NIS2 Directive · transport and logistics

NIS2 in transport and logistics.
Documentation is only the beginning.


Transport is one of the sectors covered by NIS2, but the scope of obligations depends on the type of activity and the size of the entity. For carriers, infrastructure managers, ports, airports and some transport service companies, this means putting risk, business continuity, incidents and suppliers in order.
The KSC/NIS2 deadlines are already running: registration, implementing risk management measures and preparing for the audit require action, not just documentation.
BCMLogic Next helps you maintain NIS2 requirements in a single GRC system – from risk assessment and BIA to incidents, continuity plans, suppliers and audit evidence.

What is changing
NIS2 in transport: three changes that matter operationally
NIS2 covers a wider group of transport companies and changes how cybersecurity is managed: self-assessment, management accountability and IT, OT and supplier risk become part of a single process.

Change 1
You classify yourself – and you register yourself
The company assesses its own status and – if it falls within scope – completes the registration obligation and appoints a cybersecurity contact person.
⚠ Registration within 6 months

Change 2
Management is accountable, not the IT department
Management approves risk management measures, oversees their implementation and is accountable for meeting the obligations. NIS2 is therefore not just a task for the IT department.
✓ Personal liability

Change 3
The scope is the whole organisation: IT, OT and suppliers
Risk is not limited to IT. In transport you need to consider ticketing and booking systems, traffic control and management, infrastructure, automation systems (OT) and technology service providers.
✓ IT + OT + supply chain
Scale of liability

Fines are only one dimension of NIS2 risk.

EUR 10 million
or 2% of annual turnover, whichever is higher. Maximum fine for an essential entity.
300%
of remuneration – personal fine for the head of the entity.
24 h / 72 h
early warning and full notification of a significant incident. Final report – within one month.

A fine does not require an incident. Penalties may also result from failing to meet obligations relating to registration, risk management, reporting or audit. Details in the FAQ.

Map of obligations
Five areas you need to put in order and maintain
In practice, it is not enough to have procedures – you need to be able to show that risks, actions, reviews, tests and responsibilities are up to date.
1
Classification and registration
Assessing the entity’s status, registering and keeping contact details up to date.
2
Risk management and security measures
IT and OT risk assessment, security measures, business continuity and regular reviews.
3
Supply chain
Assessment of ICT and OT suppliers and control of security requirements and third-party access.
4
Incident handling
Incident classification, meeting the 24 h / 72 h deadlines and documenting follow-up actions.
5
Management oversight, training and audit
Management oversight, training, security audit and corrective actions.

Timeline
Deadlines counted from the Act’s entry into force
3 Apr 2026
The KSC Act implementing NIS2 enters into force. All further deadlines are counted from this date.
3 Oct 2026
+6 months
Registration in the KSC register (S46 system) and appointment of a cybersecurity contact person. The nearest deadline for most transport entities.
3 Apr 2027
+12 months
Full implementation of the information security management system and statutory measures – including documentation and approval by the management board.
3 Apr 2028
+24 months
First security audit for essential entities – then at regular intervals. From this point on, fines become a real prospect.
ongoing
Incident reporting within 24 h / 72 h, risk reviews, plan testing, supplier assessments, board and staff training.

Legal basis: Directive (EU) 2022/2555 (NIS2) and the Polish Act of 5 July 2018 on the National Cybersecurity System (KSC), as amended. “Transport” sector – Annex I (sectors of high criticality): air, rail, water and road transport. Postal and courier services fall under Annex II (other critical sectors). Specific classification depends on the type of activity and the rules in Article 5 of the KSC Act.
Sector specifics
Transport and logistics: one incident can stop the entire process
In transport, the problem is not just data loss. An outage can halt ticket sales, check-in, cargo handling, route planning or access to traffic control systems. That is why risk management must be linked to business continuity and supplier dependencies.
Rail transport
Infrastructure managers and railway undertakings
Rail traffic control, communications, ticketing and timetable planning. A failure of signalling or communication systems can halt traffic on an entire line.
Air transport
Air carriers, airports and traffic management
Check-in, baggage handling, booking systems and air traffic management. System unavailability means delays, cancelled flights and a domino effect across the whole route network.
Water transport
Shipping companies, ports and VTS
Cargo handling, terminal systems and vessel traffic services (VTS). A port is a supply chain hub – downtime quickly spreads to land logistics.
Road transport
Road authorities and ITS operators
Road authorities responsible for traffic management control and operators of intelligent transport systems: traffic signal control, variable message signs and traffic monitoring.
Logistics and freight forwarding
Logistics operators and warehouses
Logistics is not a separate NIS2 subsector. Obligations may arise from another classification of your activity or from requirements of clients who are essential entities – WMS, TMS and telematics then become part of their supply chain.
Postal and courier services
Postal operators and courier companies
An Annex II sector. Sorting centres, parcel tracking systems, fleets and e-commerce integrations – downtime quickly turns into delivery backlogs.
What this means in practice: risk assessments and continuity plans must cover both IT and OT/SCADA, as well as dependencies on suppliers and maintenance providers. More details in the FAQ.
BCMLogic Next in transport and logistics
A GRC system for transport and logistics that brings order to risk and business continuity
BCMLogic Next connects risks, BIA, continuity plans, incidents, suppliers, actions and deadlines. Instead of keeping this information in separate spreadsheets and documents, your team works on one up-to-date dependency model.

