Postal and courier services are the first sector in Annex 2, the one for critical sectors. Medium-sized and large companies are important entities; none is essential by default. The standard score is 50 for a small organisation, 100 for a medium-sized one and 150 for a large one, so both reach the important level, with 133 controls.
Who is covered by NIS2 in postal and courier services
The sector comes from the NIS2 Directive, which refers to the definition of a postal service provider in EU postal legislation. It covers:
- postal service providers, meaning companies that clear, sort, transport and deliver postal items;
- courier service providers, including those delivering parcels for online shops;
- any medium-sized or large provider, whether or not it has a universal service obligation.
Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.
Which assurance level applies
| Organisation size | Entity type | Standard risk score | Assurance level | At self-assessment |
|---|---|---|---|---|
| Small or micro | outside NIS2, except for the cases in the law | 50 | basic | 34 controls, threshold 2.5 |
| Medium | important | 100 | important | 133 controls, threshold 3 |
| Large | important | 150 | important | 133 controls, threshold 3 |
The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.
Not even a large courier company reaches the essential level: its standard score, 150, stays below the 200 threshold.
Find your level and maturity score in a few minutes. The calculator opens with the “Postal and courier services” sector already selected; you choose the size and answer 12 questions.
Calculate the level for courier servicesWhere the risk lies at a courier company
A courier company works only as long as parcel tracking works. The assessment usually covers:
- the parcel tracking system and integrations with online shops, through APIs;
- automated sorting centres and scanners;
- courier apps and handheld terminals;
- the network of lockers and pick-up points;
- cash on delivery, invoicing and settlement with clients;
- SMS and email notifications to recipients, whose templates are often copied in phishing.
Royal Mail, January 2023
On 10 January 2023, a LockBit ransomware attack hit Royal Mail’s systems for international mail. For about six weeks, the company could not send parcels and letters abroad normally. The attackers demanded 80 million dollars and later published part of the stolen data.
Royal Mail did not stop entirely: domestic deliveries continued. The attack hit a single system, the one for exports, but without it part of the business stood still. For NIS2, this means knowing which system supports which service and having a continuity plan for each.
The second risk is your name. Fake messages such as “your parcel is waiting for a fee to be paid” use courier companies’ names. A domain protected with SPF, DKIM and DMARC and a clear page on what official messages look like reduce the number of people fooled.
What comes next
- notification to DNSC, within 30 days from the date OUG 155/2024 becomes applicable to the organisation; the first DNSC fine sanctioned exactly this deadline;
- the risk-level assessment, within 60 days of the DNSC decision;
- the self-assessment, within the following 60 days, on the controls of your level;
- the audit, carried out by a DNSC-certified auditor.
How TRU helps
Courier companies have many users in the field and many integrations with clients. We start with:
- PenTest, external, on the APIs and portals used by clients and couriers, with reports within 48 hours of the scan being completed;
- SOC 24/7/365, because sorting and deliveries run at night and at weekends too;
- Proton Workspace, for team and dispatch email, encrypted in transit and at rest, with Proton Pass for shared passwords.
Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.
Frequently asked questions
Is a road haulage company covered as a courier?
Only if it provides courier services. Road haulage does not appear as such in the NIS2 annexes; we explain the difference in the guide to NIS2 in transport.
Is an online shop that delivers its own parcels covered?
As a rule, no. Delivering your own products is part of the retail activity and is not a postal service for others.
What if the company has exactly 50 employees?
It usually becomes a medium-sized company, so an important entity, with a standard score of 100 and the important level. Also check turnover, balance sheet and partner or linked companies, under Law No. 346/2004.
Sources
OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · TechCrunch, the attack on Royal Mail, 23 February 2023.