News

NIS2 explained: what transport companies need to know in 2026

Read as markdown

NIS2 is the EU's cybersecurity law for the companies that keep the economy running. It applies to medium-sized and large organisations in listed sectors, makes their management answerable for cyber risk, requires a set of basic security measures, and gives them 24 hours to raise the alarm after a serious incident. Most road hauliers and freight forwarders are not named in it directly. Many of their customers are, and those customers now have a legal duty to check the security of their suppliers, carriers and software included.

That last point is the one worth keeping. For a typical transport company, NIS2 arrives less as a letter from a regulator and more as a questionnaire from a shipper.

What NIS2 is, in plain words

NIS2 is Directive (EU) 2022/2555. It replaced the first NIS directive from 2016, which covered far fewer companies and was applied very differently from one country to the next. Because it is a directive and not a regulation, it does not bind companies directly: each member state writes it into its own law, and was meant to do so by 17 October 2024.

Not every country made that date. In July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose it, and asked the court for a lump sum and daily penalties until they do (Commission press release IP/26/1499, checked 29 September 2026).

Poland finished in 2026. The act of 23 January 2026 amending the Act on the National Cybersecurity System was published in the Journal of Laws on 2 March 2026 (Dz.U. 2026 poz. 252) and has applied since 3 April 2026 (Dziennik Ustaw 2026 poz. 252, checked 29 September 2026). In Polish law, the two NIS2 categories are called podmiot kluczowy (essential entity) and podmiot ważny (important entity).

One more date for completeness: on 20 January 2026 the Commission proposed targeted amendments to NIS2 as part of a wider cybersecurity package. They are a proposal, so the rules described below are the ones that apply today.

Who NIS2 covers

Two tests decide it: the sector you work in and the size of your company.

The sectors are listed in two annexes. The first, "sectors of high criticality", includes energy, transport, banking, health, drinking water, digital infrastructure, managed IT services and public administration. The second, "other critical sectors", includes postal and courier services, waste management, chemicals, food production, processing and wholesale distribution, and the manufacture of things like machinery, electronics, motor vehicles and trailers.

Size is the second test. As a rule, NIS2 applies to organisations in those sectors that are at least medium-sized under the EU definition: 50 or more employees, or annual turnover and balance sheet total both above EUR 10 million. Some organisations are covered regardless of size, for example the sole provider of an essential service in a country.

Within scope there are two tiers. Essential entities are mostly large companies in the high-criticality sectors. Important entities are everyone else in scope. Both follow the same security and reporting rules. The difference is supervision and fines: the authority checks essential entities proactively, and important entities after the fact, when there is evidence of a problem.

Does NIS2 apply to a trucking company?

Usually not directly, and it is worth being precise about why.

Transport is a high-criticality sector, but the directive lists specific types of company within it. Under air, rail and water transport it names carriers, airports, railway undertakings, shipping companies and port operators. Under road transport it names only two: road authorities responsible for traffic management, and operators of intelligent transport systems. The Polish list is the same, naming the road manager (zarządca drogi) and providers of ITS services. A road haulier or a forwarder is not on it.

There are exceptions worth checking. A medium or large courier or postal operator falls under the postal and courier sector. Rail, water and air freight operators are named directly. And an authority can designate a company whose disruption would cause serious harm. If any of these might describe you, get a lawyer to look at your actual structure, because the classification decides everything that follows.

For everyone else, the practical effect is indirect but real. NIS2 requires every covered company to manage "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers" (Article 21(2)(d)). A food wholesaler or a chemicals plant that ships with you now has to think about how you handle its data, who can log into the systems that carry its orders, and what happens to its deliveries if you are hit by ransomware. Expect the questions to come in tenders, security questionnaires and new contract clauses.

