NIS2 · Sector deep-dive

NIS2 for Transport

Transport is an Annex I sector of high criticality, so large in-scope operators are normally supervised as essential entities. The annex splits the sector four ways — air, rail, water and road — and covers carriers as well as the infrastructure and traffic management entities they depend on: airport managing bodies, air traffic management, railway infrastructure managers, port authorities, vessel traffic services, road authorities and operators of intelligent transport systems.

Why transport is in scope

Transport is where a digital failure becomes a physical queue within minutes. Booking and departure control, cargo manifests, terminal operating systems, signalling and traffic management all now run on networked software, and there is rarely a manual fallback that can absorb full volume. A container terminal that loses its terminal operating system cannot simply move boxes by hand; a rail operator that loses its planning system cannot safely improvise a timetable.

The sector is also unusually interconnected. Carriers, ground handlers, freight forwarders, customs systems and port community systems exchange data continuously, so an incident at one operator propagates across the chain and across borders. Several of the largest cyber incidents in European logistics spread precisely this way — through shared platforms and trusted integrations rather than through a direct attack on the disrupted party.

Finally, transport runs a lot of long-lived operational technology. Signalling equipment, crane control systems, baggage handling and airfield systems are engineered for decades of service and are increasingly remote-monitored, which quietly turns isolated control networks into internet-reachable ones.

Where transport operators typically have the biggest gaps

  • OT with no owner in the risk picture. Terminal, signalling and airfield systems are managed by engineering teams whose risk assessments never meet the IT risk register, so nobody holds the combined picture.
  • Third-party platform dependency. Port community systems, slot management and booking platforms are single points of failure that most operators have never risk-assessed as such.
  • Remote and mobile access. Crews, drivers, handlers and field engineers connect from everywhere, often on shared or contractor-owned devices, with weak identity assurance.
  • Cross-border reporting confusion. Operators established in several member states rarely know which competent authority and which CSIRT they must notify, and lose hours of the 24-hour clock finding out.

What this means for the Article 21 measures

  • Risk analysis across IT and OT — Article 21(2)(a). One register covering booking, planning, control and safety-adjacent systems, with the operational consequence of each failure expressed in service terms: delayed departures, halted throughput, closed lanes.
  • Supply chain security — Article 21(2)(d). Treat shared platforms, ground handlers and maintenance vendors as in-scope dependencies. Contract for vulnerability handling, notification duties and controlled remote access.
  • Incident handling — Article 21(2)(b). A named authority and CSIRT per country of establishment, a duty officer who can send the early warning inside 24 hours, and a pre-agreed template so the first report does not wait for a full technical picture.

The full set of obligations is on the Article 21 requirements page, and the notification sequence is on the incident reporting page. Where a sector-specific act already imposes equivalent duties, the lex specialis rule decides which text applies.

Documentation

The NIS2 Starter Kit gives you the risk assessment, asset register and incident procedure to build a combined IT/OT picture across terminals, fleets and control rooms.

View the NIS2 Starter Kit

Related reading

Frequently asked questions