NIS2 and road transport: What transport and logistics companies need to know

By Qargo insights team 5 min read

If you run a road transport, freight forwarding, or logistics business anywhere in the EU, the Network Information and Security Directive 2 (NIS2) isn’t a directive you can afford to watch from the sidelines. National laws are landing right now – Belgium’s essential-entity deadline has already passed, the Netherlands’ Cyberbeveiligingswet took effect on August 15, 2026 with no grace period, and France is still finalising its version. 

Transport is explicitly named as a covered sector, and NIS2’s size-based scope means most mid-size carriers and forwarders are pulled in, whether or not you’ve ever thought of your business as “critical infrastructure.” Here’s what NIS2 actually requires, where each market stands, and how to get ahead of it before it becomes a scramble.

What is NIS2? 

The Network Information and Security Directive 2, or NIS2, is an EU-wide cybersecurity directive. It’s a replacement for NIS with additional sectors coming into scope and size-based rules instead of a fixed critical-infrastructure list. If your company falls within a covered sector, you will likely have to follow NIS2 requirements if you have 50+ employees and €10 million+ in turnover.

Different countries across the EU have varying timeframes for NIS2 coming into effect, so companies registered in multiple countries will have to be vigilant to a range of timelines, such as: 

  • Belgium – transposed earliest (Law of 26 April 2024); CyFun framework; essential-entity self-assessment deadline (April 18, 2026) already passed.
  • Netherlands – Cyberbeveiligingswet approved by Parliament and Senate in 2026, in force August 15, 2026, no grace period.
  • France – law delayed by an encryption dispute, EU Court referral in July 2026, expected to pass around September 2026; however contractual security clauses are appearing ahead of the law regardless.

Why road transport is explicitly in scope 

Transport was a named sector under NIS, but there was a lack of consistency across member states as each country identified which companies were classified as operators of essential services (OES). Under NIS2 the guidelines for inclusion are much more specific. 

There is still, however, an essential vs important entity split. For road transport, that generally looks like this: 

  • Essential: road authorities, and (depending on country) some larger transport operators
  • Important: road transport companies, freight forwarders, logistics/warehousing providers 

Smaller transport businesses which do not meet NIS2’s criteria may still need to demonstrate NIS2 compliance. This is due to the interconnected nature of logistics and larger essential companies pushing security requirements down their vendor chain (RFPs, security questionnaires, contract clauses).

What the NIS2 directive means for transport companies

The main requirements of NIS2 fall under a few key areas, including governance, risk management measures and reporting obligations. 

This may seem daunting, but you may already have a lot of these cyber security measures in place. 

In reality, for transport operators this will mean implementing: 

  • Risk management basics – access control, MFA, logging/monitoring, incident response plan
  • Incident reporting timelines – building out 24h early warnings, 72h notifications, and 1-month final report, without going deep into regulation numbers
  • Management accountability – creating a culture where cybersecurity isn’t just an “IT problem,” – leadership can be personally liable if things go wrong
  • Supply chain due diligence – expect more security questionnaires from customers and partners, and expect to have to answer them about your own systems, including your TMS

How to get ahead of NIS2

The first stage is to check whether you meet the size and sector threshold for each country that you operate in. Even if you don’t meet the threshold, it’s still worth putting measures in place as you may eventually reach the criteria or have large partners across the supply chain make requests for stringent cyber security measures. 

Each country will have its own self assessment process, such as CyFun in Belgium, MesServicesCyber in France, and Cyberbeveiligingswet portal in the Netherlands. Use these to evaluate your digital security, and find certified tools and providers. 

For existing software providers, ask to see evidence of their own security measures – and be prepared to provide the same for your customers. 

If you haven’t already, tighten access control and MFA across the systems you rely on daily. Your TMS is a good place to start, since it’s where a lot of this access-control work actually happens day to day. 

Check whether your provider offers role-based permissions, SSO, and MFA that admins can enforce – not just something individual users switch on themselves – plus audit logs you can point to if a customer or auditor asks. And rather than filling out a fresh security questionnaire every time a partner asks, check whether your provider already publishes this information. 

Qargo, for example, keeps a public Trust Centre with its ISO 27001 certificate and sub-processor list, alongside detailed FAQs and privacy policy – so you’re not starting from scratch each time one lands in your inbox.

Conclusion

NIS2 compliance in road transport isn’t optional paperwork, it’s becoming a baseline expectation from customers and partners across the EU – and getting the basics right now avoids a scramble later.

At Qargo, we’ve recently undertaken our own ISO 27001 / NIS2 alignment – registering as an important entity, formalising our incident response process, and staying security-questionnaire ready – so customers can point to their TMS vendor as part of their own compliance story rather than a gap in it. In practice, that means encryption at rest and in transit, role-based access control, SSO, MFA, and audit logging are already built into the platform, backed by a documented incident response plan with a 72-hour breach notification commitment.

Features like enforceable MFA at the admin level exist specifically because customers asked for them to meet NIS2 requirements – our platform configuration helps make it easier to align with compliance. 

Want to find out more about Qargo’s security and compliance features? Get in touch today.