NIS2 Principles
NIS2 Directive
The NIS2 Directive (2022/2555) applies to operators of essential and important services across energy, transport, manufacturing, health, water, and digital infrastructure. Our architecture is designed so that the IoT layer does not become your NIS2 gap.
What NIS2 requires
The NIS2 Directive (Directive 2022/2555) significantly expands the scope and severity of EU cybersecurity requirements. It applies to operators of essential and important services across energy, transport, manufacturing, health, water, digital infrastructure, and more.
Key obligations
- Article 21, Risk management measures: Organisations must implement technical and organisational measures including supply chain security, encryption, access controls, vulnerability handling, and incident response.
- Article 23, Incident reporting: Significant incidents must be reported to the national authority within 24 hours (early warning) and 72 hours (full notification with assessment).
- Penalties: Up to 10 million EUR or 2% of global annual turnover for essential entities, whichever is higher.
- Danish supervision: In Denmark, NIS2 implementation is supervised by Centre for Cyber Security (Center for Cybersikkerhed / CFCS).
How Nordic IoT supports your NIS2 posture
Our architecture is designed so that the IoT layer does not become your NIS2 gap. We handle the connectivity and gateway security so your IoT infrastructure supports your compliance posture rather than creating new obligations.
Encrypted data at rest (Article 21)
Every Nordic IoT gateway uses LUKS full-disk encryption (AES-256). All data stored on the device is encrypted at rest. If a device is physically stolen or decommissioned, storage contents are unreadable without the encryption key. Encryption keys are managed securely and are unique per device.
EU data residency
All data is processed and stored within EU borders on Hetzner infrastructure in Germany and Finland. The full stack runs on EU infrastructure that we operate, so your data stays under EU jurisdiction and GDPR. That gives you a clear, stable legal basis for your telemetry and a supply chain you can document end to end.
Access controls (Article 21)
Role-based access controls govern who can view dashboards, manage devices, and access administrative functions. Authentication and session management follow current best practices. All administrative actions are logged for audit purposes.
Incident logging and reporting (Article 23)
System event logs capture security-relevant events for investigation and audit purposes. When you need to demonstrate your security posture to auditors or report an incident within the 24-hour early warning window, the data is there.
Supply chain transparency (Article 21)
We document our hardware and software components with traceable origins. You know exactly what is in your system: Nordic IoT security-hardened industrial PCs, power meters from established manufacturers, Teltonika GPS trackers, and open-source software with a documented bill of materials.
Secure update mechanisms
Software updates are delivered through authenticated channels. Gateway firmware updates are signed and verified before installation, preventing tampering. Automatic security updates ensure devices stay current without manual intervention.
Hardware watchdog and unattended recovery
Every gateway includes a hardware watchdog timer that automatically recovers from software hangs. In unattended industrial deployments, this reduces the risk of extended downtime that could compromise your incident response capability.
IoT Security Checklist for NIS2
Preparing for NIS2? Request our IoT Security Checklist, a practical guide to ensuring your IoT layer supports your NIS2 readiness process. It covers encryption requirements, access control implementation, incident logging, supply chain documentation, and device hardening.
Contact us at hello@nordiciot.com or use the form below.
Request the IoT Security Checklist for NIS2
A practical guide to ensuring your IoT infrastructure supports your NIS2 readiness process. No sales pitch, just the checklist.
