
NIS2 And EV Charging
💡 NIS2 And EV Charging: Key Highlights
- Annex I of Directive (EU) 2022/2555 names “operators of a recharging point” in the electricity subsector, next to DSOs, TSOs and suppliers. Charging is regulated energy infrastructure, not a retail app.
- The size cap decides everything: 50+ staff, or financials above the €10 million small-enterprise ceilings, brings you in. 250+ staff, or turnover above €50 million and a balance sheet above €43 million, makes you an essential rather than an important entity.
- Group ownership overrides your own headcount. Linked-enterprise data is added at 100%, so a 15-person charging subsidiary of a utility is assessed on the group’s numbers.
- The incident clock runs at 24 hours, 72 hours and one month — early warning, full notification, final report — to the national CSIRT of each Member State where you are established.
- Fines reach €10 million or 2% of worldwide turnover for essential entities, and authorities can temporarily bar a CEO from managerial functions. Management bodies approve the measures and can be held liable personally.
- Non-EU operators and vendors are reached through the supply chain — Article 21(2)(d) makes your European customer’s compliance your contractual problem.
If your company manages and operates public recharging points anywhere in the EU or EEA, NIS2 is already your law: the compliance date was 18 October 2024, and the obligations attach to your business, not your hardware. If you operate outside Europe — India, the Gulf, the UK — read on for a different reason: the directive reaches you through your European customers, not a regulator, which is why operators, charger makers and platform vendors outside the bloc keep receiving questionnaires they cannot answer.
NIS2 — Directive (EU) 2022/2555 — entered into force in January 2023, had to be transposed by 17 October 2024 and replaced the original NIS directive from 18 October 2024. What matters here is one line in its Annex I, which moved an entire industry into regulated-entity status without a single sector-specific rule being written for it.
This article covers the legal obligation only: the technical standard used to satisfy it is in our guide to IEC 62443 for EV charging, AFIR is a separate instrument on rollout and payment access, and engineering practice sits in secure EV charging API practices.
Why An EU Cybersecurity Law Names Charging Operators
Annex I of NIS2 lists, under the energy sector’s electricity subsector, “operators of a recharging point that are responsible for the management and operation of a recharging point, which provides a recharging service to end users, including in the name and on behalf of a mobility service provider”. That wording is deliberate twice over: it captures the operator, not the owner of the land or hardware, and its closing clause catches white-label operation — running points under someone else’s brand does not move the obligation to them.
The company sitting next to you in that annex is a transmission system operator, and ENISA’s NIS360 2026 assessment puts electricity among the Union’s most mature and most critical sectors — now the benchmark a charging business is measured against. The logic holds: a charging network is a population of internet-connected power electronics on unattended public sites, remotely reachable by third-party service providers, sitting on the distribution grid and moving money.
Are You In Scope Of NIS2 — And As What?
Being the right type of entity is only the first test, and the rest are where operators get the answer wrong. Article 2(1) applies NIS2 to Annex I entities that qualify as medium-sized enterprises under Recommendation 2003/361/EC, or exceed those ceilings — in practice, 50 or more staff, or turnover and balance sheet above the €10 million small-enterprise ceilings. Below that line, an ordinary operator is outside the general scope.
Above it, Article 3 splits the population in two. Exceed the medium-sized ceilings — 250 or more staff, or turnover above €50 million and a balance sheet above €43 million — and you are an essential entity; everything else clearing the size cap is an important entity. The labels set your supervision regime and maximum fine.
The group-ownership trap
The most common scoping error here is counting only your own employees. Under Article 6 of the annex to Recommendation 2003/361/EC, the data of linked enterprises — where one company holds a majority of voting rights or can appoint the board of another — are added at 100%, not pro rata. A fifteen-person venture majority-owned by a utility, an oil major or a large real-estate group is assessed on the group’s numbers and usually lands straight in the essential band; holdings of 25% or more aggregate proportionally as partner enterprises.
