Postal and courier services are the first sector in Annex 2, the one for critical sectors. Medium-sized and large companies are important entities; none is essential by default. The standard score is 50 for a small organisation, 100 for a medium-sized one and 150 for a large one, so both reach the important level, with 133 controls.

Who is covered by NIS2 in postal and courier services

The sector comes from the NIS2 Directive, which refers to the definition of a postal service provider in EU postal legislation. It covers:

Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.

Which assurance level applies

Organisation sizeEntity typeStandard risk scoreAssurance levelAt self-assessment
Small or microoutside NIS2, except for the cases in the law50basic34 controls, threshold 2.5
Mediumimportant100important133 controls, threshold 3
Largeimportant150important133 controls, threshold 3

The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.

Not even a large courier company reaches the essential level: its standard score, 150, stays below the 200 threshold.

Find your level and maturity score in a few minutes. The calculator opens with the “Postal and courier services” sector already selected; you choose the size and answer 12 questions.

Calculate the level for courier services

Where the risk lies at a courier company

A courier company works only as long as parcel tracking works. The assessment usually covers:

Royal Mail, January 2023

On 10 January 2023, a LockBit ransomware attack hit Royal Mail’s systems for international mail. For about six weeks, the company could not send parcels and letters abroad normally. The attackers demanded 80 million dollars and later published part of the stolen data.

Royal Mail did not stop entirely: domestic deliveries continued. The attack hit a single system, the one for exports, but without it part of the business stood still. For NIS2, this means knowing which system supports which service and having a continuity plan for each.

The second risk is your name. Fake messages such as “your parcel is waiting for a fee to be paid” use courier companies’ names. A domain protected with SPF, DKIM and DMARC and a clear page on what official messages look like reduce the number of people fooled.

What comes next

How TRU helps

Courier companies have many users in the field and many integrations with clients. We start with:

Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.

Frequently asked questions

Is a road haulage company covered as a courier?

Only if it provides courier services. Road haulage does not appear as such in the NIS2 annexes; we explain the difference in the guide to NIS2 in transport.

Is an online shop that delivers its own parcels covered?

As a rule, no. Delivering your own products is part of the retail activity and is not a postal service for others.

What if the company has exactly 50 employees?

It usually becomes a medium-sized company, so an important entity, with a standard score of 100 and the important level. Also check turnover, balance sheet and partner or linked companies, under Law No. 346/2004.

Sources

OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · TechCrunch, the attack on Royal Mail, 23 February 2023.