NIS2 introduces new cybersecurity obligations for organisations operating across the EU’s critical sectors. If you’re one of them, this guide gives you a clear picture of what is required to comply, whether you run a grid, a gas distribution network, or a renewable generation portfolio. It also explains who is in scope and how the right IT/OT architecture can turn compliance into genuine operational resilience.
Why NIS2 Matters for Energy Operators Right Now
Energy infrastructure is fundamental to essential services. That makes it a high-value target for cyber attacks, not helped by the fact that generation assets, substations, and control systems have become increasingly connected. Operators need to protect not only business systems but also the operational technology that keeps energy flowing.
For that reason, energy is classified as an Annex I essential sector under NIS2, the EU’s Network and Information Security Directive (EU 2022/2555). It includes electricity generation and distribution, oil, gas, hydrogen, and district heating.
If your organisation is designated as an essential entity, it faces the highest supervisory obligations and the steepest penalties under the Directive.
However, NIS2 isn’t just about avoiding penalties. The measures it requires—network segmentation, supply chain security, access controls, and incident detection—are all fundamental to protecting modern energy infrastructure. You should be adopting them regardless, for operational resilience.
Who Is in Scope
General Scope Thresholds
NIS2 generally applies to medium and large organisations operating in sectors considered critical to society and the economy. These include energy, transport, healthcare, banking, digital infrastructure, water, public administration, and several other essential services.
For energy operators, the general threshold is 50 or more employees or annual turnover exceeding €10 million.
Those thresholds aren’t absolute. Member states can designate organisations as being in scope regardless of size where their services are considered critical to national infrastructure.
If your organisation generates, transmits, distributes, or supplies electricity, gas, hydrogen, oil, or district heating within the EU, assess your obligations as NIS2 is relevant to you. Smaller operators should therefore confirm their status with their national competent authority rather than assuming they’re exempt.
What Is an Essential Entity Under NIS2?
Large organisations operating critical energy infrastructure will be treated as essential entities under NIS2. If your organisation is classified as an essential entity, you’ll face the highest level of regulatory oversight, including proactive supervisory audits and the Directive’s steepest financial penalties.
Member states can also designate smaller organisations as essential where they provide services considered critical to national infrastructure.
What Is an Important Entity Under NIS2?
An important entity is an organisation in an Annex II sector, or a medium-sized entity in an Annex I sector that doesn’t meet the threshold for essential entity designation. If you are designated an important entity, you face lighter supervisory oversight—reactive rather than proactive—but still carry significant obligations and penalties.
Does NIS2 Apply in the UK?
NIS2 is an EU directive. It doesn’t directly apply in the UK following Brexit. UK energy operators are governed by the UK Network and Information Systems (NIS) Regulations 2018 and associated guidance from the National Cyber Security Centre (NCSC) and Ofgem as the relevant competent authority for energy.
The Cyber Security and Resilience (Network and Information Systems) Bill has now completed its passage through the House of Commons, and is currently progressing through the House of Lords. If enacted, it will represent the most significant update to UK cyber security legislation since the Network and Information Systems Regulations 2018. It is expected to bring UK obligations closer to the approach taken under NIS2.
UK operators with EU operations or subsidiaries may need to comply with both regimes. If your organisation operates generation assets or supplies customers in EU member states, NIS2 applies directly to those activities.
What Article 21 Requires
Technical Measures in Plain English
Article 21 of NIS2 mandates an all-hazards approach to risk management. It doesn’t prescribe a fixed set of security controls; instead, NIS2 expects your organisation to identify the cyber risks you face and implement measures that are appropriate to those risks.
Article 21 sets out ten areas that your organisation is expected to address, from risk management and supply chain security to access controls and incident response.