What covered companies must do

Article 21 asks for "appropriate and proportionate" technical, operational and organisational measures. Proportionate matters: a regional food distributor is not expected to run the same programme as an airport. The directive then lists what those measures must include at minimum:

  1. Risk analysis and information security policies.
  2. Incident handling.
  3. Business continuity, including backups, disaster recovery and crisis management.
  4. Supply chain security, meaning the suppliers and service providers you depend on.
  5. Security when buying, developing and maintaining systems, including handling and disclosing vulnerabilities.
  6. Ways to check whether all of the above actually works.
  7. Basic cyber hygiene and cybersecurity training.
  8. Rules on cryptography and, where appropriate, encryption.
  9. Staff security, access control and knowing what equipment and systems you have.
  10. Multi-factor authentication and secured voice, video and text communications where appropriate.

Poland's version, in Article 8 of the amended act, asks for an information security management system that covers the same ground and spells out a few extra items, such as continuous monitoring of the systems used to provide the service and physical security with access control.

Management carries this personally. Under Article 20, the management body approves the measures, oversees them and can be held liable when the company breaks the rules. Board members must also take cybersecurity training. The Polish act makes that concrete: the head of an essential or important entity completes training once every calendar year, and the training has to be documented.

How fast incidents have to be reported

A significant incident is one that has caused, or could cause, severe disruption to the service or financial loss for the company, or considerable damage to other people or businesses. For those, NIS2 sets three steps:

  • an early warning within 24 hours of becoming aware of it, saying whether it looks like an attack and whether it might affect other countries;
  • an incident notification within 72 hours, with a first assessment of severity and impact;
  • a final report within one month of that notification, covering the cause and what was done about it.

In Poland these reports go to the relevant CSIRT, and the clock runs from detection. Twenty-four hours is short. The companies that meet it decide in advance who declares an incident, who calls whom, and where the contact details live when the email server is the thing that is down.

Penalties

For breaking the security or reporting rules, the directive sets fine ceilings of at least:

  • EUR 10 million or 2% of total worldwide annual turnover, whichever is higher, for essential entities;
  • EUR 7 million or 1.4% of total worldwide annual turnover, whichever is higher, for important entities.

For essential entities that ignore orders, authorities can also go further, including asking a court to temporarily bar the chief executive from managing the company.

Poland uses the same ceilings, with minimum fines of PLN 20,000 for an essential entity and PLN 15,000 for an important one, and up to PLN 100 million where a breach creates a serious threat, for example to public safety. The head of the company can be fined personally, up to 300% of their monthly pay. There is also a grace period: the ordinary fines for companies and their managers can be imposed for the first time only two years after the act took effect, so from 3 April 2028.

The Polish timeline

If your company met the criteria on 3 April 2026, these are your dates:

What Deadline Source
Apply for entry in the register of essential and important entities (the S46 system) 7 May to 3 October 2026 Minister of Digital Affairs communiqué, Dz.Urz. MC 2026 poz. 7
Implement the security obligations, including the management system 3 April 2027 Art. 33(1) of the amending act
First audit, essential entities only 3 April 2028 Art. 33(2) of the amending act
First possible fines from 3 April 2028 Art. 35 of the amending act

The registration window closes on Saturday, 3 October 2026. A company that meets the criteria later has six months from that day to apply. The application is filed electronically and includes a declaration by the head of the company, made under criminal liability, that the data is true.

What a transport company should do now

If you are in scope, the list above is your project, and the registration date is this week. If you are not, the useful work is the same work, at your own scale, because it is what your customers will ask about:

  • Turn on two-factor login for email, banking, your TMS and any telematics portal. Then a stolen password alone is not enough to log in.
  • Know who has access to what. When someone leaves, their accounts close that day, including the shared ones.
  • Test a restore. A backup you have never restored is a hope, not a plan.
  • Write a one-page incident plan. Who decides, who calls the insurer and the customers, where the phone numbers are kept offline.
  • List your suppliers. For each, what data they hold and how you would carry on without them for a day.
  • Keep software updated, and give the office twenty minutes on fake payment-detail changes and suspicious attachments.