🔄
Already have documentation? We move it into the system. Starting from scratch? Wizards guide you through.
We can migrate your existing documentation into the system or start with wizards that guide users step by step.
⚠️
IT and OT risk assessment
Risk assessment for processes, systems and infrastructure, risk owners, actions and change history.
Step-by-step wizard
📋
Policies and procedures
Templates, approval workflows, version history and audit trail.
Ready-made templates
🔄
Business continuity plans
BIA, BCP and DRP for critical processes, test schedules, failure scenarios and exercise history.
OT/SCADA scenarios
🚨
Incident management
Incident handling with 24 h / 72 h deadlines, classification and a clear course of action.
24 h / 72 h timer
🏭
Suppliers and supply chain
Register and risk assessment of technology, maintenance and transport support service suppliers, plus requirements monitoring.
OT supplier register
✅
Audit readiness
Compliance status, approval and review history, and reports that support audit preparation.
Report for the auditor
Note for the largest entities – the CER Directive:
Some transport operators may also be subject to critical entity resilience requirements. The scope should be verified separately; details are in the FAQ.
Online demo
Want to see how it works in practice?
Explore BCMLogic Next with demo data or book a 30-minute meeting and walk through scenarios relevant to transport and logistics with us.
🖥

Online demo environment
Ready-made demo data: risks, incidents, business continuity and NIS2 compliance.
📞

A short meeting with our team
30 minutes for a system walkthrough and questions about your organisation and where you are in your NIS2 preparations.

Request demo access or book a 30-minute meeting →

FAQ · NIS2 and GRC in transport and logistics

Frequently asked questions about NIS2 in transport and logistics

Details that help you assess the scope of obligations and how to work with BCMLogic Next.
Who does NIS2 cover in the transport sector?
The scope includes air transport (air carriers, airports, air traffic management), rail (infrastructure managers and railway undertakings), water (shipping companies, port managing bodies, VTS) and road (road authorities responsible for traffic management control, ITS operators). Postal and courier services are a separate sector. Final classification depends on the type of activity, the size of the organisation and the rules in Article 5 of the KSC Act.
Can a risk assessment in transport be limited to IT?
No. In transport and logistics, the risk assessment should also cover OT/SCADA environments, process dependencies, technology and maintenance suppliers, and the continuity of infrastructure operations.
Does a NIS2 fine require an incident to occur?
No. Penalties may also result from failing to meet other obligations, such as registration, risk management, incident reporting or the required audit.
We already have a risk assessment and documentation. Do we need to start over?
No. Existing materials can be migrated to the platform by your team, BCMLogic or a partner. The goal is not to recreate documentation, but to keep risks, plans, actions and evidence in a single GRC system.
Does BCMLogic Next replace a NIS2 consultant or integrator?
It does not have to. BCMLogic Next can act as the platform that maintains the results of a project delivered by an external consultant or integrator. It lets you keep working with risks, documentation, suppliers, incidents and tasks after the implementation ends.
How does BCMLogic Next support audit preparation?
The platform keeps a history of changes, approvals, reviews, tests and actions. As a result, the information needed for an audit does not have to be gathered from multiple spreadsheets, documents and systems every time.
What about critical entity resilience (CER)?
Some transport companies may also be subject to critical entity resilience rules. Their status needs to be verified separately. BCMLogic Next can be used to manage requirements and evidence for multiple regulations in one environment.
How do you connect NIS2 with business continuity in transport?
First, identify the processes whose interruption causes a real operational problem, then link them to systems, locations, resources and suppliers. BCMLogic Next connects BIA, risks and continuity plans, so a change in one area does not stay stuck in a separate spreadsheet.
How should supplier risk be managed in logistics?
Start with suppliers whose unavailability could stop a critical process: IT systems, telematics, maintenance, infrastructure, communications or operational services. A GRC system lets you maintain risk assessments, requirements, actions and review dates together with process dependencies.

Next step
See how a GRC system for transport and logistics works
Explore the platform online or book a short demo tailored to the processes, risks and requirements of a transport or logistics organisation.