cyber cause. The same logic applies across modes: a ransomware event disabling an airline’s departure management system satisfies the severe operational disruption test as soon as delays are confirmed, not when the CFO quantifies revenue impact. A signalling failure at a rail infrastructure manager caused by an OT intrusion starts the clock at confirmed intrusion — not at investigation conclusion.
Article 23 also specifies a second trigger that is particularly relevant for transport: an incident is also significant where it “is capable of affecting other natural or legal persons by causing considerable material or non-material damage.” A port cyberattack that disrupts cargo across a supply chain, or an ITS failure that affects traffic across a regional network, can trigger this second criterion even before the first entity’s own services are severely disrupted.
Penalties under Article 34: Essential transport entities face administrative fines of a maximum of at least €10,000,000 or at least 2% of total worldwide annual turnover in the preceding financial year, whichever is higher. Important entities face fines of a maximum of at least €7,000,000 or at least 1.4% of worldwide annual turnover, whichever is higher. These apply when entities violate Article 21 or Article 23 obligations.
Director liability under Article 20: Where a national competent authority determines that the management body failed to approve, oversee, or receive training on the Article 21 risk-management measures, individual directors and officers can face temporary prohibition from exercising management functions. This is not the institutional fine — it is a personal sanction that runs alongside the entity-level penalty. Transport sector boards that have not formally approved and documented their organisation’s NIS2 risk-management framework are simultaneously exposed to both sanctions.
90-Day Priority Action Plan for Transport Compliance Officers
For transport entities beginning NIS2 implementation, the order of operations prevents wasted effort. A risk register built before the asset inventory is complete will need to be rebuilt. A vendor assessment programme without defined criticality tiers will be inconsistently applied.
Weeks 1–4: Scope and assets
- Confirm your entity type and sub-sector using the Annex I table above. If your organisation operates across multiple modes (port terminal plus road haulage), register each qualifying entity separately with your national competent authority.
- Build the asset register under Art.21(2)(i): catalogue all IT and OT systems by mode-specific category. For aviation: ACARS, ACDM, check-in infrastructure, airfield SCADA. For maritime: shore-based vessel management servers, port TOS (terminal operating system), VTS platforms. For rail: SCADA, signalling control systems, ETCS wayside and onboard units. For road/ITS: traffic management centres, field controllers, V2X roadside units.
- Identify your mode-specific framework gaps: aviation entities audit against Part-IS; maritime operators audit against IMO MSC-FAL.1/Circ.3 Rev.3; rail entities assess their CER designation status; road/ITS operators build from Art.21 directly without a pre-existing sector framework baseline.
Weeks 5–8: Risk assessment and incident procedure
- Draft or update the risk assessment under Art.21(2)(a). Document threat scenarios specific to your mode: GPS spoofing for ITS operators, AIS manipulation for maritime entities, ETCS integrity attacks for rail IMs, departure management system ransomware for airlines. Generic IT threat scenarios are insufficient for an operational transport environment.
- Build the Article 23 incident notification procedure. The procedure must define what constitutes a significant incident in operational terms (not abstract definitions), who has authority to notify the NCA, and the exact contact details for your national authority by mode and by member state if you operate across borders.
Weeks 9–12: Gap closure and board approval
- Close mode-specific technical gaps: implement MFA for remote access to critical operational systems; document the cryptography policy covering in-transit and at-rest encryption; establish contractual security clauses with your top-tier direct suppliers under Art.21(2)(d).
- Secure management body approval under Article 20. Present the complete security framework to the board; document the decision and the training session received. This single step closes the director liability exposure and satisfies the governance requirement that cannot be delegated to the IT or compliance team.
For a provision-level checklist mapping EASA Part-IS IS.I.OR controls and IMO MSC-FAL.1 elements to each Article 21(2) sub-paragraph — including gap analysis for multi-modal operators — see the NIS2 transport sector compliance checklist.
Frequently Asked Questions
Does a freight forwarding company fall under NIS2 transport scope?
Freight forwarders are not listed as an entity type in NIS2 Annex I Section 2 (Transport). They may qualify under Annex II if they also provide postal or courier services and meet the size thresholds — but the Annex I transport sub-sector covers road traffic management authorities and ITS operators, not commercial freight intermediaries. Large logistics groups that also operate port terminals or VTS services qualify under the water transport sub-sector for those specific activities.
If our airline is already Part-IS certified, are we NIS2 compliant?
No. Part-IS compliance does not exempt organisations classified as essential or important under NIS2. The two frameworks operate independently with separate national competent authorities and separate reporting obligations. The two primary gaps where Part-IS provides no coverage are Article 21(2)(h) (cryptography policy) and 21(2)(j) (multi-factor authentication). Aviation entities also need separate incident notification procedures: Art.23 NIS2 requires a 24-hour early warning to the national NCA, while Part-IS IS.I.OR.230 requires a 72-hour report to EASA — different timelines, different recipients, different content requirements.
Does NIS2 apply to the vessel (ship) itself?
No. NIS2 Annex I Section 2(c) explicitly excludes “individual vessels” from the scope of the water transport sub-sector. The compliance obligation sits with the shore-based legal entity — the passenger or freight transport company, the port managing body, or the VTS operator. However, the operating company’s Article 21(2)(d) supply chain security obligations do extend to the cybersecurity of shipboard systems where those systems are networked to, or managed by, the shore-based entity. Vessel OT that is remotely accessible from the company’s network is within scope of the company’s Art.21(2)(e) vulnerability management programme.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Article 21 — Cybersecurity Risk-Management Measures — NIS-2-Directive.com (primary directive text)
- Article 23 — Reporting Obligations for Essential and Important Entities — NIS-2-Directive.com (primary directive text)
- Article 34 — General Conditions for Imposing Administrative Fines — NIS-2-Directive.com (primary directive text)
- Article 20 — Governance — NIS-2-Directive.com (primary directive text)
- Transport Sector Cybersecurity — ENISA
- Port Cybersecurity: Good Practices for Cybersecurity in the Maritime Sector — ENISA
- Aviation Cybersecurity Compliance Guide — NIS2-Templates.com
- Maritime Cybersecurity Compliance Guide — NIS2-Templates.com
- Cyber and Physical Resilience: Why Railways Can’t Ignore NIS2 and CER — Ramboll
- NIS2 for Logistics and Transportation — nFlo
- NIS2 for the Transport and Logistics Industry — Plan Be Eco
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
