Space is one of the sectors introduced by NIS2 and has the narrowest definition in Annex 1 to OUG 155/2024: only operators of ground-based infrastructure supporting the provision of space-based services are covered. The standard score is 87.5 for a small organisation, 175 for a medium-sized one and 262.5 for a large one.

Who is covered by NIS2 in the space sector

Annex 1 to OUG 155/2024 takes over the definition in the NIS2 Directive: operators of ground-based infrastructure, owned, managed and operated by Member States or by private parties, that support the provision of space-based services, excluding providers of public electronic communications networks. In practice, this usually means operators of:

Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.

Which assurance level applies

Organisation sizeEntity typeStandard risk scoreAssurance levelAt self-assessment
Small or microoutside NIS2, except for the cases in the law87.5basic34 controls, threshold 2.5
Mediumimportant175important133 controls, threshold 3
Largeessential262.5essential218 controls, threshold 3.5 and at least 3 in every category

The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.

Find your level and maturity score in a few minutes. The calculator opens with the “Space” sector already selected; you choose the size and answer 12 questions.

Calculate the level for the space sector

Which systems are assessed in the ground segment

The ground segment looks like an ordinary IT network with a few highly specialised systems. It usually includes:

KA-SAT, 24 February 2022

On the morning of Russia’s invasion of Ukraine, an attack on the KA-SAT satellite network knocked out tens of thousands of customer satellite modems across Europe, including most of the active ones in Ukraine. The attackers did not touch the satellite. They got in through a misconfigured VPN appliance, reached the network’s management segment and sent the modems legitimate management commands that overwrote their memory.

The effects were felt far beyond satellite communications: in Germany, around 5,800 wind turbines lost remote monitoring because they used these modems.

For NIS2, the lesson is that the ground segment is defended like any IT network: remote access with multi-factor authentication, the management network separated from the rest, configurations checked regularly and a plan for bringing customer equipment back online at scale.

What comes next

How TRU helps

Space sector operators work with international partners and specialised equipment. We start with:

Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.

Frequently asked questions

Is a company selling satellite imagery covered?

Not if it only resells it. Operators of the ground-based infrastructure supporting space services are covered. If the company runs its own receiving and processing station, analyse the classification carefully.

Where does a satellite communications operator fit?

Under digital infrastructure, as a provider of public electronic communications networks or services. The space sector definition explicitly excludes it.

What level does a medium-sized operator have?

The important level: the standard score is 175, between 100 and 199. You apply 133 controls, with a threshold of 3 at self-assessment.

Sources

OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · Viasat, overview of the KA-SAT network cyber attack.