NIS2 Article 21 compliance checklist for transport operators across aviation, maritime, rail, and road modes

NIS2 Article 21 Checklist for Transport Operators: Aviation, Maritime, Rail, and Road — With EASA and IMO Gap Analysis

Transport operators already complying with EASA Part-IS or the IMO cyber risk guidelines have covered meaningful ground toward NIS2 Article 21(2) — but not enough. Two Article 21(2) sub-paragraphs, cryptography policy under (h) and multi-factor authentication under (j), appear nowhere in either framework. A third, supply chain contract security under (d), is addressed by the IMO guidelines only at the level of risk identification, not mandatory contractual obligations. This matters because Article 34 fines apply to infringements of Article 21 specifically, with no exemption for entities that already comply with sector-specific cyber regulations.

This checklist maps each of the ten Article 21(2) measures against what EASA Part-IS and IMO MSC-FAL.1/Circ.3 already deliver, marks the gaps, and provides a combined checklist for multi-modal operators running a port, a rail freight terminal, and road distribution — where a unified ISMS covering all three modes is the most efficient path to full compliance. The NIS2 transport compliance overview explains the broader regulatory framework; this article is the working checklist.

Who Falls Under NIS2 in the Transport Sector

NIS2 Directive 2022/2555 classifies transport entities under Annex I, Sector 2. Entity type — not the mode of transport — determines whether you are an essential or important entity, which in turn determines your penalty exposure and supervisory regime. All rail, aviation, and water transport entities above the size threshold are essential entities by default; road and ITS operators are important entities unless designated otherwise.

Sub-sector Entity types in scope Default classification
Aviation Air carriers (commercial), airport managing bodies, ATM/ATC operators including FAB service providers Essential
Rail Infrastructure managers, railway undertakings including operators of service facilities Essential
Water transport Inland waterway, sea, and coastal passenger and freight transport entities; port authorities; vessel traffic management operators Essential
Road Road authorities responsible for traffic management; Intelligent Transport Systems (ITS) operators Important

The size threshold applies across all sub-sectors: large enterprises with 250 or more employees or €50 million or more in annual turnover are in scope automatically. Medium-sized operators (50–249 employees) are classified as important entities unless member states designate them otherwise. Two situations override the size threshold: sole providers of services critical to societal or economic functions are in scope regardless of size, and entities whose disruption would create significant cross-border risk may be designated by national authorities.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Multi-modal operators — a logistics group running a seaport, a rail freight terminal, and a road distribution network — fall under three Annex I sub-sectors simultaneously, each with its own national competent authority registration requirement. That registration structure shapes how the combined checklist in the later section is organised.

How to Read This Checklist

The tables below use three coverage labels against each Article 21(2) measure. Covered means the sector framework substantially satisfies the measure, subject to any noted caveats. Partial means the framework provides a starting point but existing documentation falls short of what NIS2 requires. Gap means neither EASA Part-IS nor IMO MSC-FAL.1 addresses the measure at all; new documentation is required from scratch.

Rail and road operators have no sector-specific cybersecurity framework comparable to Part-IS or MSC-FAL.1. For those modes, every Article 21(2) measure is a NIS2-only obligation. ISO 27001:2022 and IEC 62443 are the most widely used reference frameworks for closing those gaps. Article 21(1) requires measures to be appropriate and proportionate to the risk, size, and incident likelihood of the entity, which means formally documented compensating controls are permissible where direct technical implementation is infeasible.

Aviation Operators: EASA Part-IS Checklist Mapped to Article 21(2)

Commission Implementing Regulation (EU) 2023/203, which establishes Part-IS (Information Security), requires air operators, approved organisations, and ATM/ANS providers to implement an ISMS covering systems that, if compromised, could affect aviation safety. The framework is built around five IS.I.OR provisions: IS.I.OR.200 (ISMS scope and management), IS.I.OR.205 and IS.I.OR.210 (risk management and policy), IS.I.OR.220 and IS.I.OR.230 (incident management and reporting), and IS.I.OR.240 (competence and training). These provisions address eight of the ten Article 21(2) measures — but only partially, and two measures are missing entirely.

