NIS2 for Transport
Cross-border by nature, so the article 23 cross-border impact assessment is not theoretical. A single incident can require notification in several member states at once, through different portals.
Which entities are covered
Air carriers, airport managing bodies, air traffic management; infrastructure managers and railway undertakings; inland, sea and coastal passenger and freight water transport companies, port managing bodies, vessel traffic services; road authorities and operators of intelligent transport systems.
Sub-sectors named in the annex
- Air
- Rail
- Water
- Road
Scope traps specific to this sector
Trap 1
Airport managing bodies and port authorities are in scope as such — not only the carriers using them.
Trap 2
Operators of intelligent transport systems are named, which reaches traffic-management software vendors operating infrastructure.
Trap 3
Aviation already has EASA Part-IS cybersecurity requirements; they do not displace NIS2 unless the national transposition says so.
What else applies to you
EASA Part-IS for aviation; the CER directive; ISPS for maritime port facility security.
NIS2 rarely arrives alone. Where another EU act covers the same ground and is at least equivalent in effect, article 4 disapplies the corresponding NIS2 provisions — but only those, and only where that test is met.