Glossary
NIS2
NIS2 is the European directive (EU) 2022/2555 on the security of network and information systems, transposed into national law by 17 October 2024. It widens the list of regulated sectors well beyond the first NIS directive and requires covered organizations to put risk management measures in place, including control over the devices their staff work on.
How it works
NIS2 replaces the 2016 NIS directive. As a directive rather than a regulation, what binds you is the national transposition, supervised by a national authority: ANSSI in France, the BSI in Germany, INCIBE and the CCN in Spain. Most member states legislated after the October 2024 deadline, so scope and reporting details still differ slightly between countries.
Covered organizations are split into essential entities and important entities, by sector and by size. Energy, transport, banking, health, drinking water, digital infrastructure, public administration and postal services are in scope, along with much of manufacturing and waste management, which NIS1 left out. A company above 50 staff or 10 million euros of turnover can land in scope without ever having thought of itself as critical infrastructure.
Two articles carry most of the weight. Article 21 lists the measures expected: asset inventory and access control, multi-factor authentication, cryptography, patch management, supply chain security, incident handling. Article 23 sets the clock, with an early warning within 24 hours of a significant incident, a fuller notification within 72 hours and a final report within a month. Fines reach 10 million euros or 2 % of worldwide annual turnover for essential entities, and management bodies are personally accountable.
Why it matters for a fleet
Phones and tablets are where most of your people read mail and open attachments, and nothing in article 21 carves them out. An auditor asking how you control access to company data expects the same answer for a warehouse Android tablet as for a laptop: known inventory, enforced encryption, current OS, and fast access revocation.
The 24-hour clock is the part teams underestimate. A device goes missing on a Friday evening and you need to know within hours whether it held regulated data, whether storage was encrypted and whether the wipe went through. That is an evidence problem before it is a security one, and a fleet you can only describe from a spreadsheet will not answer in time.
Worth being plain about this: NIS2 never mentions MDM. It asks for outcomes; device control is one route there.
How Appaloosa handles it
Appaloosa holds no certification and does not make you NIS2 compliant. The obligation stays with your organization. What the platform gives you is the controls and the evidence that article 21 expects on mobile: a device inventory with OS version and last check-in, enforced passcode and storage encryption, compliance rules that flag a device outside policy, selective or full remote wipe, and an export of that state for an auditor.
Hosting belongs in the same conversation. Appaloosa runs on infrastructure located in France that holds the ANSSI SecNumCloud qualification (version 3.2, which covers immunity to non-European legislation), and customer data is not transferred outside the EU. For an organization documenting its suppliers under article 21, that removes one question from the list. The mobile half of your risk measures then lives with your mobile device management configuration, not in a yearly report rebuilt by hand.
Book a demo
See Appaloosa run on your fleet
A 20-minute call on your real setup. Enrollment, private apps, security.
Book a demo →See the full platform Explore Appaloosa