Art. 21(2) Requirement Part-IS provision Coverage What still needs documenting
(a) Risk analysis and IS policies IS.I.OR.205, IS.I.OR.210 Partial Part-IS limits scope to safety-impacting risks; NIS2 requires an all-hazards approach covering non-safety cyber threats
(b) Incident handling IS.I.OR.220, IS.I.OR.230 Partial Part-IS 72-hour EASA reporting exists; NIS2 adds a 24-hour early warning to the national CSIRT
(c) Business continuity, backup, DR IS.I.OR.200 Partial No standalone BCP or DRP mandate in Part-IS; IS procedures cover continuity only incidentally
(d) Supply chain security IS.I.OR.200 Partial Need-to-know access controls exist; formal supplier cybersecurity assessments and contractual security terms not mandated
(e) Network and IS acquisition and maintenance IS.I.OR.205, IS.I.OR.210 Partial Vulnerability identification exists; formal disclosure procedures and patch-cycle governance not required
(f) Effectiveness assessment IS.I.OR.200 Partial General ISMS monitoring present; no KPI-based measurement or periodic formal review requirement
(g) Cyber hygiene and training IS.I.OR.240 Covered Strong — documented competence for personnel with critical system access. Minor: extend coverage to all staff
(h) Cryptography and encryption None Gap Entirely absent from Part-IS — new cryptography policy required
(i) HR security, access control, asset management IS.I.OR.200 Partial Need-to-know principle and asset identification present; formal HR security procedures and asset lifecycle registry needed
(j) MFA and secured communications None Gap Entirely absent from Part-IS — MFA policy and secured communication protocol documentation required

An aviation entity already certified under Part-IS needs two new policy documents (cryptography, MFA) and targeted extensions to five existing ones. It does not need to build an ISMS from the ground up. For multi-modal operators running aviation alongside ground transport: Part-IS ISMS scope applies only to aviation safety systems. Ground transport, warehousing, and road fleet systems fall outside that scope and require separate NIS2 documentation unless you explicitly extend the ISMS boundary to cover them.

Maritime Operators: IMO MSC-FAL.1/Circ.3 Elements Mapped to Article 21(2)

IMO MSC-FAL.1/Circ.3 Rev.3 structures maritime cyber risk management around five functional elements: Identify, Protect, Detect, Respond, and Recover. IMO Resolution MSC.428(98) required integration of cyber risk into existing Safety Management Systems (ISM Code) by no later than the first annual verification after 1 January 2021. Compliance with the IMO framework is therefore not optional for vessel operators — but it does not satisfy NIS2. The gap analysis below shows exactly where the two frameworks diverge.

Art. 21(2) Requirement IMO MSC-FAL.1 element Coverage What still needs documenting
(a) Risk analysis and IS policies Identify Covered Strong alignment — asset cataloguing, threat identification, vulnerability assessment, likelihood and impact rating
(b) Incident handling Detect + Respond Partial Resilience and restoration plans exist; Article 23 notification timelines (24-hour early warning, 72-hour notification, 1-month report) are entirely absent from the IMO framework
(c) Business continuity, backup, DR Recover Partial System restoration addressed; no governance-level BCP with defined recovery time objectives or board-approved continuity plans
(d) Supply chain security Identify (partial) Gap IMO identifies vendor dependencies; it does not mandate cybersecurity assessments of direct suppliers or require contractual security clauses with ECDIS vendors, VSAT providers, or port management software suppliers
(e) Network and IS acquisition and maintenance Protect Partial Protective controls exist; formal vulnerability disclosure procedures and acquisition security requirements not addressed
(f) Effectiveness assessment General process Partial Ongoing process described; no formal periodic review procedures, KPIs, or board effectiveness reporting
(g) Cyber hygiene and training Protect (personnel) Partial Human factors acknowledged; NIS2 requires explicit training programmes, competence records, and documented frequency
(h) Cryptography and encryption None Gap IMO is technology-neutral and provides no cryptographic requirements — new policy required
(i) HR security, access control, asset management Identify + Protect Partial Asset management and access principles present; formal HR security procedures with lifecycle controls not mandated
(j) MFA and secured communications None Gap IMO does not address MFA or secured protocol requirements for remote vessel access or shore-based systems

