Industry · Ports

NIS2 compliance for ports and terminals

Ports and port facilities sit in NIS2 Annex I. Managing bodies of ports and those operating terminal equipment must document risk management across IT, OT, and physical security.

Why are ports covered?

NIS2 Annex I explicitly names managing bodies of ports and port facilities, and those operating works and equipment within ports. Ports are hubs of critical infrastructure, and an outage cascades quickly into supply chains. The requirements cover both IT systems and operational technology.

Industry-specific risks

Terminal operating systems (TOS)

The system controlling loading, unloading and container flow is business-critical, and an attractive target.

Crane and OT control

Cranes, gates and handling equipment are controlled by industrial systems often connected to networks without being built for it.

Overlap with ISPS

The ISPS code covers physical and maritime security, but not the cyber requirements of NIS2. The two must be seen together.

Access control and suppliers

Many actors share the port area, forwarders, agents, maintenance, each with their own systems and access.

What Havvakt delivers

  • Mapping of TOS, OT control, access control and supplier access.
  • Risk assessment based on NSM Basic Principles, seen together with ISPS.
  • Management system, action plan and supplier register, audit-ready.
  • Incident readiness with templates for 24-hour notification.

This is what the requirements look like for your industry. Let’s talk.

Questions from ports

We have an ISPS plan, do we need more?

ISPS covers maritime security, but not the cyber risk NIS2 requires documented. We build on the ISPS work and add the compliance layer for IT and OT.

Who in the port is responsible?

NIS2 places responsibility on the management of the operating entity. We help assign ownership and build a management system that is actually followed up.

Does this cover terminal operators too?

Yes. Those operating works and equipment in the port are explicitly covered. We map both the port authority and the operators as needed.