Skip to content

Evidence request lists

EU NIS2 Directive - Transport Sector Requirements

Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

NIS2 Transport - Governance, Supply Chain and Certification (Articles 20, 22, 24)

NIS2-TRN-Art20
Management body responsibilities and training (NIS2 Article 20)

Article 20 NIS2 imposes governance responsibilities directly on the management body of Essential Entities. The management body must approve the cybersecurity risk-management measures taken under Article 21, oversee their implementation, and may be held liable for infringements. Article 20(2) requires members of the management body to follow training to gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices; Article 20(2) further requires entities to offer similar training to their employees on a regular basis. For transport entities the training scope should cover sector-specific cybersecurity threats (e.g. OT cyber-attacks on signaling, GNSS spoofing, port-system disruption).

Artefacts an auditor will ask for
  • Management body cybersecurity training records aligned with Article 20(2)
  • Annual employee cybersecurity training programme
  • Records of management-body approval of Article 21 measures
Where this commonly fails
  • No management-body cybersecurity training programme
  • Article 21 measures implemented without management-body approval
  • Liability of management body for non-compliance not factored into D&O insurance review
NIS2-TRN-Art22
Coordinated risk assessments of critical supply chains (NIS2 Article 22)

Article 22 enables Union-level coordinated security risk assessments of specific critical ICT services, ICT systems and ICT products supply chains, conducted by the NIS Cooperation Group + ENISA + Commission. Examples include the 5G coordinated risk assessment + the artificial-intelligence-and-machine-learning coordinated risk assessment + telecommunications supply chain. Transport entities relying on ICT products / services covered by an Article 22 coordinated assessment (e.g. 5G-enabled air-traffic control, AI-driven autonomous-vehicle systems) must take the assessment outcomes into account in their Article 21(2)(d) supply-chain security measures.

Artefacts an auditor will ask for
  • Tracking of Article 22 coordinated risk assessments affecting transport ICT supply chains (5G, AI, cloud)
  • Incorporation of Article 22 findings into the entity's supply-chain risk register
Where this commonly fails
  • 5G / AI / cloud supply-chain decisions not informed by Article 22 coordinated risk assessments
NIS2-TRN-Art24
Use of European cybersecurity certification schemes (NIS2 Article 24)

Article 24 NIS2 enables Member States to require Essential and Important Entities to use particular ICT products, services, or processes that are certified under European cybersecurity certification schemes adopted pursuant to Article 49 of Regulation (EU) 2019/881 (the Cybersecurity Act). The Commission may adopt implementing acts requiring such certification for specified categories of essential entities. Transport entities should consider the EUCC (European Common Criteria-based) cybersecurity certification scheme + sector-specific certifications as they emerge.

Artefacts an auditor will ask for
  • Records of European cybersecurity certification scheme conformity where applicable to transport ICT products / services
  • Tracking of Article 24 implementing acts that may impose certification requirements
Where this commonly fails
  • Procurement of ICT products / services for critical transport systems without considering available European cybersecurity certification schemes
NIS2-TRN-Sectoral-Coordination
Sectoral lex specialis coordination - air / rail / water / road (NIS2 Article 4 + Article 12)

Article 4 NIS2 coordinates with sectoral Union acts (lex specialis). Where a sectoral Union act lays down cybersecurity requirements at least equivalent to NIS2 obligations (Article 21 + Article 23), it applies in place of NIS2. Transport-relevant lex specialis includes: Regulation (EU) 2018/1139 (Civil Aviation - the EASA Cyber Information Sharing Regulation; Commission Implementing Regulation 2023/203 'Part-IS'); Directive 2017/541 (Railway Safety); Regulation (EU) 1315/2013 (TEN-T network including roads); SOLAS Chapter XI-2 / ISPS Code for maritime port security. Article 12 NIS2 establishes the NIS Cooperation Group, which has sector-specific subgroups including transport.