OT Legacy Systems and Compensating Controls

Article 21(2)(e) vulnerability management presents a category problem for vessel operators: the most critical onboard systems cannot be patched using conventional methods. ECDIS commonly runs end-of-life operating systems. AIS transmitters use NMEA 0183, a serial protocol with no built-in authentication, making false position broadcasts and identity hijacking technically feasible without hardware replacement. Ballast water management systems typically rely on Modbus-TCP or CAN bus without encryption or authentication and affect vessel stability operations directly.

Article 21(1)’s proportionality clause makes compensating controls acceptable where direct patching is technically infeasible, provided they are formally documented. Four compensating control patterns are appropriate for maritime legacy OT:

  • Zone-based network segmentation separating Global Ship Zone (external), Ship Control Zone (management), and Ship System Zone (OT) with monitored DMZ boundaries
  • Device whitelisting authorising only specific NMEA 0183 device interactions and alerting on any unauthorised communication
  • Anomaly detection identifying abnormal operational patterns without modifying legacy devices
  • Risk acceptance documentation recording residual risk, the compensating controls in place, named management sign-off, and a scheduled review date

Each compensating control must appear in writing in your risk register and ISMS scope document — not only in network architecture diagrams.

Rail Operators: Checklist Without a Sector-Specific Cyber Framework

Rail has no sector equivalent to EASA Part-IS or IMO MSC-FAL.1. Every Article 21(2) measure is therefore a NIS2-only obligation for railway infrastructure managers and undertakings. The CER Directive (EU) 2022/2557 on critical entities resilience applies to railway infrastructure managers in parallel but addresses physical resilience rather than cybersecurity and does not substitute for NIS2 compliance. Railway undertakings and infrastructure managers are classified as essential entities under Annex I, which means the Article 34(4) penalty tier — up to €10,000,000 or 2% of global annual turnover, whichever is higher — applies from the outset.

Art. 21(2) Requirement Recommended reference framework Owner Effort
(a) Risk analysis and IS security policies ISO 27001:2022, IEC 62443-2-1 CISO High
(b) Incident handling with Art.23 notification chain ISO 27035, internal SOP CISO / IT / Legal Medium
(c) Business continuity and disaster recovery ISO 22301 CISO / Operations Medium
(d) Supply chain security — signalling vendors, trackside equipment suppliers, operational software ISO 27001 A.5.19 / A.5.20 Procurement / Legal High
(e) Network security and vulnerability management — SCADA, PLC, signalling, interlocking IEC 62443-2-3 CISO / IT High
(f) Effectiveness assessment — annual review linked to audit cycle ISO 27001 Clause 9 CISO Low
(g) Cyber hygiene and training for staff with signalling or safety system access Internal programme HR / IT Low
(h) Cryptography and encryption policy ISO 27001 A.8.24 CISO / IT Medium
(i) HR security, access control, and asset management ISO 27001 A.5 / A.6 / A.8 HR / IT Medium
(j) MFA for remote access to operational systems Internal policy IT Medium

Legacy signalling systems present the same patching challenge as maritime OT. Where ETCS components or legacy interlocking equipment cannot receive conventional updates, the same compensating control logic applies: formal risk acceptance documentation plus network segmentation and continuous monitoring.

Road and ITS Operators: Traffic Management and V2X Systems Checklist

Road operators in NIS2 scope are specifically road authorities responsible for traffic management where network security risk management is a primary activity, and operators of Intelligent Transport Systems. Vehicle manufacturers and road maintenance contractors generally fall outside Annex I. ITS operators face a distinct threat profile: GPS spoofing on vehicle navigation systems, V2X protocol vulnerabilities at roadside units, and traffic management control system attacks that could alter signal timing or disable variable message signs.