The Ten Article 21 Measures
Source: Directive (EU) 2022/2555, Article 21
- Risk analysis and information system security policies
- Incident handling procedures
- Business continuity and crisis management
- Supply chain security, including relationships with direct suppliers and service providers
- Security in network and information systems acquisition, development, and maintenance
- Policies and procedures to assess the effectiveness of cybersecurity risk management
- Basic cyber hygiene practices and cybersecurity training
- Policies and procedures on the use of cryptography and encryption
- Human resources security, access control policies, and asset management
- Multi-factor authentication (MFA), continuous authentication solutions, and secure communications
For energy operators, one of the most important practical implications is the separation of operational technology (OT) from corporate IT. NIS2 expects organisations to control and monitor the flow of data between those environments, reducing the risk that an incident affecting business systems can spread into critical operational infrastructure.
Supply Chain Security Is Not Optional
Energy operators often rely on third-party vendors for supervisory control and data acquisition (SCADA) software, industrial control system (ICS) components, and managed services. Article 21 requires you to assess the cybersecurity practices of those suppliers and include security obligations in contracts. If a vendor has access to your OT environment, weaknesses in their security can become risks to your own environment.
OT and SCADA Environments
Where NIS2 Gets Operationally Complex
Legacy SCADA and ICS were engineered for availability and process reliability, not for integration with modern security controls. Patching decades-old control systems without disrupting generation or distribution is a genuine operational challenge. And NIS2 doesn’t exempt you from managing the risk those systems present.
The practical answer is compensating controls and architectural segmentation. Where you can’t patch, you isolate. Where you can’t upgrade, you control what can reach the system and what can leave it.
The IT/OT Convergence Opportunity
The convergence of IT and OT creates real operational value: real-time telemetry feeding predictive maintenance models, generation data flowing into energy management platforms, and BESS performance metrics informing grid balancing decisions. The risk is that without controlled data exchange, opening those data flows creates a path from the corporate network into the OT environment.
This is typically addressed by creating a policy-enforced boundary, where OT data can flow outward to IT analytics without creating a bidirectional attack path. A data diode, for example, enforces hardware-level unidirectional communication, allowing OT data to reach IT analytics while physically preventing reverse network traffic. Where bidirectional communication is required, a cross-domain solution such as 4Secure’s TrustedFilter® adds content inspection and policy enforcement so only authorised and validated information can cross the boundary.
Incident Reporting
What the Timelines Mean in Practice
NIS2 introduces strict reporting deadlines for significant cyber incidents. Missing them can itself become a compliance issue, so organisations need reporting processes that are as well prepared as their technical controls.
Article 23 of NIS2 establishes a three-stage reporting sequence for significant incidents. Missing these deadlines is itself a compliance failure, so understanding the timelines as operational requirements rather than administrative ones is worth doing now, before an incident occurs.
Source: Directive (EU) 2022/2555, Article 23
24 Hours: Early Warning
Submit an early warning to your national competent authority. To meet this deadline, you need to detect the incident, determine that it’s significant, and notify the right people internally within a single working day.
72 Hours: Detailed Notification
Submit a detailed incident notification, including your initial assessment of the incident severity, impact, and likely cause. Your security operations capability needs to produce that assessment within three days of detection.
30 Days: Final Report
Submit a final report covering a full analysis of the incident, the threat type involved, mitigation measures applied, and cross-border impact where relevant.
For many energy operators, the 24-hour early warning will be the most demanding requirement. If your monitoring doesn’t extend into OT, you may not detect an incident quickly enough to meet the reporting deadline. Comprehensive visibility across both IT and OT environments is both good security practice and fundamental to timely compliance.
Penalties
What Non-Compliance Can Cost
According to the European Commission NIS2 FAQ and Directive (EU) 2022/2555, Article 34:
- Essential entities face fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher
- Important entities face fines of up to €7 million or 1.4% of total worldwide annual turnover, whichever is higher
NIS2 also introduces personal liability for senior management. Cyber security governance therefore becomes a board-level responsibility, rather than solely an operational concern. That changes the conversation at board level considerably.
The penalties are significant, but the organisations most likely to avoid them are those that treat NIS2 as an opportunity to strengthen their security posture rather than simply meet a regulatory requirement.
