NIS2 (Logistics)Consumer & EducationEuropean UnionLogistics / Supply Chain

NIS2 Directive Article 21 - Supply Chain Security

NIS2 requirements specifically for logistics and supply chain operators. Requires data integrity auditing and proof of business continuity.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

NIS2 (Logistics)Article 21(2)(d)What your suppliers actually reach

Supply Chain Security

Entities MUST address security risks in supplier relationships with auditing of logistics databases.

A supplier-risk requirement has two halves and they are not equally hard. The register of providers, the contractual clauses, and the assessment of each supplier as an organisation are yours to maintain — nothing in the platform produces them. The half that is usually undocumented is what those suppliers, their tooling, and their service accounts are actually reaching inside your estate. Scanning surfaces the shared and vendor-default accounts, the credentials with no owner, and the standing privileges nobody has exercised; the query trail then shows which of those grants were used, against which classified tables, from which client host. So the review reflects observed third-party access rather than an attestation, and an integrator session that steps outside its usual pattern is scored as it happens rather than found at the next annual review.

NIS2 (Logistics)Article 21(2)(c)Continuity of the record

Business Continuity

REQUIRES proof of business continuity logs and data integrity verification.

A continuity requirement asks two different things, and only one of them is a database control. The recovery plan, the failover drill, and the tested restore are yours. What is produced here is the evidence layer under them: backups and exports are hashed and baselined alongside the datafiles, so a backup that was silently truncated, moved, or never written is evident rather than discovered at the restore. Audit events land in columnar storage on immutable object storage with a verification hash per record, so the history survives the incident that made you need it and is still queryable in seconds afterwards. Collection failure is itself an alerting condition, which is what evidences that the record was continuous rather than merely intended to be.

NIS2 (Logistics)Article 21(2)(e)A record of access

Acquisition Security

Security in network and information system acquisition MUST be documented and audited.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

NIS2 (Logistics)Article 23Detecting it in time to notify

Incident Reporting

Supply chain incidents MUST be reported within 24 hours with supporting audit data.

Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.

What NIS2 (Logistics) covers

This instrument defines no data category of its own. Regulates the security of network and information SYSTEMS. Art. 21 lists measures rather than data classes, and an entity is in scope for its sector and size, not for what it stores.

How NIS2 (Logistics) is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The national competent authority designated by each Member State.

Published maximumChargedAs at
EUR 10 million or 2% of worldwide turnoverwhichever is higher, against an essential entity2026-08
EUR 7 million or 1.4% of worldwide turnoverwhichever is higher, against an important entity2026-08

Both ceilings take the higher of the fixed sum and the percentage. The more consequential provision is not the money: Article 20 places the approval and oversight of cybersecurity risk-management measures on the management body itself, and Article 32(6) lets an authority ask a court to bar a named executive from running the business.

Article 34 sets a floor, not a ceiling. Member States may and do set higher maximums when transposing, so the national figure is the one that governs.

Who is personally on the hook

Who can be charged
Any natural person discharging managerial responsibilities at chief executive or legal representative level in an essential entity
For what
failing to approve and oversee the cybersecurity risk-management measures the entity is required to take
Maximum
A temporary prohibition on exercising managerial functions in that entity, lasting until the deficiencies are remedied. Article 20 separately makes the management body accountable for approving and overseeing the measures
Brought by
The national competent authority, through the courts of the Member State
Disqualification

Uncapped exposure that sits outside this instrument

These come from company law rather than from NIS2 (Logistics), and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Who the instrument makes accountable

Article 20 requires the management body to approve the cybersecurity risk-management measures and oversee their implementation, and makes it accountable for that. Article 20(2) adds a training obligation on the same people.

The insurance position

Cyber wordings in the EU commonly cover the incident response and the regulatory defence; administrative fines are often excluded where local law makes them uninsurable, and that varies by Member State.

How this class of policy is commonly written. Only your own policy answers what it covers.

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for NIS2 (Logistics),
not configured for it afterwards

Policy Template

Supply Chain Data Integrity

Audit logistics and routing database modifications

Report

NIS2 Supply Chain Report

Business continuity and data integrity evidence

Classification

Logistics Data Patterns

Identify shipment, routing, and supply chain data

Alert

Supply Chain Incident Alert

24-hour notification capability for supply chain incidents

Other Consumer & Education frameworks

Walk into the NIS2 (Logistics) audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment