NIS2 is usually discussed as a cybersecurity directive, but its risk-management obligations extend to the physical security of the infrastructure that supports essential and important services.
Organisations in scope are required to manage risk to the systems that underpin their service — and physical access to server rooms, control rooms and critical infrastructure is squarely part of that risk surface. A cyber-hardened system behind an unmanaged door is still a NIS2 gap.
The directive’s emphasis on accountability and demonstrable risk management means physical security decisions need to be documented and auditable in the same way cybersecurity controls are — access logs, incident response procedures and evidence that risk assessments actually happened.
For operators already engineering their cyber controls to NIS2 requirements, the practical extension is straightforward: bring physical access control, video evidence retention and incident logging up to the same standard of documentation and auditability.