NIS2 and the Connected Utility

Is Europe Ready for NIS2? A Country and Sector Guide to NIS2 for Utilities

NIS2 for utilities has stopped being a legal deadline. It is now an operational test: can you demonstrate, with evidence, that you understand your risk and can respond when something goes wrong?

This whitepaper sets out what NIS2 for utilities means in practice, sector by sector and country by country, and gives you a structured 90-day plan to improve readiness without waiting for a multi-year transformation programme.

What’s Inside

  • Why NIS2 for utilities is now an evidence test, not a policy exercise, and why utilities are an unusually difficult environment to protect, from legacy OT to third-party support chains
  • Which European countries are furthest ahead: a country-by-country look at Belgium, Croatia, Hungary and Italy, and why legislative transposition isn’t the same as utility maturity
  • How sector readiness differs: electricity, gas, water and wastewater are not on the same footing, and ENISA’s own data shows where the gaps sit
  • What NIS2 for utilities means at the network level: routing control, segmentation, secure remote access and observability, explained without vendor jargon
  • A 90-day action plan: a structured, three-phase approach covering understanding the estate, reducing unnecessary exposure, then testing your evidence and incident response process

Why this matters…

Regulatory pressure around NIS2 on utilities is no longer theoretical. On 8 July 2026, the European Commission referred four Member States to the Court of Justice for failing to fully transpose NIS2, with financial sanctions requested. Meanwhile, ENISA’s own research shows the operational gaps are real: a third of energy operators have no critical OT process monitored by a security operations centre, and over a quarter take more than three months to patch critical vulnerabilities.

Utilities depend on a growing number of connected assets, from smart meters to substations to remote telemetry, often spread across mobile networks, roaming arrangements and multiple suppliers. Written policy will not answer a regulator’s questions about an incident. Evidence will.

For MNOs and IoT connectivity providers, this is also a commercial opportunity. Utility customers are asking harder questions about routing, segmentation, remote access and evidence than they were even a year ago, and connectivity is increasingly part of that conversation. This whitepaper sets out how MNOs and IoT providers can strengthen their utility proposition and support these requirements without replacing their existing core or connectivity platforms.

Dowload the Whitepaper – NIS2 and the Connected Utility

This field is for validation purposes and should be left unchanged.
This field is hidden when viewing the form

Next Steps: Sync an Email Add-On

To get the most out of your form, we suggest that you sync this form with an email add-on. To learn more about your email add-on options, visit the following page (https://www.gravityforms.com/the-8-best-email-plugins-for-wordpress-in-2020/). Important: Delete this tip before you publish the form.
Your Name(Required)
Privacy and marketing(Required)

Frequently Asked Questions (FAQs)

NIS2 is the EU’s updated cybersecurity directive, formally Directive (EU) 2022/2555. It replaces the original 2016 NIS Directive and significantly widens its scope, bringing an estimated 160,000 organisations across the EU into scope, including utilities. It sets out risk management measures, incident reporting obligations and governance accountability that essential and important entities must meet.

The EU deadline for member states to transpose NIS2 into national law was 17 October 2024, with obligations applying from 18 October 2024. In practice, implementation has been uneven. As of mid-2026 most member states have national NIS2 laws in force, but a handful, including Ireland, Spain and France, are still finalising their legislation. For utilities, this means checking the transposition status in each country you operate in, since obligations and deadlines apply at the national level, not the EU level.

NIS2 covers 18 sectors split into two tiers. Eleven high-criticality sectors, including energy, transport, banking, health, drinking water, wastewater and digital infrastructure, fall under stricter essential entity rules. Seven further sectors, such as postal services, waste management, chemicals, food and manufacturing, are classed as important entities with lighter supervision. Utilities sit squarely in the essential entity tier, covering electricity, oil, gas, hydrogen and district heating alongside drinking water and wastewater.

Compliance starts with understanding your exposure: mapping your assets, third-party dependencies and legacy OT systems against NIS2’s risk management requirements. From there, utilities need to demonstrate network-level controls such as segmentation, secure remote access and observability, alongside a tested incident reporting process that can meet the directive’s 24-hour early warning and 72-hour reporting windows. A phased approach, understanding the estate first, then reducing unnecessary exposure, then testing evidence and response, is more realistic than a single large transformation programme.