Art. 21(2) Requirement ITS-specific implementation Effort
(a) Risk analysis Asset inventory: traffic management centres, roadside units, V2X communication infrastructure, control data centres Medium
(b) Incident handling Incident classification including GPS spoofing, signal manipulation, and traffic control system compromise; Art.23 notification chain Medium
(c) Business continuity Manual fallback procedures for traffic management; defined recovery timelines for ITS systems Low
(d) Supply chain Contractual cybersecurity requirements with traffic system vendors and V2X hardware manufacturers Medium
(e) Network security and vulnerability management Roadside unit firmware update governance; V2X protocol security assessment; traffic management centre segmentation High
(f) Effectiveness assessment Annual control review; penetration testing of V2X interfaces Low
(g) Training Staff operating traffic management centres; incident response drills Low
(h) Cryptography Encrypted communications between traffic management centre and roadside units Medium
(i) Access control and asset management Privileged access management for traffic management systems; roadside unit inventory with lifecycle tracking Medium
(j) MFA Multi-factor authentication for traffic management centre and remote access systems Medium

Multi-Modal Operators: Combined Checklist for Port, Rail, and Road

A logistics group operating a seaport (water transport), a rail freight terminal (rail), and a road distribution network (road) carries three simultaneous Annex I obligations. Most compliance frameworks treat each mode as a separate project, which duplicates governance effort without adding compliance value. The efficient path is a single, scope-extended ISMS with documented sub-scope boundaries identifying which systems fall under which sectoral framework and, where relevant, which compensating controls apply per mode.

Art. 21(2) Maritime (port) Rail terminal Road / ITS fleet Shared documentation
(a) Risk analysis OT asset inventory: ECDIS, AIS, BWMS, VSAT, port management software; IMO Identify baseline extends here Signalling, SCADA, interlocking, terminal management systems Traffic management systems, GPS, V2X units Single risk register with mode-specific annexes
(b) Incident handling Art.23 reporting chain + IMO Respond element; coordination with port authority CSIRT contact Rail incident SOP + Art.23 notification to rail NCA Traffic management SOP + Art.23 notification to road NCA Unified incident classification; mode-specific NCA notification trees
(c) BCP / DR Tested backup and recovery timelines for port systems; vessel offline fallback Signalling fallback; manual operation procedures Manual traffic management fallback procedures Single BCP document with three operational annexes
(d) Supply chain New for all modes: cybersecurity clauses in supply contracts; ECDIS vendor and VSAT provider assessments Signalling vendor and maintenance contractor security requirements V2X and traffic system vendor assessments Master supply chain security policy + per-mode supplier registers
(e) Network / vulnerability OT zone segmentation; ECDIS and AIS legacy compensating controls documented SCADA / PLC segmentation; legacy signalling compensating controls Roadside unit segmentation; V2X protocol controls Shared vulnerability register; per-mode compensating control appendices
(f) Effectiveness Linked to SMS audit cycle (IMO) Linked to railway safety management system audit Annual review with penetration test results Single effectiveness report; mode-specific KPIs
(g) Training Seafarer, shore staff, and board-level cyber hygiene Rail operations staff training; incident response drills Traffic management centre staff training Unified training programme + role matrix
(h) Cryptography New — IMO gap New New Single cryptography policy covering all modes; OT exception register noting legacy constraints
(i) Access control Port systems access control; remote vessel access governance Signalling system privileged access management Traffic management centre access control Single access control policy; per-mode system annexes
(j) MFA New — IMO gap; remote vessel access scenarios documented New New Single MFA policy covering all remote access scenarios across modes

The critical governance question for multi-modal operators is which national competent authority receives Article 23 incident notifications when an event spans modes. An attack that propagates from a port’s OT network into the adjacent rail terminal control system involves two Annex I sub-sectors and, potentially, two separate NCAs. The answer under the directive is both NCAs, notified separately within the applicable timelines. Document the cross-NCA escalation tree and the CSIRT contact details for each mode before an incident occurs.

