NIS2 Compliance
Full NIS2 Directive compliance for space essential entities.
The NIS2 Directive (EU 2022/2555) establishes cybersecurity requirements for essential and important entities, including space operators. This module provides comprehensive NIS2 compliance guidance specific to the space sector.
Regulations
Jurisdictions
What this module does
Entity Classification
Determine your entity classification (essential vs. important) under NIS2 based on sector, size, and criticality criteria.
Security Measures Assessment
Gap analysis against all Art. 21(2) security measures (a)–(j) with space-sector-specific control mappings.
Incident Reporting Workflows
Structured workflows meeting the 24h early warning, 72h notification, and 1-month final report requirements.
Supply Chain Security
Evaluate and document supply chain security measures for critical space system components and services.
What the assessment includes
Auto-generated compliance documents
What we automate for you
Automated entity classification questionnaire
Pre-mapped controls to Art. 21(2) measures
Incident timeline enforcement and reminders
Management liability documentation
See if this module applies to you
Take the free compliance assessment to find out which modules are relevant to your operation.
Frequently Asked Questions — NIS2 Compliance
Am I an essential or important entity under NIS2?+
Space is a sector in NIS2 Annex I (No. 11: operators of ground-based infrastructure that supports space-based services). Entities of that type that exceed the EU ceilings for medium-sized enterprises (250 or more staff, or annual turnover above EUR 50M and balance sheet above EUR 43M; Recommendation 2003/361/EC) are essential (Art. 3(1)(a)); medium-sized ones are important (Art. 3(2)). Small and micro entities are outside NIS2 (Art. 2(1)) unless a size-independent case of Art. 2(2) applies, for example identification by a Member State. National transposition laws decide the details.
What security measures does NIS2 require?+
Article 21(2) requires at least: (a) policies on risk analysis and information system security; (b) incident handling; (c) business continuity, backup management, disaster recovery and crisis management; (d) supply chain security; (e) security in acquisition, development and maintenance, including vulnerability handling and disclosure; (f) procedures to assess the effectiveness of the measures; (g) basic cyber hygiene and cybersecurity training; (h) cryptography and, where appropriate, encryption; (i) human resources security, access control and asset management; (j) multi-factor or continuous authentication and secured communications, where appropriate.
What are the penalties for NIS2 non-compliance?+
For infringements of Art. 21 or 23, Member States must provide fines with a maximum of at least EUR 10M or 2% of total worldwide annual turnover, whichever is higher, for essential entities and at least EUR 7M or 1.4% for important entities (Art. 34(4)-(5)). Other supervisory and enforcement measures follow from Art. 32-33; penalties for other infringements are set nationally (Art. 36).
Related NIS2 Cybersecurity Resources
NIS2 for Space Operators
How the NIS2 Directive applies to satellite operators and space services.
Cybersecurity Module
NIS2-aligned cybersecurity assessment and compliance tracking.
NIS2 Assessment
Classify your organization under the NIS2 Directive.
Supervision & Reporting
Ongoing supervisory obligations and incident reporting.