NIS2 for Transport: Where Aviation, Rail and Maritime Rules Collide With Article 21

A regional freight forwarder with 180 employees told us their lawyer had cleared them of NIS2. Their reasoning: they are not an airline, not a port, and not a railway. Six weeks later their largest customer — a port managing body — sent them a supplier questionnaire with 40 security questions and a contract clause referencing Article 21(2)(d).
Transport is the NIS2 sector where scope is misjudged most often. Not because the text is vague, but because "transport" in Annex I is four separate regulatory worlds stapled into one entry, each with its own pre-existing safety regime that clients assume already covers them.
It does not.
Annex I treats transport as four sectors, not one
NIS2 Annex I lists transport as a sector of high criticality and then splits it into four subsectors, each with its own list of entity types.
Air. Air carriers used for commercial purposes. Airport managing bodies, including core airports, and entities operating ancillary installations at airports. Traffic management control operators providing air traffic control.
Rail. Infrastructure managers. Railway undertakings, including operators of service facilities.
Water. Inland, sea and coastal passenger and freight transport companies. Port managing bodies, including port facilities and entities operating works and equipment within ports. Operators of vessel traffic services.
Road. Road authorities responsible for traffic management control. Operators of intelligent transport systems.
Two things follow from that list, and both catch consultants out.
First, road transport is far narrower than clients expect. A haulage company that moves goods by truck is not in Annex I road transport. A public authority running traffic management control is. An ITS operator is. The trucking firm is only in scope if it lands somewhere else — for example as a supplier inside another entity's Article 21(2)(d) supply chain obligations, which is exactly what happened to the freight forwarder above.
Second, water transport is far broader than clients expect. "Entities operating works and equipment within ports" pulls in terminal operators, crane and gantry operators, and equipment maintenance businesses that never thought of themselves as regulated infrastructure.
Does NIS2 Apply to Your Organisation?
1Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?
Yes▼No▼2Does your organisation have 50 or more employees, or an annual turnover exceeding €10 million?
✗NIS2 does not directly apply to your organisation.
Yes▼No▼✓NIS2 applies to your organisation as an Essential or Important Entity.
3Is your organisation a critical infrastructure provider or a qualified trust service provider?
Yes▼!NIS2 may apply to your organisation — seek legal advice to confirm your status.
1Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?
Yes ↓No →2Does your organisation have 50 or more employees, or an annual turnover exceeding €10 million?
Yes ↓No →3Is your organisation a critical infrastructure provider or a qualified trust service provider?
Yes ↓No →✗NIS2 does not directly apply to your organisation.
✓NIS2 applies to your organisation as an Essential or Important Entity.
!NIS2 may apply to your organisation — seek legal advice to confirm your status.
AppliesPossibly appliesDoes not apply
Size decides the supervision regime, and transport has an override
The default rule is mechanical. In an Annex I sector, a large enterprise — 250 or more employees, or turnover above €50 million and balance sheet above €43 million — is an essential entity. A medium enterprise, from 50 employees or €10 million turnover, is an important entity.
Essential means proactive supervision: on-site inspections, regular audits, security scans, and requests for evidence without any incident having occurred. Important means reactive supervision, triggered by an incident or a complaint. Fines run to €10 million or 2% of global turnover for essential entities, and €7 million or 1.4% for important ones.
Transport is where the override matters. Article 2(2) lets Member States bring entities below the size thresholds into scope regardless of headcount, and transport is the classic case: a 30-person operator of a vessel traffic service, or a small ITS operator whose failure would disrupt a national corridor, can be designated because it is the sole provider of a service essential for societal activity.
Do not run the headcount test and stop. Check the national designation list first. In several Member States the transport designations were published separately from the general registration guidance, and if your client is on it, the size test is irrelevant. Which authority publishes that list depends on where the entity is established — we covered the jurisdiction rules in Article 26: which regulator actually supervises your client.
Aviation's Part-IS does not switch NIS2 off
This is the single most expensive misunderstanding in transport compliance right now.
Since 16 October 2025, EASA Part-IS — Delegated Regulation (EU) 2022/1645 — has applied to aerodrome operators, design and production organisations, and apron management service providers. Implementing Regulation (EU) 2023/203 extended the framework to further organisation types from February 2026. Aviation clients read that and conclude NIS2 is handled.
Article 4 of NIS2 does provide for this. Where a sector-specific Union legal act imposes cybersecurity risk-management measures or incident notification requirements that are at least equivalent in effect, the corresponding NIS2 provisions do not apply. That is a real carve-out.
