NIS2 in the energy sector is not just another compliance document: it is the framework that redefines what an acceptable cybersecurity posture looks like for an electricity, gas, hydrogen or oil operator in Europe.
Directive (EU) 2022/2555 expands the universe of obligated entities, raises minimum requirements and makes the responsibility of the governing body explicit. For the energy sector, where the impact of an incident can cross borders and affect the supply of millions of homes and industries, these requirements are not rhetoric: they are operational commitments.
This guide translates the key NIS2 requirements into the language of compliance teams, CISOs, operations directors and legal officers at energy entities. The goal is that by the end you have a clear picture of what is expected, what needs to be documented and where the risk of inaction lies.
Transposition Status in Spain: What You Need to Know Today
Important legal note (last reviewed 11 August 2026): Spain has not yet notified complete transposition of NIS2. On 8 July 2026, the European Commission referred Spain to the Court of Justice of the European Union over the delay. The national implementation details therefore remain subject to change. Energy operators should continue preparing proportionate controls and evidence, because the underlying operational, contractual and continuity risks do not wait for the final law.
Until the Spanish transposition law is enacted, organisations should distinguish obligations under the current Spanish cybersecurity framework from the future NIS2 implementation. The draft legislation proposes roles for INCIBE-CERT, CCN-CERT and a National Cybersecurity Centre, but those arrangements should not be described as final law. Incident procedures should identify the reporting channel that currently applies to the entity and be ready to adapt when the final national framework is published.
Who Does NIS2 Apply To in the Energy Sector?
The directive distinguishes two categories: essential entities and important entities. Energy is a sector of high criticality in Annex I of the Directive, but Annex I inclusion alone does not make every energy operator an essential entity. Classification depends on the entity type, size-cap rules, any specific designation and the applicable national transposition.
As a general rule, medium-sized and larger entities in the listed energy categories are within scope. Large Annex I entities are generally classified as essential, while medium-sized Annex I entities are generally important. Certain entities may still be brought into scope regardless of size because of their criticality or a specific designation. The assessment must therefore consider the exact legal entity, activity, employee and financial thresholds, group relationships and national rules.
Covered infrastructures include:
- Electricity undertakings, producers, distribution and transmission system operators
- Nominated electricity market operators and relevant aggregation, demand-response, storage and recharging-point operators
- District heating and cooling operators
- Natural gas supply, distribution, transmission, storage, LNG and relevant treatment operators
- Oil pipelines, production, refining, treatment, storage and transmission operators, including central stockholding entities
- Hydrogen production, storage and transmission operators
If you operate in more than one Member State, determine the competent authority and registration or notification requirements in each relevant jurisdiction. ACER supports EU energy-sector cooperation and cross-border arrangements, but it is not the general NIS2 supervisory authority for every energy operator.
The Core Obligation: Proportionate and Documented Risk Management
Article 21 of Directive (EU) 2022/2555 sets out the cybersecurity risk management measures that every obligated entity must adopt. It is not an exhaustive checklist: it is a proportionality framework that takes into account the state of the art, costs, size and risk exposure of the entity.
Mandatory minimum measures include:
Information security policies and risk management. A documented framework must exist covering periodic risk analysis, domain owners and a formal review cycle. In energy, that framework must cover both corporate IT and OT/remote control environments, not treat them as separate silos.
Incident management. Clear procedures for detection, classification, containment, recovery and communication. This includes defining internally what a “significant incident” is before one occurs, not in the heat of the crisis.
Business continuity and crisis management. Backup plans, critical systems recovery, continuity procedures during the incident and formalised lessons learned. For network operators, this intersects with pre-existing sector obligations for supply continuity.
Supply chain security. Assessing and managing risks introduced by vendors, integrators and digital service providers with access to critical systems. A standard contract is not enough: active review of access and conditions must be evidenced.
Security in the acquisition, development and maintenance of systems. Security criteria in procurement contracts, integration projects and changes to production environments.
Policies and procedures to assess the effectiveness of measures. Compliance must be measurable. Without metrics or review evidence, the framework is not sustainable under audits or in the event of a real incident.
Basic cybersecurity hygiene and training. Operators must ensure their staff, including management, receives adequate training. NIS2 requires the management body to approve the measures and understand their implications.
Cryptography policies. Particularly relevant for communications between control systems, market exchanges and telemetry transmission.
