The revised directive on the security of network and information systems (NIS2) will apply to postal service providers, including providers of courier services, that have more than 50 employees and a total annual turnover of €10m or more. This includes all providers that provide at least one of the four steps in the postal delivery chain, excepting transport.
Postal service providers must establish a cybersecurity risk mitigation strategy that:
- assesses the risks associated with their network and information systems;
- implements security policies to address the identified risks;
- establishes access control policies and uses authentication solutions to prevent unauthorised access;
- includes an incident handling procedure in response to cyberattacks; and
- establishes a service continuity strategy, including disaster recovery.
Postal providers must also notify significant security breaches within 24 hours to the national computer security incident response team.
As so-called “important entities” under NIS2, postal providers are subject only to ex post supervision.
For more information and to access our postal NIS2 report, please click on “Access the full content” - or on “Request Access”, in case you are not subscribed to our Postal intelligence service.
more news
21 September 26
EU Kids Act: EU Commission unveils gradual and differentiated approach to protect children online, including a social media delay
As announced by EU Commissioner Von der Leyen in her State of the Union address, the EU Commission unveiled a gradual and differentiated approach to protect children online, where “each age benefits from a tailored protection level”. Read our full analysis.
18 September 26
EU Timeline: regulatory milestones for the remainder of 2026
This edition of Cullen International’s EU Timeline highlights key policy and regulatory developments foreseen at EU level until the end of 2026.
17 September 26
Electric power backup and other redundancy requirements for telecoms operators across Europe
Our latest European Benchmark explores electric power backup and other redundancy requirements for mobile network operators to ensure service continuity during power outages, natural disasters, and other events impacting the operation of telecoms networks.