NIS2 and physical security: what does it mean for your entrances and access?
When organisations hear NIS2, the conversation often starts with cybersecurity. But the digital systems supporting essential services exist within physical environments—with people, entrances, access points and critical areas that also need protection.
NIS2 is designed to strengthen the security and resilience of network and information systems across the European Union.
But behind those systems are services people depend on every day.
Healthcare teams rely on systems to deliver patient care. Transport networks use connected technology to keep people moving. Energy, water and digital infrastructure support homes, organisations and communities.
Protecting these services requires more than compliance for its own sake. It requires organisations to understand the risks that could interrupt them and take appropriate steps to remain secure, reliable and available.
Physical security is one part of that wider picture.
So, what does NIS2 mean for your organisation – and where does physical access and entrance solutions fit in?
What is NIS2?
The Network and Information Security Directive (NIS2) is European Union legislation designed to strengthen cybersecurity and resilience across organisations providing essential and important services.
It replaces the original NIS Directive, covers more sectors and organisations, and places greater responsibility on those within scope to understand and manage cybersecurity risks.
Because NIS2 is a directive, each European Union Member State must bring its requirements into national law. This means the timing, terminology and detailed obligations can vary between countries.
At the time of publication:
The Netherlands - NIS2 has been implemented through the Cybersecurity Act (Cyberbeveiligingswet), which came into force on 15 August 2026. Organisations within scope must comply with duties including risk management and incident reporting. Read the official Dutch guidance.
Germany - NIS2 has been implemented through the NIS2 Implementation Act (NIS-2-Umsetzungsgesetz), which came into force on 6 December 2025. Organisations within scope are subject to cybersecurity risk-management, registration and incident-reporting requirements. Read the guidance from Germany’s Federal Office for Information Security.
France - France: France is continuing the process of bringing NIS2 into national law. ANSSI has been supporting organisations in preparing for the new requirements, including through its developing French Cybersecurity Framework, ReCyF. View the ReCyF working document.
Belgium - NIS2 has been implemented through the Belgian NIS2 Law, with its main requirements applying since 18 October 2024. Organisations within scope must take appropriate cybersecurity risk-management measures, report significant incidents and meet relevant registration and oversight requirements.
Ireland - Ireland is continuing the process of transposing NIS2 through the National Cyber Security Bill. Until the new legislation is enacted, the existing NIS framework remains in force for organisations already covered by it. Read the guidance from Ireland’s National Cyber Security Centre.
Does NIS2 apply to my organisation?
NIS2 covers more organisations and sectors than its predecessor.
As a starting point, an organisation may fall within scope if it operates in a sector covered by the directive and meets the relevant size criteria. Some organisations may also be included regardless of size because of the nature or importance of the services they provide.
These sectors include areas such as:
- Energy
- Transport
- Banking and financial market infrastructure
- Healthcare
- Drinking water and wastewater
- Digital infrastructure
- Information and communication technology service management
- Public administration
- Space
- Postal and courier services
- Waste management
- Chemicals
- Food
- Manufacturing
- Digital providers
- Research
These sectors support many of the systems and services around which modern life is built. Disruption can therefore extend beyond the affected organisation to patients, passengers, customers, communities and wider supply chains.
For many organisations, size also matters. Medium-sized and larger organisations operating within covered sectors can fall within scope. Some smaller organisations may also be covered because their services are particularly important or because they provide specific types of digital service.
Organisations in the Netherlands can also use the Dutch Authority for Digital Infrastructure’s official NIS2 self-assessment to help understand whether they may fall within scope.
Scope can depend on an organisation’s sector, size, services and national legislation. Official or legal guidance should therefore be used for a definitive assessment.
If NIS2 applies to you, what does it actually mean?
NIS2 requires organisations within scope to understand and manage relevant cybersecurity risks, take appropriate measures to protect their network and information systems, and prepare for and report significant incidents.
These measures include areas such as:
- Risk analysis and information-system security
- Incident handling
- Business continuity and crisis management
- Supply-chain security
- Access-control policies
- Asset management
- Security awareness and training
- The use of appropriate authentication and secure communications
The purpose is not simply to protect technology. It is to reduce the likelihood and impact of incidents that could interrupt important services.
That wider purpose matters. A hospital system becoming unavailable can affect patient care. Disruption to transport technology can affect passengers and operations. A cyber incident affecting an energy or water organisation can have consequences across entire communities.
Preparedness begins long before disruption occurs.
Why physical security still matters
NIS2 is cybersecurity legislation. It does not prescribe a particular entrance solution or make every physical entrance part of NIS2 compliance.
However, network and information systems exist in physical places.
Servers, control systems, communications equipment and operational technology may sit within data halls, control rooms or other protected areas. People require physical access to install, use and maintain them.
Unauthorised access to those spaces could expose technology or information to interference, theft or damage. At the same time, a cyber incident could affect access control, surveillance, communications or other connected physical security systems.
The relationship works in both directions.
This is why organisations need to consider physical access where it contributes to the protection and continuity of the systems and services within scope.
The practical focus should remain on risk:
- Who needs physical access to critical systems and spaces?
- How are identity and permission verified?
- Which areas require stronger protection?
- How are unauthorised access attempts prevented and detected?
- What happens to physical access if a connected system becomes unavailable?
- Can authorised teams still reach critical areas when normal arrangements change?
These are not only questions about compliance.
They help organisations understand whether their security arrangements support the people and operations needed to keep essential services available.
Where do physical access and entrance solutions fit?
Entrances are one part of a wider security environment, but they play an important role.
They are where access decisions take physical effect: where identity and permission are checked, entry is controlled and people are either allowed to continue or prevented from reaching a protected space.
Different areas may require different levels of control.
A public entrance may need to support visitors and higher numbers of people. A staff entrance may require reliable access for regular users. A control room, data hall or other sensitive space may need stronger identity verification and tighter control over individual entry.
The aim is not simply to add more barriers.
It is to apply the appropriate protection where it is needed, while enabling authorised people to reach the systems and spaces they are responsible for operating and maintaining.
At Boon Edam, we help organisations translate their security, operational and user needs into physical entrance and access strategies. This means considering who needs to enter, what lies beyond each access point and the potential consequences if access is misused or unavailable.
Because strong security is not measured only by what an organisation can stop.
It is also reflected in its ability to protect the people, operations and essential services that must continue.
From compliance to continuity
NIS2 is an important step towards stronger cybersecurity and resilience across Europe.
For organisations within scope, meeting legal obligations is essential. But the wider purpose reaches beyond the legislation itself.
It is about protecting healthcare, energy, transport, water, digital connectivity and the other services people rely on every day.
Physical entrances cannot deliver cybersecurity compliance on their own. But where physical access protects critical technology, information or operational areas, it forms part of the organisation’s wider security environment.
Understanding that role can help organisations move from treating NIS2 as a technical requirement towards seeing it as part of a broader responsibility: keeping essential services secure, reliable and available for the people who depend on them.
Life Is Worth Protecting.
How prepared is your organisation?
Understanding whether NIS2 applies to your organisation is an important first step. The next is understanding what evolving security and resilience requirements could mean for your own physical environment.
Complete our Critical Infrastructure Risk Assessment to assess your current approach to physical security, access, resilience and operational preparedness.
Need more support? Speak with one of our physical entrance and access experts to explore what your environment actually needs.
For definitive guidance on whether NIS2 applies to your organisation and your legal obligations, consult the relevant national authority and official guidance.
This article provides general information and does not constitute legal advice. For definitive guidance on whether NIS2 applies to your organisation and what obligations it may have, consult the relevant national authority or an appropriately qualified legal adviser.