NIS2 Directive
The EU Directive 2022/2555 on measures for a high common level of cybersecurity across the Union, applicable to space infrastructure operators.
The NIS2 Directive (EU 2022/2555) is the updated European cybersecurity framework that significantly expands the scope of cybersecurity obligations. For space operators, NIS2 introduces mandatory security requirements for critical infrastructure.
Space Sector Coverage Space is explicitly listed as a critical sector under NIS2. This includes:
- Satellite communication providers
- Ground station operators
- Space data service providers
- Launch service providers with digital dependencies
Entity Classification In-scope entities are essential or important:
- Essential Entities: among others, entities of a type in Annex I that exceed the ceilings for medium-sized enterprises (Art. 3(1)(a))
- Important Entities: the other in-scope entities of a type in Annex I or II (Art. 3(2))
Key Requirements
- Risk management measures (Art. 21)
- Reporting of significant incidents: early warning within 24 hours and notification within 72 hours of becoming aware, final report within one month of the notification (Art. 23(4))
- Supply chain security
- Business continuity planning
- Encryption and access controls
Penalties (for infringements of Art. 21 or 23; Member States set the maxima at least at)
- Essential entities: €10 million or 2% of total worldwide annual turnover, whichever is higher (Art. 34(4))
- Important entities: €7 million or 1.4% of total worldwide annual turnover, whichever is higher (Art. 34(5))
Implementation Deadline The NIS2 transposition deadline was 17 October 2024; Germany implemented it via the NIS2UmsuCG, in force since December 2025.