Skip to main content

Glossary

NIS2

NIS2 is the European directive (EU) 2022/2555 on the security of network and information systems, transposed into national law by 17 October 2024. It widens the list of regulated sectors well beyond the first NIS directive and requires covered organizations to put risk management measures in place, including control over the devices their staff work on.

How it works

NIS2 replaces the 2016 NIS directive. As a directive rather than a regulation, what binds you is the national transposition, supervised by a national authority: ANSSI in France, the BSI in Germany, INCIBE and the CCN in Spain. Most member states legislated after the October 2024 deadline, so scope and reporting details still differ slightly between countries.

Covered organizations are split into essential entities and important entities, by sector and by size. Energy, transport, banking, health, drinking water, digital infrastructure, public administration and postal services are in scope, along with much of manufacturing and waste management, which NIS1 left out. A company above 50 staff or 10 million euros of turnover can land in scope without ever having thought of itself as critical infrastructure.

Two articles carry most of the weight. Article 21 lists the measures expected: asset inventory and access control, multi-factor authentication, cryptography, patch management, supply chain security, incident handling. Article 23 sets the clock, with an early warning within 24 hours of a significant incident, a fuller notification within 72 hours and a final report within a month. Fines reach 10 million euros or 2 % of worldwide annual turnover for essential entities, and management bodies are personally accountable.

Why it matters for a fleet

Phones and tablets are where most of your people read mail and open attachments, and nothing in article 21 carves them out. An auditor asking how you control access to company data expects the same answer for a warehouse Android tablet as for a laptop: known inventory, enforced encryption, current OS, and fast access revocation.

The 24-hour clock is the part teams underestimate. A device goes missing on a Friday evening and you need to know within hours whether it held regulated data, whether storage was encrypted and whether the wipe went through. That is an evidence problem before it is a security one, and a fleet you can only describe from a spreadsheet will not answer in time.

Worth being plain about this: NIS2 never mentions MDM. It asks for outcomes; device control is one route there.

How Appaloosa handles it

Appaloosa holds no certification and does not make you NIS2 compliant. The obligation stays with your organization. What the platform gives you is the controls and the evidence that article 21 expects on mobile: a device inventory with OS version and last check-in, enforced passcode and storage encryption, compliance rules that flag a device outside policy, selective or full remote wipe, and an export of that state for an auditor.

Hosting belongs in the same conversation. Appaloosa runs on infrastructure located in France that holds the ANSSI SecNumCloud qualification (version 3.2, which covers immunity to non-European legislation), and customer data is not transferred outside the EU. For an organization documenting its suppliers under article 21, that removes one question from the list. The mobile half of your risk measures then lives with your mobile device management configuration, not in a yearly report rebuilt by hand.

Book a demo

See Appaloosa run on your fleet

A 20-minute call on your real setup. Enrollment, private apps, security.

Book a demo

See the full platform Explore Appaloosa

Frequently asked questions

Does NIS2 require an MDM?
No. The directive asks for outcomes, not products. But article 21 expects access control, cryptography and patch management on the systems your staff use, and on smartphones and tablets an MDM is the practical way to apply and prove those measures across a fleet.
How do I know whether my company is in scope?
Check your sector against annexes I and II of the directive, then your size. Above 50 employees or 10 million euros of turnover in a listed sector, you are likely an important or essential entity. Your national authority publishes the definitive criteria and the registration process.
What do I have to report within 24 hours?
An early warning, not a full analysis. You state that a significant incident occurred, whether it looks malicious and whether cross-border impact is possible. The detailed notification follows within 72 hours and the final report within a month, which is when device logs and inventory data matter.