Designation regardless of size
Article 2(2) lets a Member State bring in an entity of any size where it is the sole provider of an essential service, where disruption could significantly affect public safety or induce systemic risk, or where it is critical at national or regional level. A small operator holding the only fast-charging corridor on a strategic route is exactly that profile. Check your competent authority’s list before assuming you are out.
One regulator per country, not one for Europe
This is the detail that surprises multi-country operators most. Article 26(1) places an entity under the jurisdiction of each Member State in which it is established. The “main establishment” rule — one lead regulator, where cybersecurity decisions are taken — exists only for the digital categories in Article 26(1)(b): cloud, DNS, data centres, managed service providers. Energy entities are not on that list, so a charging operator with subsidiaries in five Member States answers to five authorities, files five registrations and reports one incident to five national CSIRTs. The Commission proposed amendments on 20 January 2026 to simplify NIS2’s jurisdictional rules and route reporting through a single ENISA entry point — a proposal, not law.
There is also no EU-representative obligation for a non-EU energy entity — Article 26(3) imposes one only on the digital categories — so an Indian or Emirati operator with no EU establishment is not directly caught, only contractually. Your answer should land on one of three outcomes: in scope as essential, in scope as important, or not directly in scope but obligated through a customer.
Your NIS2 status, decided in five tests
Run them in order. The first failure ends the assessment; the last two can reverse it.
| Test | Threshold | What it decides |
|---|---|---|
| ActivityAnnex I, energy / electricity | You manage and operate recharging points providing a recharging service to end users — including under another brand | Whether the directive can apply to you at all |
| SizeArt. 2(1) + Rec. 2003/361/EC | 50+ staff, or turnover and balance sheet above the €10m small-enterprise ceilings | Whether the general size cap brings you in |
| GroupRec. 2003/361/EC, Art. 6 | Linked enterprises counted at 100%; partner holdings of 25%+ counted pro rata | Whether a small subsidiary is assessed on its parent’s numbers |
| BandArt. 3(1)(a) and 3(2) | 250+ staff, or turnover >€50m and balance sheet >€43m | Essential entity; otherwise important |
| DesignationArt. 2(2)(b)–(e) | Sole provider, public-safety impact, systemic risk, or national/regional criticality | Whether a sub-threshold operator is pulled in regardless of size |
| JurisdictionArt. 26(1) | Each Member State where you are established — no main-establishment rule for energy | How many authorities, registrations and CSIRTs you answer to |
The Obligations That Actually Cost Money
Article 21(2) sets ten minimum measures, proportionate by design — Article 21(1) weighs your exposure, size and cost of implementation. Four carry real budget: supply-chain security across direct suppliers; security in system acquisition, development and maintenance, including vulnerability handling and disclosure; multi-factor authentication and secured internal communications; and business continuity with backup and crisis management. The other six, from risk-analysis policies to cryptography, training and access control, are documentation and discipline for a serious operation.
The NIS2 incident clock: 24 hours, 72 hours, one month
An incident is significant under Article 23(3) if it has caused or could cause severe operational disruption or financial loss to you, or considerable damage to others — for a charging network, a payment-path compromise, a mass disconnection of chargers, or manipulated remote start-stop commands. The clock runs in three steps: an early warning within 24 hours of becoming aware, flagging whether the event looks malicious or cross-border; a notification within 72 hours with an initial severity assessment and indicators of compromise; and a final report within one month covering root cause, mitigation and cross-border impact.
Twenty-four hours is what quietly reshapes operations: you cannot classify severity that fast without charger- and session-level telemetry, retained logs and a named decision-maker on call. An operator running one charging management platform like YoCharge estate-wide pulls connector states, session records and audit trails for the window in minutes; one running four vendor portals spends day one establishing what happened.
Registration is a separate, earlier duty
Article 3(4) requires in-scope entities to give their competent authority a name, contact details including IP ranges, their Annex I subsector and the Member States they serve, with changes notified within two weeks; national lists were due by 17 April 2025. Timing varies sharply: Germany’s transposing act took effect on 6 December 2025 with no transition period, requires registration within three months of first becoming affected, and lifts the number of BSI-supervised organisations from roughly 4,500 to about 29,500.
