NIS2 for utilities: a practical connectivity checklist
Effective NIS2 compliance for utilities: A practical checklist to secure and manage connected assets, focusing on identity, access control, monitoring, supply chain, and incident response.
Why vending operators servicing NIS2-regulated sites need to prove how technicians access machines, and how Zero Trust replaces shared VPN access.
A vending machine placed inside a hospital, a train station, or a government building is not just a sales point. It is a device with its own SIM, its own payment terminal, and its own remote access path, placed inside a site that NIS2 designates as an essential or important entity once it meets the directive's size and sector thresholds, and that carries its own legal duty to secure its network and information systems, including the suppliers who access them.
NIS2 (Directive EU 2022/2555) requires essential and important entities, including hospitals, transport operators, and public administration bodies, to assess the security practices of the suppliers who touch their premises. A vending operator with technicians restocking and servicing machines on site is one of those suppliers. If a facilities manager asks how your technicians access a machine and the honest answer is a shared VPN with standing access, that answer becomes a line item in someone else's audit.
NIS2 Article 21(2) sets out ten technical, operational, and organisational measures that essential and important entities have to put in place, including a specific requirement to manage supply chain security.
A vending or micro-market operator is not itself an essential or important entity in most cases. The exposure comes from where the machines sit. A site in scope under NIS2 has to account for every supplier with physical or remote access to its premises, and that includes the operator servicing its vending fleet.
IXT Zero Trust addresses the access control, segmentation, and audit trail that a supplier risk assessment asks for. It does not make the host site NIS2-compliant, and it does not make a vending machine compliant with the Cyber Resilience Act on its own.
The Cyber Resilience Act (Regulation EU 2024/2847) is a separate obligation that sits with the manufacturer or integrator of the machine's connected payment terminal or controller, not with the site and not with IXT.
Facilities and security managers at hospitals, transport hubs, and public buildings are under their own NIS2 obligation to manage risk from suppliers with access to their sites. A vending machine on the concourse is a small part of that picture, until someone asks how the operator's technicians reach it.
That question is not hypothetical. Article 21(2)(d) of NIS2 requires essential and important entities to address security in their relationships with suppliers, including assessing the security practices of those suppliers directly. A vending operator with a standing VPN connection into a hospital's guest network, used to service a payment terminal, is exactly the kind of relationship that assessment is built to catch.
A connected vending machine is not a single device. It is a payment terminal, a stock sensor, and, for machines with remote diagnostics, a maintenance endpoint, all reachable over one SIM.
Two machines from the same operator can look very different in practice. The unit at the main station takes hundreds of transactions a day. The one on a quiet street corner takes a fraction of that. Both have to stay live, and both carry the same access risk if the path a technician uses to reach them is not controlled.
A private APN keeps that traffic off the public internet, but it does not segment one machine from another, does not show an operator what a device is actually communicating with, and does not restrict what a technician can reach once connected. It hides traffic. It does not defend it.
What it requires: security measures covering an organisation's direct suppliers, including an assessment of their security practices.
Where IXT Zero Trust contributes: Privileged Remote Access replaces VPN-based technician access with browser-based, time-limited, session-recorded connections. A technician authenticates through a web portal, sees only the application needed to service that machine, and never receives network-level access to the site. No VPN client is installed. The session recording gives the operator, and the site if asked, a documented record of exactly what happened and when.
What remains the operator's responsibility: vendor due diligence, the service contract terms with technicians and subcontractors, and the operator's own supplier governance process.
What it requires: controls over who has access to what, and an accurate inventory of the devices in scope.
Where IXT Zero Trust contributes: the IXT CMP gives a real-time inventory of every SIM and machine, including session diagnostics and searchable access history. That is the asset register a supplier risk assessment expects an operator to produce.
What remains the operator's responsibility: the access policy itself, deciding which technician gets which machine and for how long.
What it requires: the ability to detect, respond to, and recover from a security incident.
Where IXT Zero Trust contributes: traffic visibility flags a machine communicating with an unexpected destination, for example a compromised payment terminal reaching out to somewhere it should not. That shortens the time between an incident happening and the operator finding out.
What remains the operator's responsibility: the incident response plan, internal escalation, and any notification to the host site or a regulator.
If your business builds or integrates the connected payment terminal or controller inside the machine, the CRA's secure-by-design and vulnerability handling obligations sit with you. Vulnerability and incident reporting obligations apply from 11 September 2026, with full requirements, including conformity assessment, from 11 December 2027. For the complete breakdown of what the CRA requires and where Zero Trust fits around it, see IXT's dedicated NIS2 and CRA article.
A site in scope under NIS2 has to account for you as a supplier. If you also manufacture or integrate the machine's connected hardware, the CRA places separate obligations on you as well. Both come back to the same control: who can access the machine, how that access is granted, and what record exists afterwards. Controlled, auditable technician access answers both questions at once.
Verify the specific claims in this article against your legal and compliance team's interpretation of the transposed national legislation in your jurisdiction before using it in a tender response or compliance document.
In most cases, no. NIS2 applies to essential and important entities in sectors such as energy, transport, health, and public administration. A vending operator becomes relevant when it supplies or services machines on a site that is itself in scope, because that site has to assess the security practices of its suppliers.
Because NIS2 Article 21(2)(d) requires them to manage security risk in their supplier relationships. A vending operator with technicians accessing machines on site is one of those relationships, and the site's own audit will ask how that access is controlled.
Through Privileged Remote Access. Technicians authenticate through a browser, see only the application needed for that machine, and work inside a time-limited, recorded session. No client software is installed and no network-level access is granted.
No single product makes an organisation NIS2-compliant. IXT Zero Trust addresses the Article 21(2) technical controls that matter most for supplier and third-party access to connected devices. Risk documentation, incident response plans, and supplier governance remain the operator's responsibility.
It applies to the manufacturer or integrator of the machine's connected payment terminal or controller, as a product with digital elements. It does not apply to the site hosting the machine, and IXT Zero Trust does not make a product CRA-compliant on its own.
A private APN keeps the machine's traffic off the public internet, but it does not segment machines from each other, show what a device is communicating with, or control what a technician can reach once connected. Zero Trust adds identity-based access, segmentation, and a recorded audit trail on top of that connection.
See how Privileged Remote Access works for field technician access to distributed device fleets. Book a demo at ixt.io.
Related articles
Effective NIS2 compliance for utilities: A practical checklist to secure and manage connected assets, focusing on identity, access control, monitoring, supply chain, and incident response.
Enhance utility network security with Zero Trust principles. Learn how IXT SecureNet offers precise, per-session access control and robust auditing, replacing fragile site-to-site VPNs.
Third-party vendor access is one of the most common entry points for cyberattacks on industrial and IoT environments. Here is what the risk actually looks like, why traditional access methods make it worse, and what a more secure approach requires.