Enforcement, Fines, and What Management Must Personally Sign Off

Transport entities classified as essential entities — aviation, rail, and water transport operators above the size threshold — face the higher penalty tier under Article 34(4): a maximum administrative fine of at least €10,000,000 or 2% of total worldwide annual turnover from the preceding financial year, whichever is higher. Road operators and ITS entities classified as important entities face a maximum of at least €7,000,000 or 1.4% of worldwide annual turnover under Article 34(5). Both tiers apply to infringements of Article 21 (risk management measures) or Article 23 (incident reporting). Member states may also impose periodic penalty payments to compel cessation of infringement.

Article 20 adds a personal accountability layer. Management bodies must formally approve the cybersecurity risk-management measures required by Article 21 and oversee their implementation. Members of management bodies must complete regular cybersecurity training to develop the knowledge needed to identify risks and assess the impact of risk-management practices on services provided. Several member states have implemented provisions under which individual directors can be held personally liable for failure to discharge these duties — the director liability implications of NIS2 vary by jurisdiction.

The board sign-off checklist for transport management bodies:

  • Formally approve the ISMS scope document and risk appetite statement
  • Review and approve the risk register at least annually, with documented sign-off date and attendees
  • Approve all Article 21(2) policy documents as a named management decision
  • Complete documented cybersecurity training — record the date, content, and delivery method
  • Receive regular security performance reports from the CISO or equivalent, with a named board member as accountability owner

Three Immediate Actions for Transport Compliance Officers

Transport compliance teams already operating under EASA Part-IS or IMO cyber guidelines have a realistic 60–90 day path to substantially closing their NIS2 gaps — provided they focus on the three measures neither framework provides.

Action 1: Document a cryptography and encryption policy (Art. 21(2)(h)). Neither Part-IS nor MSC-FAL.1 addresses cryptography. Start with a policy that identifies which systems handle operationally critical communications or personal data, what encryption standards apply where technically feasible, and where legacy OT constraints require a documented exception with risk acceptance sign-off.

Action 2: Implement an MFA policy (Art. 21(2)(j)). Document which systems require multi-factor authentication for remote access, which user categories are in scope, and what technical exceptions apply — for example, legacy vessel systems where MFA is not yet technically feasible. Risk-accept each exception in writing, naming the residual risk and the review date.

Action 3: Update supply chain contracts (Art. 21(2)(d)). Identify direct suppliers whose compromise could affect your operations. For maritime operators, this includes ECDIS vendors, VSAT providers, and port management software suppliers. For aviation, it includes maintenance management systems and operational data providers. At next contract renewal, add cybersecurity incident notification requirements, audit rights, and access termination provisions.

Frequently Asked Questions

Does a freight forwarding company fall under NIS2 transport scope?

Freight forwarders are logistics intermediaries, not transport operators in the Annex I sense. They generally fall outside NIS2 transport scope unless they operate digital infrastructure classified under another Annex I or Annex II sector. If a forwarding company operates its own digital freight brokerage platform that functions at scale, it may qualify under a different Annex classification. Verify with your national competent authority based on your specific services.

Is EASA Part-IS compliance alone sufficient for NIS2?

No. Part-IS compliance addresses eight of the ten Article 21(2) measures partially and leaves Art. 21(2)(h) cryptography and Art. 21(2)(j) MFA entirely uncovered. It also restricts ISMS scope to safety-impacting risks, while NIS2 requires an all-hazards approach. Part-IS compliance is a strong foundation; it is not a substitute for NIS2 compliance.

If a cyber incident spans our maritime and rail systems, how do we handle Article 23 reporting?

Each Annex I sub-sector registration is a separate notification obligation. If an incident materially affects both your port operations (water transport sub-sector) and your adjacent rail terminal, notify the relevant NCA for each sub-sector within the applicable Article 23 timelines: 24-hour early warning and 72-hour notification for each. Document the cross-NCA escalation tree and contact details in your incident response plan before an incident occurs, not during it.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: