NIS2 Compliance & Physical Access Security
Are You Ready?

Did you know that in 2025:
To address this growing threat, the EU is enforcing the NIS2 Directive, which came into force in October 2024, with enforcement now accelerating across member states throughout 2026.
Our solutions are designed for:
What is NIS2?
The NIS2 Directive strengthens cybersecurity requirements across the EU, helping companies improve resilience against an increasingly complex threat landscape.
It introduces broader risk management obligations covering both digital and physical security. This includes areas such as access control, perimeter protection, visitor management, and securing critical infrastructure and sensitive locations.
Failure to meet NIS2 requirements can lead to significant financial penalties and increased accountability for management. Taking a proactive approach to compliance not only reduces risk but also helps build a more resilient organisation.
As cyber threats continue to evolve, making continuous improvement, regular risk assessments, and ongoing security investment is essential for long-term resilience.
Which Companies are Subject to NIS2 Requirements Today?
NIS2 applies to medium and large companies operating in sectors considered essential or important to the European economy and society. Companies within the supply chain of NIS2-regulated entities may also need to meet enhanced cybersecurity expectations.
Classified Companies:
- Mid-size Organizations: 50 to 250 employees and €10M–€50M in annual revenue
- Large Organizations: more than 250 employees and more than €50 million in annual revenue
Large (essential) and mid-size (important) organizations are required to comply with NIS2 in the following 18 sectors: Energy, Transport, Banking, Financial Market Infrastructures, Health, Drinking Water, Wastewater, Digital Infrastructure, ICT Service Management, Public Administration (If a member state decides), Space, Waste management, Manufacture, production and distribution of chemicals, Production, processing and distribution of food, Manufacturing, Digital Providers, Research.
Why NIS2 Requires Ongoing Board Management Commitment
NIS2 places responsibility for cybersecurity compliance on board management. Those responsible for ensuring compliance may face personal sanctions, (incurring fines of up to €10 million or 2% of global annual turnover, whichever is higher), management bans, and more.
As cyber threats continue to evolve, compliance should be viewed as an ongoing business commitment—not a one-off project.
The Role of Physical Access Security in NIS2 (Access Control, Video Management System)
While NIS2 focuses on strengthening cybersecurity, it also recognises the importance of protecting the physical environment of network and information systems. Access control helps reduce risk by ensuring only authorised individuals can access buildings, IT & critical infrastructure, and sensitive areas.
An access control solution supports NIS2 by helping companies to:
- Secure buildings and restricted areas
- Manage employee, visitor, and contractor access
- Maintain detailed access logs for auditing and investigations
- Reduce the risk of unauthorised access and insider threats
- Strengthen business continuity and organisational resilience
(Physical) security aspects in the field of personnel, access policy, and asset management
- Adaptive security through Threat level management: Adapt security policies instantly in response to changing threat levels or incidents. Automatically adjust access rights, lockdown sensitive areas, and strengthen protection when elevated security measures are required.
- Flexibility through granular permission settings (RBAC): Assign access permissions based on an individual's role, responsibilities, or department. Granular access rights help enforce the principle of least privilege, reduce insider risk, and simplify ongoing user management.


Incident handling & real time response
- Always notified about pre-defined events: Automatically trigger predefined actions when a security event occurs, such as displaying live camera feeds, notifying security personnel, or activating site responses. Automation helps ensure faster, more consistent responses to potential threats.
- Automated alarm notification with workflow: An operator gets physical access alarm notification through floorplan with workflow steps should be taken.
Cryptography and Encryption
- Secure access via OTP & SSO: Protect access to security systems with authentication methods, including passwords, one-time passwords (OTP), single sign-on (SSO), and Microsoft Entra ID integration. Multi-layer authentication helps verify user identities and reduce the risk of unauthorised access.
- Secure end-to-end communication with IPROTECT: Ensure data exchanged between credentials, controllers, and servers is protected through end-to-end encryption.


Business continuity and crisis management
- Automated backup for operations (Failover protection): Automatically switch to a standby system if a server fails, ensuring continuous surveillance monitoring and uninterrupted security operations with minimal downtime.
- Camera as a backup for lost network (Edge recording): Maintain video recording even during network outages by securely storing footage on cameras. Once connectivity is restored, recordings are automatically or manually synchronised to preserve a complete evidence trail.
Multi-factor authentication
Card & PIN and Card & Biometry offer flexible multi-factor authentication to strengthen access security while ensuring a fast and seamless user experience.


Security in the processing, development and maintenance of network and information systems, incl. your IT room and infrastructure
- A Unified Security Interface: It provides a single, intuitive interface to monitor access points, cameras, alarms, intercoms, and more through a live, interactive floor plan of a facility. Take action in real time: arm or disarm systems, adjust door states, control video feeds, and respond to events as they happen.
- Automation of predefined actions: Automatically initiate predefined responses to security events, such as displaying live video, notifying security personnel, activating alarms, or triggering other security workflows. Automation reduces response times and ensures consistent incident handling.
- Automation of intrusion detection: Continuously monitor IT cabinets and critical infrastructure through door state monitoring, handle status detection, side panel tamper detection, and optional camera verification. Real-time alerts help security teams detect unauthorised access and respond rapidly to potential threats.
Real Use Cases
See how our solutions help companies protect their facilities and IT infrastructure against real security threats, ensuring business continuity, operational resilience, and rapid incident response.

Unauthorized Access
No card cloning risk with IPROTECT

Network Sabotage
Automated backup operation for system continuity - Failover protection

Database Attack
Secure end to end communication with IPROTECT

Incident Response
Pre-defined event in IPROTECT triggers alarm
And much more!
Customer Story
noris network AG
Founded in 1993, noris were the first Internet service provider in northern Bavaria making them a pioneer. They have been living up to this role for 30 years. With now more than 500 colleagues, they offer their customers IT services in various areas.



