EU NIS2 Directive — Transport Sector Requirements
The NIS2 Directive (Directive (EU) 2022/2555) designates the transport sector as an essential entity category, requiring enhanced cybersecurity measures. This includes air transport (carriers, airports, air traffic management systems), rail transport (operators, infrastructure managers), water transport (shipping companies, ports, vessel traffic services), and road transport (operators of road infrastructure and intelligent transport systems).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Assurance
| Code | Title |
|---|---|
| NIS2-TRN-009 | Effectiveness assessment of cybersecurity measures |
Collaboration
| Code | Title |
|---|---|
| NIS2-TRN-022 | Information sharing and ISAC participation |
Conformity
| Code | Title |
|---|---|
| NIS2-TRN-018 | Use of European cybersecurity certification schemes |
Cryptography
| Code | Title |
|---|---|
| NIS2-TRN-011 | Cryptography and encryption policy |
Enforcement
| Code | Title |
|---|---|
| NIS2-TRN-019 | Supervisory and enforcement powers |
General Provisions and Scope
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 6 | Writing |
Governance
| Code | Title |
|---|---|
| NIS2-TRN-016 | Management body responsibilities and training |
| NIS2-TRN-020 | Interaction with sectoral lex specialis |
Identity
| Code | Title |
|---|---|
| NIS2-TRN-012 | Human resources security and access control |
| NIS2-TRN-013 | Multi factor authentication and secure communications |
Incident Reporting Obligations
| Code | Title |
|---|---|
| Art. 23 | Transitional Provisions |
| Art. 23(4)(a) | Early warning |
| Art. 23(4)(b) | Incident notification |
| Art. 23(4)(d) | Final report |
Incidents
| Code | Title |
|---|---|
| NIS2-TRN-004 | Incident handling for transport operations |
National Cybersecurity Frameworks
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 7 | Minimum Standards |
| Art. 8 | Compliance with the Requirements |
| Art. 9 | Risk Management System |
People
| Code | Title |
|---|---|
| NIS2-TRN-010 | Cyber hygiene practices and training |
Procurement
| Code | Title |
|---|---|
| NIS2-TRN-007 | Security in network and information systems acquisition |
Registration
| Code | Title |
|---|---|
| NIS2-TRN-002 | Registration with national competent authority |
Reporting
| Code | Title |
|---|---|
| NIS2-TRN-014 | Significant incident notification |
| NIS2-TRN-015 | Cross border incident coordination |
Resilience
| Code | Title |
|---|---|
| NIS2-TRN-005 | Business continuity and crisis management |
| NIS2-TRN-021 | Critical entity resilience alignment |
Risk
| Code | Title |
|---|---|
| NIS2-TRN-003 | Risk management measures |
Scope
| Code | Title |
|---|---|
| NIS2-TRN-001 | Sectoral scope for transport entities |
Supervision and Enforcement
Supervisory bodies, liability, and penalty frameworks
| Code | Title |
|---|---|
| Art. 32 | Entry into Force |
| Art. 34 | Notification of Personal Information Breach |
| Art. 36 | Right to Correction or Deletion |
| Art. 69-71 | Supervisory Powers |
| Art. 70 | Criminal Penalties for False Consent |
| Art. 73 | Reporting of Serious Incidents |
| Art.45 | Entry into force |
| Art.50 | Good Practices and Governance |
| Art.51 | Exercise of the power to impose administrative penalties and remedial measures |
| Art.52 | Administrative Sanctions |
| Sec. 35 | Security of Processing |
| Sec. 37 | Financial Penalties |
| Sec. 40 | Right to Object |
| Sec. 72 | Offences and penalties |
Third party
| Code | Title |
|---|---|
| NIS2-TRN-006 | Supply chain cybersecurity |
Transport Sector Coverage (Annex I)
| Code | Title |
|---|---|
| Annex I, Sec. 5(a) | Air transport |
| Annex I, Sec. 5(b) | Rail transport |
| Annex I, Sec. 5(c) | Water transport |
| Annex I, Sec. 5(d) | Road transport |
Transport Sector Risk Management
| Code | Title |
|---|---|
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 21 | Cooperation with Competent Authorities |
| Art. 21(2)(a) | Risk analysis and information system security policies |
| Art. 21(2)(b) | Incident handling |
| Art. 21(2)(c) | Business continuity and crisis management |
| Art. 21(2)(d) | Supply chain security |
Vulnerability
| Code | Title |
|---|---|
| NIS2-TRN-008 | Vulnerability handling and disclosure |
| NIS2-TRN-017 | Coordinated vulnerability disclosure for OT |
Your Compliance Coverage
If you comply with EU NIS2 Directive — Transport Sector Requirements, you already cover:
EU AI Act
21%
12 controls mapped
Compare →BS 65000:2014 — Guidance on Organizational Resilience
21%
12 controls mapped
Compare →Digital Services Act (DSA) - Regulation (EU) 2022/2065
19%
11 controls mapped
Compare →+ 647 more: EU In Vitro Diagnostic Medical Devices Regulation (IVDR) (19%), EU Network Code on Cybersecurity for the Electricity Sector (19%)
See all 650 mapped frameworks ↓Maps to 650 other frameworks
Frequently Asked Questions
What is EU NIS2 Directive — Transport Sector Requirements?
EU NIS2 Directive — Transport Sector Requirements is a compliance framework from European Union with 23 domains and 58 controls. The NIS2 Directive (Directive (EU) 2022/2555) designates the transport sector as an essential entity category, requiring enhanced cybersecurity measures. This includes air transport (carriers, airports, air traffic management systems), rail transport (operators, infrastructure managers), water transport (shipping companies, ports, vessel traffic services), and road transport (operators of road infrastructure and intelligent transport systems). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does EU NIS2 Directive — Transport Sector Requirements have?
EU NIS2 Directive — Transport Sector Requirements has 58 controls organised across 23 domains. The largest domains are Supervision and Enforcement (14 controls), Transport Sector Risk Management (6 controls), General Provisions and Scope (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does EU NIS2 Directive — Transport Sector Requirements map to?
EU NIS2 Directive — Transport Sector Requirements maps to 650 other compliance frameworks. The top mapping partners are EU AI Act (21% coverage), BS 65000:2014 — Guidance on Organizational Resilience (21% coverage), Digital Services Act (DSA) - Regulation (EU) 2022/2065 (19% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with EU NIS2 Directive — Transport Sector Requirements compliance?
Start your EU NIS2 Directive — Transport Sector Requirements compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EU NIS2 Directive — Transport Sector Requirements requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 58 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required