What NIS2 Requires for EV Charging Connectivity

Article 21(2) names the technical measures. Here is which ones your connectivity answers, and which ones stay yours.

NIS2 requires operators of in-scope services to put technical and organisational measures behind their network and information systems. Article 21(2) names the ones that land hardest on connectivity: security policies for network and information systems, incident handling, supply chain security, access control and asset management, and multi-factor or continuous authentication. For an EV charging network, a connectivity architecture that answers those measures has four properties. Charger traffic never crosses the public internet. Each charger reaches only the application it needs. Vendor access is brokered, time-limited and recorded. Every session is logged in a form an auditor reads.

This article covers what the directive asks of the connectivity layer. It does not claim that any product makes an operator compliant. Compliance is an organisational posture, and most of it sits outside the network.

 

 

Why NIS2 lands differently on EV charging than on IT

An enterprise IT estate is made of managed endpoints. Someone installs an agent, patches the operating system, and pulls telemetry back to a security operations centre.

 

A charging network is made of unmanaged endpoints in public places. The charger is an OT device with a long service life, a constrained processor, and no capacity for a security client. It sits in a car park, physically reachable by anyone, connected over cellular, and maintained by hardware vendors who are not your employees. Every assumption behind an IT security model breaks against that picture.

 

NIS2 grants no exemption for it. The directive places accountability at board and C-suite level, personally.

 

 

Article 21(2)(d): supply chain security

What it requires: security in the relationships with direct suppliers and service providers, including the access those suppliers hold to your systems.

 

Where connectivity contributes: a charging operator with eight hardware vendors has eight parties needing access to their own chargers. The default answer is a VPN per vendor, which grants network reach far beyond the devices in question and creates IP conflicts between vendor networks. Privileged Remote Access replaces that with a browser session against one device, time-limited to a maintenance window and recorded end to end. No client install, no routable path into the wider network.

 

What stays yours: supplier governance, contractual security obligations, and the process that decides which vendor reaches what.

 

 

Article 21(2)(i) and (j): access control and authentication

What it requires: access control policies and asset management, and where appropriate multi-factor or continuous authentication.

Where connectivity contributes: identity begins at the SIM. The network authenticates the subscriber identity before the charger sends anything. A Zero Trust layer then checks each session against policy rather than trusting the connection because it originated inside the APN. Each charger receives least privileged access to the back office application it needs and nothing beyond it.

 

What stays yours: the policy itself, the identity lifecycle for human operators, and the decision about which systems justify stronger authentication.

 

 

Article 21(2)(a): security policies and network segmentation

What it requires: policies on risk analysis and information system security, which in practice means containing a security event in one part of the network so it does not reach the rest.

 

Where connectivity contributes: a private APN isolates charger traffic from the public internet, which is where most operators stop. Private APN hides traffic but doesn't defend it. Inside that APN the chargers sit on a flat network, so a compromise on one unit reaches the others. Policy-based segmentation between individual devices contains it to a single charger and stops lateral movement across the estate.

 

What stays yours: the segmentation policy design, and segmentation of the back office systems the chargers connect to.

 

 

Article 21(2)(b): incident handling and detection

What it requires: incident handling, with reporting obligations that begin within 24 hours of becoming aware of a significant incident.

 

Where connectivity contributes: detection depends on knowing what normal looks like. Real-time traffic mapping across every connected charger shows which devices talk to which destinations and flags deviations. That 24-hour clock is unforgiving when your fleet data updates on a 24-48 hour delay, which is the position many connectivity portals leave you in.

 

What stays yours: the incident response plan, the reporting workflow to your national authority, and the staffing behind both.

 

 

Article 21(2)(f): proving the measures work

What it requires: policies to assess whether the cybersecurity risk management measures are effective, rather than measures that exist on paper.

 

Where connectivity contributes: a full audit trail of every device, every user, and every third-party contractor that accessed a charger, along with what they did in the session. Session recording turns vendor maintenance from an assertion into evidence.

What stays yours: retention policy, and the audit programme that reviews the evidence.

 

 

What this architecture does not do

It does not write your risk documentation. It does not train your staff. It does not patch charger firmware or manage the devices themselves. It does not replace a SIEM or an incident response function. It certifies nothing. IXT Zero Trust addresses NIS2 Article 21(2) technical controls at the connectivity layer, and the rest of the directive remains an operator responsibility.

Verify these claims against your legal and compliance team's interpretation of the transposed national legislation in your jurisdiction before including them in tender responses or compliance documentation.

 

 

Where to start

Map your charger estate against the measures above and mark which ones your current connectivity answers. Most operators find access control and segmentation are the two with nothing behind them, because a private APN was treated as the security layer rather than as the isolation layer.

 

Ask us how the Article 21(2) technical controls map to your charging network. Book a demo at ixt.io.