Artefacts an auditor will ask for
  • Identification of applicable sectoral lex specialis for the entity (e.g. EASA Part-IS for aviation, ISPS for maritime, Railway Safety Directive)
  • Internal coordination ensuring sectoral compliance + NIS2 baseline where lex specialis is less stringent
Where this commonly fails
  • Compliance plan that ignores sectoral lex specialis
  • Treating sectoral lex specialis as a replacement when it does not cover all Article 21 / Article 23 obligations

NIS2 Transport - Incident Reporting (Article 23)

NIS2-TRN-Art23
Incident reporting obligations - 24h early warning + 72h notification + 1-month final report (NIS2 Article 23)

Article 23 NIS2 sets the layered incident-reporting regime applying to Essential Entities (including transport): (1) Article 23(4)(a) Early warning to the CSIRT or competent authority within 24 hours of becoming aware of a significant incident (information on whether it was caused by unlawful or malicious acts + potential cross-border impact); (2) Article 23(4)(b) Incident notification within 72 hours of becoming aware (severity + initial assessment + indicators of compromise); (3) Article 23(4)(c) Intermediate report on request; (4) Article 23(4)(d) Final report no later than one month after submitting the incident notification (detailed description of incident + severity + impact + root cause + cross-border implications + mitigation measures). The 'significant incident' threshold under Article 23(3) covers incidents causing severe operational disruption + financial loss + material/non-

Artefacts an auditor will ask for
  • Internal incident-detection + classification + reporting workflow capable of meeting the 24-hour early-warning deadline
  • CSIRT / competent authority reporting channel configured + tested
  • Incident-report templates for the layered (24h/72h/1-month) reporting
  • Cross-border coordination procedure where the incident affects multiple Member States
Where this commonly fails
  • No 24/7 capability to meet 24-hour early-warning deadline
  • Slow incident classification preventing meeting 72-hour notification
  • Late or omitted final report
  • Transport-disruption thresholds for 'significant incident' not internalised in alerting rules

NIS2 Transport - Risk Management Measures (Article 21(2))

NIS2-TRN-Art21(2)
Cybersecurity risk-management measures (NIS2 Article 21(2)(a)-(j))

Article 21(2) NIS2 requires Essential Entities (including transport-sector entities) to take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems. The measures cover at least: (a) policies on risk analysis and information system security; (b) incident handling; (c) business continuity (backup management + disaster recovery + crisis management); (d) supply chain security (including security-related aspects concerning the relationships between each entity and its direct suppliers / service providers); (e) security in network and information systems acquisition / development / maintenance + vulnerability handling and disclosure; (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures; (g) basic cyber-hygiene practices and cybersecurity training;

Artefacts an auditor will ask for
  • Article 21(2)(a)-(j) compliance file for each transport entity covering all 10 baseline measure categories
  • OT security architecture for signaling / traffic control / vessel-traffic-service systems
  • Supply chain security agreements with direct suppliers and service providers under Article 21(2)(d)
Where this commonly fails
  • Transport entity without an Article 21(2) compliance file
  • OT systems excluded from cybersecurity risk-management measures
  • Supply chain security limited to IT and not extended to OT vendor relationships

NIS2 Transport - Sectoral Scope (Annex I Sector 5)

NIS2-TRN-Scope
Sectoral scope - Annex I Sector 5 Transport (NIS2 Article 2 + Annex I)

NIS2 Annex I, Sector 5 lists Transport as a critical sector classifying covered entities as 'Essential Entities' (Article 3(1)(a) NIS2 - size-cap rule + sectoral scope + entity-type). The four sub-sectors are: (a) Air transport - air carriers (Regulation (EC) 300/2008 + 1008/2008), airport managing bodies (Directive 2009/12/EC), air traffic management control providers; (b) Rail transport - infrastructure managers (Directive 2012/34/EU) + railway undertakings; (c) Water transport - inland-waterway, sea + coastal-passenger / freight (Council Directive 2017/352 + (EC) 725/2004) + port managing bodies + vessel traffic services; (d) Road transport - road authorities responsible for traffic management + ITS (Intelligent Transport System) operators under Directive 2010/40/EU. The size-cap rule (Article 2(2) NIS2) generally applies medium/large enterprises (>= 50 employees / EUR 10M+ annual tur

Artefacts an auditor will ask for
  • Internal scope determination identifying the entity's NIS2 Annex I Sector 5 sub-sector + size-cap analysis
  • Registration with the national competent authority per Article 27 NIS2
Where this commonly fails
  • Transport entity above the size-cap threshold not registered as an Essential Entity
  • Sub-sector classification missing (air vs rail vs water vs road) for compliance scoping

NIS2 Transport - Supervision and Enforcement (Articles 31-34)

NIS2-TRN-Art27
Registration of essential and important entities (NIS2 Article 27)

Article 27 NIS2 requires Member States to establish a list of essential and important entities and require those entities to submit registration information by 17 April 2025 (subject to national-law transposition variations). The information required includes: name + address + Member State + sector + relevant sectoral and sub-sectoral activity + list of Member States where the entity provides services + IP ranges + EUDAMED-equivalent identifiers. For transport entities operating cross-border (multinational air carriers + rail undertakings + shipping lines), registration involves identifying the home Member State + reporting cross-border presence.