But it is narrower than the marketing around it suggests. DORA is the clean case: Article 1(2) of Regulation (EU) 2022/2554 states in its own text that it counts as a sector-specific act for Article 4 purposes. Nothing equivalent exists in the Part-IS regulations. The Commission's guidelines on the application of Article 4(1) and (2) list the acts it considers to fall within scope, and the aviation position has been debated openly since — including on EASA's own community forum.
The practical position for a consultant: assume both apply until the client's national competent authority says otherwise in writing.
That is less painful than it sounds, because the frameworks are not in conflict. Part-IS is scoped to information security risks with a potential impact on aviation safety. NIS2 Article 21 is scoped to risks to network and information systems supporting the service. The overlap is large but the edges are different — Part-IS will not require you to prove supply chain security across your commercial IT estate, and NIS2 will not require you to link every finding back to a safety outcome.
Map both, mark the shared controls once, and document the delta. Auditors accept a mapped control that serves two regimes. They do not accept "we are covered by Part-IS" as an answer to an Article 21 evidence request.
Maritime has the same structure with different names. ISPS and the IMO's maritime cyber risk management guidance sit alongside NIS2, not instead of it. Port managing bodies routinely produce their ISPS port facility security plan when asked for NIS2 evidence. It is a good document. It is not a risk management policy under Article 21(2)(a).
The Article 21 measures land differently in an operational environment
The ten measures are the same in every sector. What changes is where the evidence lives.
In transport, three of them consistently produce findings.
Article 21(2)(c), business continuity and crisis management. Transport operators have excellent continuity plans — for physical disruption. Weather, strikes, blocked corridors. Almost none of them have tested a scenario where the scheduling or dispatch system is encrypted and unavailable for four days. That is the scenario the regulator will ask about.
Article 21(2)(d), supply chain security. Transport runs on shared operational systems: terminal operating systems, baggage handling, signalling suppliers, maintenance telemetry vendors. Each of these is a named third party whose security posture your client has to be able to describe. Passing a questionnaire down the chain is not enough on its own — the obligation is to assess and to act on what you find. See why supplier contracts are now part of NIS2 compliance.
Article 21(2)(i), access control and asset management. Operational technology in transport is old, physically distributed, and frequently maintained by external engineers with standing remote access. A complete asset inventory that includes trackside, quayside and airside equipment is the hardest single deliverable in this sector, and it is the first thing an inspector asks to see.
Article 21 — 10 NIS2 Cybersecurity Measures
Article 21
10 Cybersecurity Measures
Governance & Strategy
1Risk analysis & information security policies6Effectiveness assessment of security measuresIncident & Continuity
2Incident handling & notification3Business continuity & disaster recoverySupply Chain & Systems
4Supply chain security5Security in network & information systems developmentTechnical Controls
8Cryptography & encryption10Multi-factor authentication & secure communicationsPeople & Assets
7Cyber hygiene & training9HR security & access control
The IT/OT boundary problem here is the same one we mapped for manufacturers, with one difference: in transport the OT is often not on your client's premises at all.
Incident reporting: two clocks, two regulators
Transport operators already report. Aviation reports occurrences under Regulation (EU) 376/2014. Rail reports to national safety authorities. Maritime reports under its own regime.
None of that satisfies Article 23.
NIS2 requires an early warning to the CSIRT or competent authority within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month. Common templates adopted by the NIS2 Cooperation Group in May 2026 removed the format excuse.
The failure mode is predictable: the safety report goes out on time, the cyber report does not, because nobody in the operations room knows the 24-hour clock exists. Build the trigger into the existing occurrence reporting workflow rather than beside it, and make the duty officer's checklist ask one extra question — could this have originated in a network or information system? The reporting deadlines are covered in detail here.
What to do in the next 30 days
For each transport client, in this order:
- Confirm the Annex I subsector and entity type in writing, using the actual wording of the list rather than a summary.
- Check the national designation list for below-threshold entities before applying the size test.
- If aviation or maritime, produce a control mapping between the sector regime and Article 21 — and mark the gaps rather than assuming coverage.
- Pull the asset inventory for operational technology. If it does not exist, that is your first project, not your last.
- Wire the 24-hour NIS2 clock into the existing operational incident workflow.
Everything after that is documentation discipline, and we set out what inspectors actually ask for in the supervisory audit evidence checklist.
If you want a structured starting point for a transport client, run a free NIS2 quick scan — it produces a gap analysis against the Article 21 measures in about ten minutes, which is enough to tell you whether the sector regime the client is relying on is actually carrying the weight they think it is.
Still have a question?
Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.
