FAQ

Which physical security measures does NIS2 actually require?

25. January 2026

NIS2 (Article 21) requires physical security “as appropriate”, based on a risk analysis. The specific measures are risk-based and proportionate: your own risk analysis under Section 30 BSIG determines what is needed for your particular facility. For clearly bounded critical facilities such as substations, power stations and data centres, a typical risk assessment covers access control, perimeter protection, site surveillance and demonstrable documentation.

Leave us a rating

Click a star to rate this page.

out of 5 · ratings

No ratings yet.

We are sorry this page was not helpful.

Help us improve it.

How can we improve this page?