Human resources security, access control and asset management. Up-to-date inventories, identity management, privilege control and joiner/leaver processes.
Use of multi-factor authentication (MFA) or continuous authentication. NIS2 requires these measures where appropriate and proportionate to risk. For privileged access, external support, bastion hosts and remote management of sensitive systems, MFA should normally be treated as a priority control, with any technical exception documented and supported by compensating measures.
Energy NIS2 Controls and Evidence at a Glance
| Requirement | Energy-sector action | Evidence to retain |
|---|---|---|
| Risk management | Map critical services and assess connected IT and OT risks | Service inventory, asset register, risk assessment and assigned owners |
| Access security | Control privileged, remote and vendor access to OT and supporting systems | Access approvals, MFA records, session logs and exception decisions |
| Incident handling | Define significant-incident classification, escalation and reporting | Response plan, decision log, notification templates and exercise results |
| Continuity | Test recovery of critical control, operational and communications services | Recovery procedures, backup tests, exercise reports and corrective actions |
| Supply chain | Classify critical vendors and review remote access, support and update arrangements | Supplier assessments, security clauses, review records and remediation plans |
| Governance | Give management usable risk information and record approval and oversight | Board papers, approvals, training records, metrics and review minutes |
Management Body Responsibility: A Real Paradigm Shift
One of the most disruptive elements of NIS2 is the explicit management liability. Article 20 of Directive (EU) 2022/2555 requires that the management bodies of obligated entities:
- Approve cybersecurity risk management measures.
- Oversee their implementation.
- Receive periodic cybersecurity training.
- Be held accountable for infringements by the entity in accordance with the applicable national implementation and enforcement conditions.
The Spanish draft legislation has included proposed personal consequences for directors, including financial penalties and possible temporary disqualification. These remain draft provisions, not final penalties currently in force under a completed Spanish NIS2 transposition. The practical governance point remains: management cannot treat cybersecurity as a responsibility delegated entirely to the CISO without effective approval and oversight.
For the energy sector, where cybersecurity has historically lived in technical departments with limited executive visibility, this change requires renewed reporting structures and risk language that management can understand, not just the technical team.
Incident Management and Notification: Deadlines That Cannot Be Improvised
NIS2 establishes a three-phase incident notification regime for incidents that meet the significant-incident criteria. Deadlines run from the moment the entity becomes aware of the significant incident, not from when it has been fully analysed. The final reporting channel and any additional sector-specific procedure depend on the applicable national framework:
| Phase | Deadline | Minimum content |
|---|---|---|
| Early warning | 24 hours | Whether malicious origin is suspected and whether cross-border impact is possible |
| Incident notification | 72 hours | Initial impact assessment, available indicators of compromise, mitigation measures adopted |
| Final report | 1 month | Detailed description, root cause analysis, actual impact and lessons learned |
Source: INCIBE-CERT. NIS2: What You Need to Know
What cannot be improvised: internal incident classification, the decision chain from NOC or SOC to management, and external communication procedures with regulators. Having these flows in place before an incident is what distinguishes an orderly response from a communications crisis layered on top of a technical one.
Digital Supply Chain: The Risk Vector the Directive Places at the Centre
Article 21 explicitly requires managing the security of vendors and service providers. In the energy sector, this has immediate implications for:
OT and SCADA integrators. Remote maintenance access, firmware update windows and OEM support credentials are documented risk vectors. The directive requires the entity not only to trust the contract, but to evidence active review of those access conditions.
Cloud and SaaS vendors. If asset management systems, CMMS platforms, telemetry analytics tools or corporate ERPs are in the cloud, the entity must have security clauses, audit rights and documented exit plans.
Critical hardware and firmware components. Dependency on manufacturers with embedded software updates or licence keys is a continuity risk that NIS2 does not resolve technically, but does require managing and documenting.
Subcontractors with access to essential systems. Any third party with access, even occasional, to systems that affect service continuity must be covered by the vendor assessment process.
The assessment does not need to be exhaustive from day one, but it must be systematic and documented: vendor classification by criticality, periodic review criteria and records of decisions taken in response to identified risks.
Technical Measures: What NIS2 Expects in Energy OT/IT Environments
The directive does not prescribe specific architectures, but the “state of the art” referenced in Article 21 translates into practical expectations for the sector:
- Network segmentation between corporate IT and OT/SCADA environments, with a documented policy of authorised flows and periodic firewall rule reviews.
- Centralised identity and privileged access management (PAM) for critical systems, including external vendor accounts with automatic expiry and session recording.
- Monitoring and detection across IT environments and, progressively, OT environments, with cross-domain correlation capability.
- Vulnerability management with a documented process for environments where immediate patching is not possible due to certification or continuity requirements.
- Verified, isolated backups with tested recovery procedures for critical control systems and operational data.
- Encryption in transit for sensitive communications between control systems, remote access and third-party data transfers.
For many operators, the gap is not ignorance of these measures, but the absence of formal documentation, assigned owners and evidence of periodic review. That is precisely what distinguishes an auditable posture from a real but indefensible one before supervisors.
5 Energy-Sector Scenarios a NIS2 Plan Must Cover
Energy environments combine long-lived operational technology, outsourced maintenance, real-time availability requirements and dependencies that cross organisational and national borders. A useful NIS2 programme therefore tests credible operating scenarios instead of applying an office-IT checklist to substations, terminals, control rooms or generation assets. ENISA’s energy-sector work highlights the importance of smart-grid, industrial-control, time-service and cross-border dependencies.
- Legacy OT cannot be patched on the IT timetable. Some industrial assets have limited vendor support, strict availability requirements or certification constraints. The risk decision should document compensating controls such as segmentation, allow-listing, monitored jump hosts, restricted engineering access and a tested replacement plan. “The system cannot be patched” is the start of the assessment, not the conclusion.
- A remote vendor account is misused. Maintenance access can bypass normal network boundaries and may remain enabled between interventions. The exercise should test approval, strong authentication, session recording, time-limited access, emergency revocation, subcontractor visibility and whether the supplier can notify the operator quickly enough to support its own incident-reporting duties.
- A shared time, communications or data service becomes unreliable. Grid and market operations can depend on accurate time signals, telemetry, forecasts and external communications. Teams should identify where loss or manipulation of these services affects safe operation, define alternative sources and test how inconsistent data is detected before it drives an operational decision.
- An incident crosses entities or borders. A disturbance can involve a parent company, network operator, market participant, managed-service provider and authorities in several jurisdictions. The playbook should show who leads, which entity assesses notification, what can be shared, how operational confidentiality is protected and how updates remain consistent across NIS2, sector and contractual channels.
- Backups exist but the service cannot be restored safely. Recovery evidence should go beyond a successful file restore. Tests must consider configuration, clean-room procedures, OT safety, dependencies, manual operation, vendor availability, recovery priorities and the conditions for reconnecting systems. Findings should create owned corrective actions and feed back into the risk register.
Certifications as a Compliance Lever
NIS2 does not mandate certification, but existing certifications can provide structured supporting evidence. Commission Implementing Regulation (EU) 2024/2690 establishes binding technical and methodological requirements for specified digital-infrastructure, digital-provider and ICT-service entities. It does not directly apply to traditional energy operators. Energy entities may use it as an optional source of implementation detail, but should not present it as a binding energy-sector standard or a confirmed statement of supervisory expectations.
ISO/IEC 27001 provides the baseline ISMS: risk policy, documented controls and a continual improvement cycle. For energy entities that must demonstrate proportionate and auditable risk management, it is the most internationally recognised standard.
ENS (National Security Framework) applies when the entity has a contractual relationship with public administrations or provides services involving public sector information processing. In the energy sector, many distribution operators and infrastructure operators have this relationship.
IEC 62443 is the sector reference framework developed by the International Electrotechnical Commission for cybersecurity in industrial automation and control systems (IACS). Its various parts, 62443-2-1 for asset owners, 62443-3-3 for system requirements, 62443-4-1 and 62443-4-2 for manufacturers, cover security zones, protection levels (SL-1 to SL-4) and OT vendor auditing. Although not directly linked to NIS2, its adoption makes it easier to demonstrate proportionate measures in the OT domain and it is the most robust technical reference for the IT/OT boundary in energy.
Combining an ISO 27001 ISMS with selected IEC 62443 controls in OT and, where applicable, ENS can provide a practical structure for addressing NIS2 expectations in mixed IT/OT environments. These frameworks support compliance evidence; they do not replace an entity-specific legal and risk assessment.