None of this needs a consultant. All of it helps you answer a security questionnaire without guessing.

How LiteTMS supports your NIS2 supply-chain checks

If your customers are in scope, your TMS is part of the supply chain they have to check. If you are in scope yourself, it is part of yours. Since NIS2 certifies no software, the useful question to put to any supplier is what it can show. Here is what LiteTMS can show today, against the measures listed above.

  • Each company's data kept apart. A company's operational data lives in its own separate database with its own database account, not in shared tables next to other customers' records.
  • Multi-factor login and access control. Every user can turn on two-step verification with an authenticator app or SMS codes, and administrators can see in the user list who has it switched on. Roles and permissions decide what each person can open, and access can be limited to selected branches.
  • A protected login. Repeated failed attempts are blocked for a while, users receive an email when their account signs in from a new device, sessions end after a period of inactivity, and changing a password signs out the other sessions.
  • A record of who did what. Security events such as sign-ins, failed sign-ins, permission changes and data exports are logged, and administrators with the right permission can review that log in the admin panel.
  • Encryption. Connections are encrypted, browsers are instructed to refuse unencrypted ones, and sensitive secrets such as two-factor keys and card PINs are stored encrypted.
  • Continuity and a way out. Backups are automated and kept isolated from the live system, and a company can request an export of its employee, vehicle, trailer and contractor records with related files. We wrote about how import and export work separately.
  • Vulnerability handling. Every deployment runs static code analysis, automated tests and a check of third-party libraries against known vulnerabilities. Dependency updates are monitored daily, the code is scanned for leaked secrets, and researchers can report a vulnerability privately to security@litetms.eu, as published in our security.txt file.
  • Commitments in writing. Our data processing agreement lists the core technical and organisational measures in its annex, names the sub-processors, gives at least 14 days' notice before a new one starts, allows an audit once a year, and commits us to report a personal-data breach without undue delay, aiming for an initial notice within 48 hours where feasible. Core hosting and storage are in the EU.

That is the material a supplier questionnaire usually asks for, and it is ready to hand over. If you want to walk through it with the person who fills in those questionnaires, or see it on one of your own transport jobs, get in touch and we will arrange it.

Sources

Questions people ask

Does NIS2 apply to road haulage companies?
Usually not directly. For road transport, NIS2 names road authorities that manage traffic and operators of intelligent transport systems, not hauliers or forwarders. A haulier can still be in scope through another route, such as courier services, and many will be asked about security by customers who are covered.
What is the NIS2 registration deadline in Poland?
Companies that met the criteria on 3 April 2026 must apply for entry in the register of essential and important entities between 7 May and 3 October 2026. Companies that qualify later have six months from the day they meet the criteria.
What are the fines under NIS2?
At least EUR 10 million or 2% of worldwide annual turnover for essential entities, and EUR 7 million or 1.4% for important entities, whichever is higher. In Poland the head of the company can also be fined up to 300% of their monthly pay, and fines can first be imposed from 3 April 2028.
How quickly must a NIS2 incident be reported?
An early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month of that notification.
What is the difference between an essential and an important entity?
Both follow the same security and reporting rules. Essential entities, mostly large companies in high-criticality sectors, are supervised proactively and face higher fines. Important entities are supervised after the fact, when there is evidence of a problem.
Is there a NIS2 certificate for software?
No. NIS2 places obligations on organisations, not on products, so no software is "NIS2 certified". What a covered company can ask a software supplier for is evidence of its security measures and contractual commitments, which it then weighs as part of its own supply-chain risk management.

Share

Keep in touch

Make room for better reads.

Choose LiteTMS as a preferred source to find more of our articles on Google.

Choose LiteTMS on Google

Confirm your choice on Google · Opens in a new tab

Personal onboarding

LiteTMS is live. Ready to bring your company on board?

LiteTMS is live, and we are onboarding new companies personally. Leave your email to join the next onboarding group. Self-service signup is coming soon.

Join the onboarding list