NIS2 Directive · energy sector

NIS2 in the energy sector.
Documentation is only the beginning.


Energy is one of the key sectors covered by NIS2. For many companies this means self-assessment, registration and ongoing cybersecurity risk management – across IT, OT and the supply chain.
The KSC/NIS2 deadlines are already running: registration, implementing risk management measures and preparing for the audit require action, not just documentation.
BCMLogic Next helps you maintain NIS2 compliance in a single GRC system – long after the implementation project ends.

What is changing
NIS2 in energy: three changes that matter operationally
NIS2 covers a wider group of energy companies and changes how cybersecurity is managed: self-assessment, management accountability and IT, OT and supplier risk become part of a single process.

Change 1
You classify yourself – and you register yourself
The company assesses its own status and – if it falls within scope – completes the registration obligation and appoints a cybersecurity contact person.
⚠ Registration within 6 months

Change 2
Management is accountable, not the IT department
Management approves risk management measures, oversees their implementation and is accountable for meeting the obligations. NIS2 is therefore not just a task for the IT department.
✓ Personal liability

Change 3
The scope is the whole organisation: IT, OT and suppliers
Risk management covers not only IT, but also OT/SCADA and the suppliers and services on which the continuity of energy processes depends.
✓ IT + OT + supply chain
Scale of liability

Fines are only one dimension of NIS2 risk.

EUR 10 million
or 2% of annual turnover, whichever is higher. Maximum fine for an essential entity.
300%
of remuneration – personal fine for the head of the entity.
24 h / 72 h
early warning and full notification of a significant incident. Final report – within one month.

A fine does not require an incident. Penalties may also result from failing to meet obligations relating to registration, risk management, reporting or audit. Details in the FAQ.

Map of obligations
Five areas you need to put in order and maintain
In practice, it is not enough to have procedures – you need to be able to show that risks, actions, reviews, tests and responsibilities are up to date.
1
Classification and registration
Assessing the entity’s status, registering and keeping contact details up to date.
2
Risk management and security measures
IT and OT risk assessment, security measures, business continuity and regular reviews.
3
Supply chain
Assessment of ICT and OT suppliers and control of security requirements and third-party access.
4
Incident handling
Incident classification, meeting the 24 h / 72 h deadlines and documenting follow-up actions.
5
Management oversight, training and audit
Management oversight, training, security audit and corrective actions.

Timeline
Deadlines counted from the Act’s entry into force
3 Apr 2026
The KSC Act implementing NIS2 enters into force. All further deadlines are counted from this date.
3 Oct 2026
+6 months
Registration in the KSC register (S46 system) and appointment of a cybersecurity contact person. The nearest deadline for most energy companies.
3 Apr 2027
+12 months
Full implementation of the information security management system and statutory measures – including documentation and approval by the management board.
3 Apr 2028
+24 months
First security audit for essential entities – then at regular intervals. From this point on, fines become a real prospect.
ongoing
Incident reporting within 24 h / 72 h, risk reviews, plan testing, supplier assessments, board and staff training.

Legal basis: Directive (EU) 2022/2555 (NIS2) and the Polish Act of 5 July 2018 on the National Cybersecurity System (KSC), as amended. “Energy” sector – Annex I to the Directive (sectors of high criticality): electricity, district heating and cooling, oil, gas, hydrogen.
Sector specifics
Energy is not an ordinary IT environment
In energy, cybersecurity is not only about data, but also about service continuity and infrastructure control. That is why a GRC system for the energy sector must reflect the specifics of OT/SCADA, suppliers and long infrastructure lifecycles.
Electricity
Generation, transmission, distribution, trading
Also nominated electricity market operators, aggregators, demand response and energy storage – together with telecontrol, protection and metering systems.
Heating and cooling
District heating and cooling systems
Heat generation and distribution. Seasonality raises the stakes for continuity plans – the window to restore service at the winter peak is short.
Gas
Transmission, distribution, storage, LNG
System operators, LNG facilities, supply undertakings and natural gas refining and treatment facilities.
Oil
Pipelines, production, storage
Operators of oil transmission pipelines, production, refining, treatment and storage facilities, as well as central stockholding entities.
Hydrogen
Production, storage, transmission
A new subsector in NIS2 – covering facilities that are only now being built in national hydrogen projects and are designing their security architecture from scratch.
Recharging points
Recharging infrastructure operators
Distributed, remotely managed infrastructure that depends heavily on platform and integration providers – hence the focus on supply chain oversight.
What this means in practice: risk assessments and continuity plans must cover both IT and OT/SCADA, as well as dependencies on suppliers and maintenance providers. More details in the FAQ.
BCMLogic Next in energy
A GRC system for energy that keeps you NIS2-compliant every day
BCMLogic Next brings risks, policies, plans, incidents, suppliers and deadlines together in one environment. We can work alongside your consultant or integrator – the system keeps the results of your NIS2 project alive in day-to-day work.

