Directive NIS2 European Union
Cart 0
Annex I · sector 2 of 18

NIS2 for Transport


Cross-border by nature, so the article 23 cross-border impact assessment is not theoretical. A single incident can require notification in several member states at once, through different portals.

Annex
I
Default class
Essential
Supervision
ex ante
Maximum fine
10 M€ / 2 %

Which entities are covered


Air carriers, airport managing bodies, air traffic management; infrastructure managers and railway undertakings; inland, sea and coastal passenger and freight water transport companies, port managing bodies, vessel traffic services; road authorities and operators of intelligent transport systems.

Sub-sectors named in the annex

  • Air
  • Rail
  • Water
  • Road

Scope traps specific to this sector


Trap 1

Airport managing bodies and port authorities are in scope as such — not only the carriers using them.

Trap 2

Operators of intelligent transport systems are named, which reaches traffic-management software vendors operating infrastructure.

Trap 3

Aviation already has EASA Part-IS cybersecurity requirements; they do not displace NIS2 unless the national transposition says so.

What else applies to you


EASA Part-IS for aviation; the CER directive; ISPS for maritime port facility security.

NIS2 rarely arrives alone. Where another EU act covers the same ground and is at least equivalent in effect, article 4 disapplies the corresponding NIS2 provisions — but only those, and only where that test is met.

Cart 0