NIS2 · Sector deep-dive

NIS2 for Energy

Energy is the first sector listed in Annex I of NIS2, the annex of sectors of high criticality, which means most in-scope energy entities are supervised as essential entities. The sector spans electricity, district heating and cooling, oil, gas and hydrogen — hydrogen being newly brought in under NIS2, covering the operators of hydrogen production, storage and transmission. Within those sub-sectors the directive reaches generation, transmission and distribution system operators, suppliers and market participants, and the newer flexibility roles: demand response operators, electricity storage operators and aggregators.

Why energy is in scope

Energy is the infrastructure other infrastructure depends on. A disruption at a transmission or distribution operator does not stay inside the sector: water treatment, hospitals, telecoms, transport and payment systems all lose capability within hours. That cascading effect is the reason the directive treats energy as high criticality and supervises its large operators proactively rather than after the fact.

The attack surface has also grown considerably. Smart metering, distributed generation, remote substation monitoring and cloud-based market and balancing platforms have replaced isolated control systems with networks that reach thousands of endpoints and multiple external parties. Grid control now depends on data flowing correctly across those links, not only on the physical plant behaving.

Where energy operators typically have the biggest gaps

  • SCADA and grid-control security. Control systems, RTUs and substation automation often run long-lived protocols with weak or absent authentication, on hardware that cannot be patched during operation. Monitoring coverage in the control environment is usually far thinner than in corporate IT.
  • Third-party maintenance access to critical infrastructure. Turbine, converter, protection-relay and control-system vendors need remote access to support their equipment. Standing accounts, shared credentials and unlogged sessions are common, and each one is a privileged path into the operational environment.
  • Cross-border interconnection risk. Operators connected to neighbouring national grids exchange operational data continuously with counterparties under different national regimes and different supervisory authorities. Incident coordination, information sharing and the security assumptions on each side of the interconnection are frequently undocumented.

What this means for the Article 21 measures

  • Multi-factor authentication and secure communications — Article 21(2)(j). Apply MFA to control-room access, engineering workstations and every remote-access route into the operational environment, and secure the voice and data channels used for operational coordination.
  • Incident handling — Article 21(2)(b). Given the cascading impact a grid incident can have, detection, escalation and the 24-hour early-warning obligation need to work at any hour, with the control room and the security function operating from one agreed procedure rather than two.
  • Supply chain security — Article 21(2)(d). Assess grid hardware and control-system vendors, including their remote-access practices, their firmware vulnerability handling, and how long they will support the equipment you are installing for the next two decades.

As an essential entity, an energy operator is subject to proactive supervision — authorities can inspect and audit without any incident having occurred — so the evidence behind these measures needs to exist before it is asked for. The complete set is on the Article 21 requirements page.

Documentation

The NIS2 Starter Kit's incident handling and access control templates are built for critical-infrastructure operators.

View the NIS2 Starter Kit

Related reading

Frequently asked questions