🔄
Already have documentation? We move it into the system. Starting from scratch? Wizards guide you through.
We can migrate your existing documentation into the system or start with wizards that guide users step by step.
⚠️
IT and OT risk assessment
Risk assessment for IT and OT, risk owners, actions and a full change history.
Step-by-step wizard
📋
Policies and procedures
Templates, approval workflows, version history and audit trail.
Ready-made templates
🔄
Business continuity plans
BCP and DRP, scenarios for critical environments, test schedules and exercise history.
OT/SCADA scenarios
🚨
Incident management
Incident handling with 24 h / 72 h deadlines, classification and a clear course of action.
24 h / 72 h timer
🏭
Suppliers and supply chain
Register and risk assessment of ICT/OT suppliers and monitoring of security requirements.
OT supplier register
✅
Audit readiness
Compliance status, approval and review history, and reports that support audit preparation.
Report for the auditor
Note for the largest entities – the CER Directive:
Some energy companies may also be subject to critical entity resilience requirements. Details are in the FAQ below.
Online demo
Want to see how it works in practice?
Explore BCMLogic Next with demo data or book a 30-minute meeting and walk through scenarios relevant to the energy sector with us.
🖥

Online demo environment
Ready-made demo data: risks, incidents, business continuity and NIS2 compliance.
📞

A short meeting with our team
30 minutes for a system walkthrough and questions about your organisation and where you are in your NIS2 preparations.

Request demo access or book a 30-minute meeting →

FAQ · NIS2 and GRC in energy

Frequently asked questions about NIS2 in the energy sector

Useful details on implementing a GRC tool in the energy sector.
Who does NIS2 cover in the energy sector?
The scope includes selected entities in electricity, district heating and cooling, gas, oil and hydrogen. Final classification depends on the type of activity, the size of the organisation and national law.
Does NIS2 apply only to IT systems?
No. In energy, the risk assessment should also cover OT/SCADA environments, process dependencies, technology and maintenance suppliers, and the continuity of infrastructure operations.
Does a NIS2 fine require an incident to occur?
No. Penalties may also result from failing to meet other obligations, such as registration, risk management, incident reporting or the required audit.
We already have NIS2 documentation. Can we use it in BCMLogic Next?
Yes. Existing materials can be migrated to the platform by your team, BCMLogic or a partner. The goal is not to recreate documentation, but to keep risks, plans, actions and evidence in a single GRC system.
Does BCMLogic Next replace a NIS2 consultant or integrator?
It does not have to. BCMLogic Next can act as the platform that maintains the results of a project delivered by an external consultant or integrator. It lets you keep working with risks, documentation, suppliers, incidents and tasks after the implementation ends.
How does BCMLogic Next support audit preparation?
The platform keeps a history of changes, approvals, reviews, tests and actions. As a result, the information needed for an audit does not have to be gathered from multiple spreadsheets, documents and systems every time.
What about the CER Directive?
Some energy companies may also be subject to critical entity resilience rules. Their status needs to be verified separately. BCMLogic Next can be used to manage requirements and evidence for multiple regulations in one environment.

Next step
See how a GRC system for energy works
Explore the platform online or book a short demo tailored to the needs of an energy sector organisation.