NIS2 also operates alongside other energy and critical-infrastructure requirements. Applicable organisations should map overlaps with the Critical Entities Resilience framework and, for relevant electricity entities, the EU network code on sector-specific cybersecurity aspects of cross-border electricity flows. This avoids duplicate controls while preserving each regime’s distinct reporting and resilience obligations.
6 NIS2 Non-Compliance Risks for Energy Operators
The risks of inaction extend beyond the financial penalty. The precise supervisory response depends on the final national law, the entity category, the facts and the safeguards that apply, but energy operators should plan for the following six exposures:
- Administrative fines for essential entities. The Directive requires Member States to provide maximum administrative fines of at least €10 million or 2% of worldwide annual turnover, whichever is higher.
- Administrative fines for important entities. The Directive requires maximum administrative fines of at least €7 million or 1.4% of worldwide annual turnover, whichever is higher.
- Management and governance consequences. Liability and any temporary prohibition depend on the final national law, the entity category and the enforcement conditions. Figures appearing in Spain’s draft legislation should not be treated as penalties already in force under completed NIS2 transposition.
- Supervisory measures affecting authorisations. For essential entities, competent authorities may have powers to request temporary suspension of relevant certifications or authorisations, subject to the conditions, safeguards and proportionality requirements implemented in national law.
- Commercial and reputational exposure. Industrial customers, partners, insurers and investors increasingly request demonstrable cybersecurity controls. Weak evidence or an unmanaged incident can affect tenders, contracts and confidence before a formal fine is imposed.
- Operational and safety consequences. Unmanaged attack paths, fragile supplier access or untested recovery can turn a cyber event into loss of visibility, delayed restoration or disruption of essential energy services.
The most common form of non-compliance is not ignorance of the regulation, but the gap between what exists on paper and what is practised operationally. That gap is precisely what an experienced sector supervisor looks for.
7 Steps to Prepare Your NIS2 Compliance Plan in Energy
Step 1. Determine scope and category. Is the entity essential or important? Which systems and services fall within the NIS2 scope? Which authority will supervise compliance? Reference: INCIBE-CERT NIS2 FAQ.
Step 2. Gap assessment. Compare the current state of technical and organisational measures against Article 21 requirements. Identify the gaps with the highest risk and greatest visibility to supervisors.
Step 3. Prioritise by real risk. Not everything can be done at once. Risk analysis must drive prioritisation: which failure scenario has the greatest impact? Which missing control leaves the greatest exposure?
Step 4. Structure governance. Formalise management body involvement per Article 20, assign domain owners and create the reporting mechanisms that connect operations with management.
Step 5. Document and evidence. Compliance without evidence does not exist before an auditor. Every measure must have documentation, an owner, a last-review date and, where applicable, effectiveness metrics.
Step 6. Test the plans. Incident simulations, recovery tests, notification exercises. Not to tick a box, but to identify where the real plan diverges from the plan on paper.
Step 7. Maintain the programme. NIS2 is not a one-off project; it is a continuous programme. The directive expects periodic review, updates in response to changes in the threat landscape and a documented improvement cycle.
What PrivaLex Offers in NIS2 Projects for Energy
PrivaLex is a consultancy specialised in certifications, regulatory compliance and data protection. We support compliance officers, CISOs, operations management and legal teams at energy entities in translating NIS2 into operational controls, defensible risk decisions and evidence that can be used with management, auditors, customers and supervisors.
Energy-sector work must connect legal scope with real IT and OT dependencies. Our approach integrates NIS2, ISO/IEC 27001, ENS and IEC 62443 where relevant, while keeping the requirements and evidence for each framework distinguishable.
1. Energy Scope and Entity Classification
We map the legal entity, energy activity, services, size, group structure and national designations against the NIS2 annexes. The assessment identifies which parts of the organisation support the in-scope service and records the reasoning behind potential essential or important status. It also distinguishes direct obligations from requirements received through licences, customer contracts or participation in an energy group.
2. IT/OT Risk and Control Assessment
We assess governance, architecture and operational evidence against Article 21, with particular attention to segmentation, engineering access, logging, vulnerability decisions, secure configuration, identity, recovery and legacy-system constraints. Findings are tied to credible energy-service scenarios, owners and evidence requirements. Where a measure cannot be implemented immediately, the plan documents compensating controls, residual risk and a time-bound treatment decision.