Management Liability, Fines And Who Supervises You
Article 20 is why NIS2 belongs on a board agenda rather than an IT backlog. Management bodies must approve the risk-management measures, oversee implementation and can be held liable for the entity’s infringements; members must also undergo training. Delegating to a CISO does not discharge the approval duty.
Exposure scales with the band: essential entities face fines of at least €10 million or 2% of total worldwide annual turnover, whichever is higher; important entities, €7 million or 1.4%. Note the base — the turnover of the undertaking the entity belongs to, so the group logic that set your band also sizes your fine.
Supervision differs just as sharply. Essential entities are supervised ex ante under Article 32 — inspections, random checks and audits at their own cost, no suspicion required — while important entities are supervised ex post under Article 33, only on evidence of non-compliance. One power belongs to essential entities alone: where lesser measures fail, Article 32(5) lets authorities suspend an authorisation or ask a court to temporarily bar the chief executive from managerial functions.
A gap in national law is a timing question, not an exemption: on 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify complete transposition, seeking a lump sum plus daily penalties. Assume the obligations arrive with the transposing act — Germany’s arrived overnight.
Supply Chain: How A Vendor Outside The EU Gets Pulled In
Article 21(2)(d) obliges every in-scope entity to secure its relationships with direct suppliers and service providers, and Article 21(3) says how: account for the vulnerabilities specific to each supplier and the overall quality of their products and practices, including secure development procedures. A European CPO cannot evidence that with a brochure — it does it supplier by supplier, which turns an EU legal duty into a commercial requirement worldwide.
The direct suppliers that matter are the backend platform, the charger maker with remote-maintenance access, the connectivity and payment providers, and roaming counterparties reached over an OCPI roaming integration. Remote third-party access into field equipment is the highest-risk path: it bypasses the site entirely and is usually the least logged.
If you sell into Europe, the test is whether you can answer a buyer’s questionnaire with evidence, not assurances. Have five things ready: a named security contact with a 24/7 escalation path; a contractual notification commitment fast enough to feed the customer’s 24-hour early warning, which in practice means 8 to 12 hours; a published vulnerability-disclosure route and patch service levels; a current list of sub-processors and hosting locations per Member State; and enforced multi-factor authentication with role-based access on every operator console. Where you hold third-party evidence, name its exact scope — the next question is always which part was certified, and by whom.
A 90-Day Starting Sequence
Starting cold, sequence the NIS2 work so the legally dated items land first and the engineering follows.
Decide status, then register
- Run the five tests, including group consolidation
- Confirm the band per Member State of establishment
- Register with each competent authority
- Name the accountable management-body member
Inventory and gap assessment
- Asset register: chargers, gateways, backend, payment path, roaming links
- Gap-assess against the ten Article 21(2) measures
- Close MFA and access-control gaps first
- Book management-body training
Runbook and supplier clauses
- Write and rehearse the 24/72-hour reporting runbook
- Confirm CSIRT channels and escalation contacts
- Issue supplier notification and audit clauses
- Record the board’s formal approval of the measures
Frequently Asked Questions
Scope, deadlines and liability questions charging operators ask most about NIS2.
Sources: Directive (EU) 2022/2555 (EUR-Lex) | Recommendation 2003/361/EC on the SME definition | European Commission — NIS2 Directive | European Commission — referral to the Court of Justice, 8 July 2026 | ENISA NIS360 2026 | BSI — NIS-2 obligations (Germany)
Make Your Charging Operation Auditable
Compliance is an evidence problem before it is a security problem. Talk to us about consolidating charger, session and access data into one auditable platform.
What happens next ?
Scope review across every Member State you operate in
Asset and supplier inventory mapped to Article 21(2)
Reporting-readiness check against the 24-hour clock
Audit trails and evidence your buyers can verify