Understanding NIS2 for IoT and OT connectivity
What NIS2 Article 21(2) asks of IoT and OT connectivity: segmentation, access control, visibility, resilience and audit trail, and who owns each part.
Compare global IoT connectivity providers on core control, permanent roaming, Zero Trust, real-time visibility and NIS2 evidence. Seven questions to ask.
Most teams do not choose the wrong connectivity provider. They outgrow the one they started with.
The first hundred devices behave. One country, one carrier contract, one invoice. Then the fleet ships across borders. Units land on networks nobody negotiated for. A batch goes quiet in Poland and nobody finds out until the weekly report lands. A hardware vendor asks for remote access to twelve units, and the only route you have is a VPN into the whole network.
None of that is a coverage problem. It is a control problem, and it surfaces at the point where connectivity stops being a procurement line and starts being risk you carry personally. This guide sets out what to compare when you buy global IoT connectivity in 2026, and what evidence to ask for at each step.
Global IoT connectivity is sold as one product and delivered as four distinct layers. Keeping them apart is the difference between a real evaluation and a folder of coverage maps.
Most providers price the first layer and describe the other three in brochure language. Ask for each layer on its own terms, with its own answer.
Architecture decides what a provider is able to change for you. Soracom, Emnify, and Onomondo are built on cloud-native, virtualised architectures running on partner infrastructure. That model is fast to deploy and works well for straightforward deployments. It also means routing rules, policy changes, and security controls pass through somebody else's platform.
IXT runs a dedicated mobile core built for IoT from the ground up. Routing, policy, and security sit under direct control, not behind a partner dependency.
Ask each provider one question: when you need a routing or policy change for your fleet, who makes it, and how long does it take.
Every provider quotes a network count. The number that matters is what happens to a device that stays in a country longer than the roaming agreement expects. Permanent roaming rules have tightened across several markets, and a device parked on a foreign network indefinitely is a service interruption waiting for a regulator to trigger it.
One SIM covers 600+ mobile networks across 190+ countries. That is table stakes. The follow-up question is the real test: what happens in month 14 in a market that restricts permanent roaming. IXT supports local IMSI options in key markets to reduce permanent roaming risk.
Ask for the provider's permanent roaming position country by country for your actual deployment markets, in writing.
Two answers dominate this question, and both were built for a different kind of device.
A private APN isolates traffic from the public internet. It gives you a flat network with everything inside it reachable from everything else. Private APN hides traffic but does not defend it.
A VPN encrypts transit and requires client software on the endpoint. Most sensors, meters, chargers, and cameras have no operating system to run that client. The VPN model breaks on first contact with real IoT hardware.
Zero Trust removes the assumption that anything inside your network is trusted. In IXT's model, Zero Trust means SIM identity, SecureNet private networking, and a Zero Trust layer that checks every session in the network and cloud. No client on the device. No exposed ports. Each device reaches the application it needs and nothing else.
Ask whether the provider's security requires software on the device. If it does, count the devices in your fleet that are able to run it.
When a device goes offline at 2am, how long before you know?
Most IoT platforms show usage and status with a 24-48 hour data delay. For a billing report that is fine. For a fleet where uptime is the product, it means the first person to notice an outage is your customer.
IXT's CMP shows every SIM in real time: status, usage, location, and session logs, with API access so the same data reaches your own systems.
Ask for a live demonstration, not a screenshot. Ask what the refresh interval is, in minutes.
Hardware vendors, installers, and maintenance contractors need to reach devices they supplied. The default answer is a VPN account, which grants far more than the device in question. One compromised contractor laptop then reaches the whole estate.
Privileged Remote Access replaces that with a browser session: time-limited, scoped to specific devices, session-recorded, with no client to install and no IP conflicts between vendors. A European EV charging operator with eight hardware vendors used this to give each vendor access to their own chargers and nothing beyond them.
Ask how many third parties hold standing access to your network today, and what each one is able to reach.
NIS2 places accountability at board and C-suite level, which changes who carries the consequence of a weak answer here. The Cyber Resilience Act adds product-side obligations for manufacturers.
IXT Zero Trust addresses NIS2 Article 21(2) technical controls: access control, network segmentation, incident detection, supply chain access, audit trail, and continuous authentication. Micro-segmentation contains a breach to a single device and prevents lateral movement across the fleet. You get a full audit trail of every device, every user, and every third-party contractor that accessed that device, including what actions they took.
Be direct about the boundary. IXT Zero Trust does not make you NIS2-compliant on its own. Risk documentation, incident response plans, staff training, supplier governance, and conformity assessment remain your responsibility. A provider that claims otherwise is selling you a problem for later.
Ask which specific Article 21(2) measures the provider contributes to, and which ones stay with you.
Per-device data plans create two failures at once. High-use devices run into overage charges while low-use devices leave allocation unused. Someone on your team then spends their month reallocating bundles by hand.
A shared data pool combines the fleet's allocation into one figure, so no gateway runs dry while others sit idle. Pool sizing depends on realistic usage estimates at setup, and an undersized pool affects the whole fleet, so treat the sizing conversation as part of the evaluation, not an afterthought.
Ask what happens commercially when a device doubles its usage, and what happens when half the fleet halves it.
IXT is a full MVNO running its own mobile core built for IoT. One SIM covers 600+ mobile networks across 190+ countries, available as SIM, eSIM, or iSIM. SecureNet keeps device traffic off the public internet and routes it to your data centre or to AWS, Azure, GCP, and Alibaba. Zero Trust is the standard security offering, delivering Zscaler ZTNA through the SIM with Illumio traffic mapping and policy-based segmentation on top. The CMP sits across all of it with real-time visibility and API access.
Choose a price-led provider if your fleet is small, domestic, and outside a regulated sector. Choose a cloud-native platform if speed of self-service matters more than direct control of routing and policy. Choose IXT when devices cross borders, third parties need access, and someone on your board has to sign the compliance statement.
Zero Trust is IXT's standard security offering. SecureNet on its own is the lighter option for deployments that decline Zero Trust, not the default position.
Yes. That constraint is the reason the enforcement sits in the network and cloud, not on the device. Headless sensors, meters, and cameras are the target case, not the exception.
It extends it. Existing Zscaler deployments reach devices that run an agent. IXT delivers the same Zero Trust Exchange to IoT and OT devices over cellular, which is the part your current deployment cannot reach.
IXT qualifies Zero Trust at 500+ devices, or earlier where a compliance deadline or vendor access problem is already live. Below 100 devices with no security pressure, start with the SIM and the CMP.
Visibility and enforcement. An APN isolates traffic but shows you nothing about what devices communicate with, and it applies no policy between devices inside it. Traffic mapping, anomaly detection, and segmentation come from the Zero Trust layer.
It depends on form factor. eSIM and iSIM deployments are provisioned over the air. Physical SIM fleets need a swap, which is why form factor belongs in the evaluation, not in the implementation plan.
Take the seven questions above into your next provider conversation and compare the answers side by side. If you want to see real-time fleet visibility and browser-based vendor access running against live SIMs, ask us how it works for your deployment. Book a demo at ixt.io.
Related articles
What NIS2 Article 21(2) asks of IoT and OT connectivity: segmentation, access control, visibility, resilience and audit trail, and who owns each part.
NIS2 affects how you connect, monitor, and secure IoT devices. Learn which requirements apply to SIM-based connectivity and the questions your provider should answer.
Effective NIS2 compliance for utilities: A practical checklist to secure and manage connected assets, focusing on identity, access control, monitoring, supply chain, and incident response.