Building a Compliant IT/OT Security Architecture
Network segmentation is the architectural foundation. OT environments should be isolated from corporate IT, with controlled and auditable data flows at the boundary. That isolation should be supported by technical controls and monitoring, not just documented in policy.
Data diodes and cross-domain solutions (CDS) provide the technical means for that boundary. A data diode allows OT telemetry to reach IT analytics without creating a return path. A CDS with content inspection, like TrustedFilter, adds policy-enforced filtering so that authorised and validated data can cross the boundary in either direction.
Together, these approaches support NIS2’s requirements for network segmentation while enabling the operational data flows needed for modern energy management.
Continuous monitoring across both environments supports Article 21 risk management and gives you the detection capability you need to meet the 24-hour reporting window. Limiting monitoring to corporate IT can leave significant blind spots in OT environments, making timely detection and response more difficult.
A Practical NIS2 Compliance Checklist for Energy Operators
Achieving NIS2 compliance is an ongoing process rather than a one-off project. The checklist below highlights the areas worth prioritising first:
- Confirm your scope. Establish whether your organisation meets the essential entity threshold and which national NIS2 requirements apply to your operations. UK operators should review their position under the UK NIS Regulations and monitor the Cyber Security and Resilience Bill as it progresses through Parliament.
- Map your IT/OT boundaries. Identify every point where corporate IT and OT networks connect or share data. Assess whether those connections are controlled, logged, and auditable.
- Review your current security controls. Prioritise gaps in network segmentation, access controls, MFA, supply chain security, and incident detection. Essential entities should also ensure they can demonstrate how those gaps are being addressed.
- Build your incident reporting workflow. Assign ownership for the 24-hour early warning. Test your detection-to-notification timeline. Make sure OT visibility is included in your monitoring scope.
- Brief your board. NIS2 introduces management liability. Your board needs to understand their obligations and the investment required to meet them.
If you want a structured gap analysis of your IT/OT controls against Article 21 obligations, 4Secure’s NIS2 Readiness Assessment is tailored to energy sector operations, with a clear view of where your architecture stands and what needs to change.
Speak to the team to get started, or explore our IT/OT secure connection capability to see how controlled data exchange supports compliance in practice.
Frequently Asked Questions
Does NIS2 apply in the UK?
No. NIS2 is an EU directive and doesn’t apply directly in the UK post-Brexit. UK energy operators are governed by the UK NIS Regulations 2018, with NCSC and Ofgem as relevant authorities. The Cyber Security and Resilience Bill, currently progressing through Parliament, is expected to update the UK regime when enacted. UK operators with EU operations must comply with NIS2 for those activities.
What are the fines for NIS2 non-compliance?
Essential entities face fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face fines of up to €7 million or 1.4% of total worldwide annual turnover, whichever is higher. Senior management can also face personal liability. Source: European Commission NIS2 FAQ.
How do I know if my energy company needs to comply with NIS2?
If your organisation operates in the EU energy sector with 50 or more employees or turnover exceeding €10 million, you are likely in scope. Essential entities (250+ employees or €50m+ turnover) face the highest obligations. Smaller operations may still be designated as critical by national authorities. If you’re unsure, check your designation with your national competent authority, particularly if your organisation operates critical infrastructure or provides services that may be nationally designated.
Does NIS2 require specific cybersecurity technologies?
No. NIS2 doesn’t mandate specific products or technologies. Instead, it requires organisations to implement appropriate technical and organisational measures based on their risk profile. Technologies such as network segmentation, data diodes, secure gateways, and continuous monitoring can all help organisations meet those requirements where appropriate.
What is the biggest NIS2 challenge for energy operators?
For many organisations, the challenge isn’t understanding the legislation—it’s applying modern cybersecurity controls to legacy OT and SCADA environments without disrupting operations. Network segmentation, controlled data exchange, and improved visibility across IT and OT environments are often key parts of that process.