NIS2 · Sector deep-dive
NIS2 for the Space Sector
Space is an Annex I sector of high criticality, and the one whose scope is most often misread. NIS2 does not regulate spacecraft. It regulates the ground-based infrastructure that supports space-based services — the antennas, control centres, telemetry links and data platforms without which a satellite is unreachable. If your organisation operates any part of that ground segment above the size threshold, you are in scope.
The ground segment is the attack surface
Attacks on space services have overwhelmingly targeted the ground, not orbit. The disruption of a satellite broadband service across Europe at the start of the war in Ukraine was achieved through the management network of the ground infrastructure and user modems, not by touching the spacecraft. That is the pattern the directive is written against: compromise the systems that command, monitor or distribute, and the space asset becomes useless without anyone going near it.
Ground segments have a characteristic shape that makes this harder than it looks. Antenna sites are remote and often unstaffed. Mission control software is long-lived, specialised and difficult to patch on a normal cadence. Operations are frequently shared between the satellite owner, a ground-station network, an integrator and a data-processing partner, so privileged access is spread across several organisations. And in many programmes the same team runs commercial, scientific and government payloads on shared infrastructure.
Downstream dependency is what raises the stakes. Positioning, navigation and timing, earth observation, and satellite communications feed energy grids, transport, finance and emergency services. A ground-segment incident therefore propagates into other NIS2 sectors, which is precisely why space was added to Annex I rather than left out as a niche.
Where space operators typically have the biggest gaps
- Remote antenna sites. Unstaffed teleports and TT&C stations reached over vendor VPNs, with physical and logical access controls that were designed for availability rather than for an adversary.
- Split operational responsibility. Satellite owner, ground-station provider and payload operator each hold privileged access, and no single party can produce a complete list of who can command what.
- Legacy mission control software. Bespoke systems with long qualification cycles, running on operating systems that are years behind, because a patch means a revalidation campaign.
- Security treated as a mission-assurance annex. Extensive reliability and safety engineering, but no risk management framework in the Article 21 sense, and no management body approving it.
- Unclear incident ownership. When an incident spans owner, ground network and data provider, the 24-hour early warning is everyone's job and therefore nobody's.
What this means for the Article 21 measures
- Supply chain security — Article 21(2)(d). The single highest-value measure in this sector. Contract every ground-segment partner for named individual accounts, time-boxed privileged access, logging you can read, and vulnerability notification for the systems they supply.
- Access control and asset management — Article 21(2)(i) and (j). A single authoritative register of who can issue commands, from where, and through which system, with MFA and strong authentication on every command path.
- Business continuity and crisis management — Article 21(2)(c). A tested fallback for losing a primary ground station or control centre, including restoration of mission control configuration from verified offline backups.
- Incident handling — Article 21(2)(b). One agreed procedure across the operating consortium that names which party files the early warning and how the others feed it. See the reporting timeline.
- Cryptography and secure communications — Article 21(2)(h) and (k). Encryption and authentication on telemetry, command and inter-site links, with a policy governing key handling across organisational boundaries.
The full measure list is on the Article 21 requirements page. Operators supplying communications services should also read NIS2 for digital infrastructure, since satellite communications capacity can bring a second sector entry into play.
Documentation
The NIS2 Starter Kit provides the risk assessment, asset register, access control policy and incident procedure that a ground-segment operator needs as its baseline evidence.
