Space is one of the sectors introduced by NIS2 and has the narrowest definition in Annex 1 to OUG 155/2024: only operators of ground-based infrastructure supporting the provision of space-based services are covered. The standard score is 87.5 for a small organisation, 175 for a medium-sized one and 262.5 for a large one.
Who is covered by NIS2 in the space sector
Annex 1 to OUG 155/2024 takes over the definition in the NIS2 Directive: operators of ground-based infrastructure, owned, managed and operated by Member States or by private parties, that support the provision of space-based services, excluding providers of public electronic communications networks. In practice, this usually means operators of:
- ground stations that control satellites and receive their data;
- mission operations and flight control centres;
- ground-based infrastructure for satellite navigation, Earth observation and satellite communications;
- platforms that process and distribute satellite data, when they are part of the space service.
Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.
Which assurance level applies
| Organisation size | Entity type | Standard risk score | Assurance level | At self-assessment |
|---|---|---|---|---|
| Small or micro | outside NIS2, except for the cases in the law | 87.5 | basic | 34 controls, threshold 2.5 |
| Medium | important | 175 | important | 133 controls, threshold 3 |
| Large | essential | 262.5 | essential | 218 controls, threshold 3.5 and at least 3 in every category |
The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.
Find your level and maturity score in a few minutes. The calculator opens with the “Space” sector already selected; you choose the size and answer 12 questions.
Calculate the level for the space sectorWhich systems are assessed in the ground segment
The ground segment looks like an ordinary IT network with a few highly specialised systems. It usually includes:
- satellite command and control systems and the encryption keys of the command links;
- antennas, modems and radio-frequency equipment at ground stations;
- the networks linking ground stations to operations centres, including the management segment;
- platforms that process and distribute data to clients;
- time synchronisation and positioning, on which other systems depend;
- access by equipment suppliers and partners in other countries.
KA-SAT, 24 February 2022
On the morning of Russia’s invasion of Ukraine, an attack on the KA-SAT satellite network knocked out tens of thousands of customer satellite modems across Europe, including most of the active ones in Ukraine. The attackers did not touch the satellite. They got in through a misconfigured VPN appliance, reached the network’s management segment and sent the modems legitimate management commands that overwrote their memory.
The effects were felt far beyond satellite communications: in Germany, around 5,800 wind turbines lost remote monitoring because they used these modems.
For NIS2, the lesson is that the ground segment is defended like any IT network: remote access with multi-factor authentication, the management network separated from the rest, configurations checked regularly and a plan for bringing customer equipment back online at scale.
What comes next
- notification to DNSC, within 30 days from the date OUG 155/2024 becomes applicable to the organisation; the first DNSC fine sanctioned exactly this deadline;
- the risk-level assessment, within 60 days of the DNSC decision;
- the self-assessment, within the following 60 days, on the controls of your level;
- the audit, carried out by a DNSC-certified auditor.
How TRU helps
Space sector operators work with international partners and specialised equipment. We start with:
- PenTest, external, on remote access points and VPNs, with reports within 48 hours of the scan being completed; radio-frequency equipment is tested separately;
- SOC 24/7/365, for continuous detection, including the hours when partners in other time zones are working;
- Proton Workspace, for project documents and communication with partners, encrypted in transit and at rest, with the encryption keys under your control.
Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.
Frequently asked questions
Is a company selling satellite imagery covered?
Not if it only resells it. Operators of the ground-based infrastructure supporting space services are covered. If the company runs its own receiving and processing station, analyse the classification carefully.
Where does a satellite communications operator fit?
Under digital infrastructure, as a provider of public electronic communications networks or services. The space sector definition explicitly excludes it.
What level does a medium-sized operator have?
The important level: the standard score is 175, between 100 and 199. You apply 133 controls, with a threshold of 3 at self-assessment.
Sources
OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · Viasat, overview of the KA-SAT network cyber attack.