3. Management Governance and Training
We help management bodies approve the risk-management measures, receive meaningful reporting and understand the decisions they must challenge. Deliverables can include a RACI matrix, risk-acceptance thresholds, management dashboards, approval records and role-based training. This makes the Article 20 responsibility visible without asking directors to manage technical operations themselves.
4. Incident and Notification Exercises
We connect detection in the SOC or control environment with legal classification, operational escalation and management decisions. Tabletop exercises can test ransomware, loss of telemetry, compromised vendor access or cross-border disruption. Teams practise the early warning, incident notification and final reporting stages using incomplete information, while preserving evidence and coordinating any parallel sector or contractual communications.
5. OT Supplier and Remote-Access Controls
We classify suppliers by their ability to affect the essential service, review security clauses and test how access works in practice. The review covers approval, strong authentication, jump hosts, session records, subcontractors, vulnerability coordination, notification timelines and exit arrangements. This turns supply-chain security into verifiable controls rather than a standard questionnaire attached to every contract.
6. Evidence Mapping and Remediation
For each obligation and priority control, we identify the evidence an assessor should be able to trace: approvals, architecture decisions, access reviews, supplier assessments, incident records, recovery-test results and closed corrective actions. The remediation roadmap separates urgent operational exposure from documentation gaps, assigns realistic deadlines and gives management a view of risk reduction rather than only completion percentages.
7. Framework Alignment and Continuous Readiness
We map shared controls across NIS2, ISO 27001, IEC 62443, ENS and applicable resilience or energy-sector rules so one effective control can support several obligations without blurring their scope. We also monitor the Spanish transposition and update authority, registration, reporting and enforcement procedures once they are final. The outcome is a maintained programme with tested controls and a current evidence set, not a one-off compliance project.
Start with the PrivaLex NIS2 service to review the framework, or contact our team to confirm scope and build a proportionate energy-sector roadmap.
Frequently Asked Questions (FAQs)
Energy is listed in Annex I of Directive (EU) 2022/2555, covering defined electricity, district heating and cooling, oil, gas and hydrogen entity types. Annex I inclusion does not automatically make every operator essential: classification depends on the exact entity type, size-cap rules, specific designations and national implementation. A documented scope assessment is therefore required.
The regime has three phases: early warning within 24 hours, incident notification within 72 hours and a final report within one month. Deadlines run from when the entity becomes aware of the incident, not from when it has been fully analysed. The reporting channel must be confirmed under the Spanish framework that currently applies to the entity and updated when the final NIS2 transposition is enacted. Internal classification and escalation procedures should therefore be in place before an incident occurs.
NIS2 does not mandate a specific certification, but it does require documented and auditable risk management measures. ISO/IEC 27001 is the most recognised standard for demonstrating that compliance in a structured way. The European Commission may establish mandatory certification schemes for certain products and services in the future. In the meantime, combining ISO 27001 with IEC 62443 for OT environments and ENS where applicable is the structure that best covers NIS2 expectations for operators with mixed IT/OT environments.
Article 20 of Directive NIS2 requires management bodies to approve cybersecurity measures, oversee their implementation and receive periodic training. National law may establish management liability and, under defined conditions, temporary prohibitions following serious infringements. Spain’s draft provisions are not final penalties currently in force under a completed NIS2 transposition. The immediate obligation is nevertheless clear: management must provide effective approval and oversight rather than delegating the entire programme to the technical team.
The directive requires assessing and managing risks introduced by vendors with access to critical systems. For OT environments this means: classifying vendors by criticality, documenting remote access conditions (including MFA and session logging), establishing contracts with effective security clauses and evidencing periodic review of those access conditions. A standard contract is not sufficient. The IEC 62443 framework provides a solid technical reference for structuring OT vendor auditing.
The Directive requires Member States to provide maximum administrative fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and €7 million or 1.4% for important entities, whichever is higher in each case. The precise penalties, management consequences and supervisory measures depend on national implementation and the facts of the infringement.
Commission Implementing Regulation (EU) 2024/2690 is binding for specified digital-infrastructure, digital-provider and ICT-service entities. It does not directly apply to traditional energy operators. An energy entity may use it as a voluntary source of implementation detail, but should rely on the Directive, applicable national law and sector-specific requirements when defining its obligations.
