NIS2 (Network and Information Security) and the transportation sector – the essentials of cybersecurity.

In Bulgaria, the NIS2 Directive was transposed through amendments to the Cybersecurity Act, adopted on February 5, 2026, and entered into force on February 17, 2026. The full sanctions regime will take effect after June 1, 2026, making this year critical for organizations to achieve compliance.

What is NIS2 in a nutshell (NIS2: Network and Information Security)

The NIS2 Directive establishes a unified framework for a high level of cybersecurity in the EU and expands the scope of organizations required to implement measures to protect networks and information systems. It builds on NIS1 and introduces stricter requirements, expands the scope to include more sectors, and provides for stronger oversight and sanctions.

Transportation is one of the key sectors. Transportation companies are considered part of critical infrastructure because they ensure the continuity of the economy, rely heavily on digital systems, and are part of supply chains and international networks

NIS2 covers 18 critical sectors, including transportation, energy, healthcare, finance, and others.

In the transport sector, this includes: rail transport, air transport, maritime transport, road transport and logistics, and infrastructure operators (ports, airports, terminals)

Which transport companies are covered by the directive:

  • Essential entities – stricter control
  • Important entities – follow-up review

A large proportion of transport operators fall into the “Significant” category.

NIS2 requires cyber risk management; therefore, organizations must have: a formalized risk management process, documented policies and procedures, and measures commensurate with the actual risk.  This means: a minimum set of technical and organizational measures, which  include: access control, incident response procedures, business logging and monitoring, and event traceability

One of the biggest changes in NIS2 is that countries must incorporate policies on supply chain security and vulnerability management. What does this mean in practice for transportation companies:

The transportation sector is heavily reliant on IT providers, logistics partners, telecommunications operators, and fleet and cargo management systems. Companies are now also responsible for supplier risk and must have processes in place for incident detection, impact assessment, and rapid reporting to the authorities. Incident response is a central focus of the directive.

Management accountability is a very important issue because it makes management personally responsible and requires management oversight of cybersecurity.

NIS2 introduces significant penalties and stricter oversight. This transforms cybersecurity from an IT issue into a regulatory and business obligation.

NIS2 makes cybersecurity a key regulatory and strategic priority for the transport sector. Companies must implement systematic risk management, technical and organizational security measures, supplier oversight, incident response capabilities, and management oversight of security.

Our company, RTS Transport Solutions, has partnered with a leading cybersecurity auditor to ensure the highest level of expertise and compliance with NIS2 requirements. Through this collaboration, we will guide our clients toward the most suitable and effective solutions tailored to their specific risks and needs.

Contact us to find out whether your company falls within the scope of the directive and what specific steps you need to take to comply with the requirements of NIS2