Artefacts an auditor will ask for
  • Article 27 registration submission to the national competent authority
  • Cross-border-presence reporting
  • Annual update of registration data
Where this commonly fails
  • Transport entity meeting Annex I scope but not registered with the national competent authority
  • Multinational entity not coordinating registration across Member States
NIS2-TRN-Art31_32_33
Supervisory measures for essential entities (NIS2 Articles 31-33)

Article 31 NIS2 sets the scope of supervision for essential entities (ex-ante and ex-post). Article 32 enumerates the supervisory measures for essential entities: (a) on-site inspections + off-site supervision; (b) targeted security audits based on risk assessments + by competent authority or accredited audit body; (c) ad-hoc audits in case of significant incident or where significant evidence of non-compliance; (d) security scans based on objective + non-discriminatory + transparent criteria; (e) requests for information; (f) requests for access to data + documents. Article 33 establishes enforcement powers including issuing warnings + binding instructions + ordering certification or audit by an accredited body + ordering implementation of the recommendations resulting from a security audit + ordering disclosure of aspects of the cybersecurity risk-management measures + temporary suspen

Artefacts an auditor will ask for
  • Audit-readiness records (Article 21(2) measures + Article 23 incident records + Article 27 registration data)
  • Procedure to receive + respond to Article 32 information requests
  • Internal procedure to handle Article 33 binding instructions
Where this commonly fails
  • No audit-readiness file
  • Slow response to Article 32 requests
  • Article 33 binding instructions not promptly implemented
NIS2-TRN-Art34
Administrative fines (NIS2 Article 34) - up to EUR 10M or 2% of turnover

Article 34 NIS2 requires Member States to ensure that administrative fines are imposed for infringements of the obligations laid down in Article 21 (risk-management measures), Article 23 (incident reporting) and Article 26 (jurisdiction). The maximum administrative fines for Essential Entities are at least: EUR 10 million OR 2% of the total worldwide annual turnover of the undertaking to which the essential entity belongs in the preceding financial year, whichever is higher. (For Important Entities the ceiling is EUR 7 million or 1.4%.) Article 34(3) sets the criteria for fixing the level of the fine (nature + gravity + duration + intentional / negligent nature + previous infringements + measures taken to mitigate damage + degree of cooperation + relevant industry standards).

Artefacts an auditor will ask for
  • Awareness of the EUR 10M / 2%-of-turnover ceiling in the entity's compliance risk register
  • Compliance program demonstrating proactive risk management against Article 34 criteria
  • Insurance / financial-coverage analysis for Article 34 exposure
Where this commonly fails
  • Compliance program ignoring the Article 34 penalty ceiling
  • Incident-mitigation efforts not documented in a way that supports the Article 34(3) cooperation + mitigation criteria
NIS2-TRN-Status
Sectoral application view status (this corpus node)

This corpus node is a sector-specific application view of the NIS2 Directive (EU) 2022/2555 for transport entities. The substantive cybersecurity obligations come from the NIS2 main Directive (referenced via cross-mappings to Art.21(2)(a)-(j) + Art.23 + Art.20 + Art.22 + Art.24 + Art.27 + Articles 31-34). This corpus node does NOT add new substantive obligations - it organises NIS2 obligations for the transport sector and captures sectoral coordination considerations (lex specialis coordination, OT security calibrations, sub-sector specificities for air / rail / water / road). Status: referenced (sector-application view of an existing enacted directive). Member States transposed NIS2 by 17 October 2024 (Article 41 NIS2). Transport entities must comply with the transposed national NIS2 law from that date.

Artefacts an auditor will ask for
  • Internal mapping of the entity's NIS2 compliance program to the transposed national law of each Member State where it operates
  • Coordination with sectoral regulators (EASA, ERA, EMSA) on cybersecurity matters
Where this commonly fails
  • Treating this corpus node as the substantive source (it is a sector-application view; the substance is NIS2 main + national transposition law)
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the EU NIS2 Directive - Transport Sector Requirements framework page.