NIS2 and Technical Surveillance Risk

NIS2 requires essential and important entities to protect the physical environment of their information systems on an all-hazards basis. Here is where covert surveillance and eavesdropping risk fits Article 21, what management bodies are personally accountable for, and what a defensible TSCM control looks like.

Framework: European UnionLast reviewed: 2026-09-03

What NIS2 actually requires

Directive (EU) 2022/2555 — NIS2 — obliges essential and important entities across eighteen sectors to take "appropriate and proportionate technical, operational and organisational measures" to manage the risks posed to the security of network and information systems. Article 21(2) states that these measures shall be based on an all-hazards approach that protects both the systems and the physical environment of those systems from incidents.

Recital 79 spells out what the physical environment means in practice: protection against unauthorised physical access, damage and interference with information and information processing facilities — explicitly referencing the ISO/IEC 27000 series for physical and environmental security. A covert listening or video device planted in a boardroom, a server room, or an executive office is precisely such unauthorised physical interference.

Article 21(2)(j) goes further and names "secured voice, video and text communications" as a measure entities should apply where appropriate. Voice communications are not secured while an unauthorised transmitter is live in the room, whatever encryption is applied to the call itself.

Where eavesdropping risk enters your Article 21 obligations

Four of the minimum measures in Article 21(2) intersect directly with technical surveillance risk. Point (a) requires policies on risk analysis — a risk analysis that has never considered covert surveillance of the spaces where credentials, incident response plans and strategic decisions are spoken aloud is incomplete. Point (d) requires supply chain security: contractor and vendor access to your premises is the most common route by which devices are introduced.

Point (f) requires policies to assess the effectiveness of your measures — which is what a periodic technical surveillance countermeasures inspection is: an effectiveness test of your physical information security. Point (j) covers secured communications, which presumes the rooms those communications happen in are themselves clean.

None of this requires reading the word TSCM into the directive. It requires taking the all-hazards language at face value: if a threat to the confidentiality of your information exists through the physical environment, Article 21 expects you to have assessed it and, where proportionate, to have a control in place.

Management liability and penalties

Article 20 makes the management bodies of essential and important entities responsible for approving cybersecurity risk-management measures and overseeing their implementation — and provides that they can be held liable for infringements. This is personal accountability, not just corporate exposure.

The fines are substantial: for essential entities, up to at least €10,000,000 or 2% of total worldwide annual turnover, whichever is higher; for important entities, up to at least €7,000,000 or 1.4%. Member State transpositions may go further. A board that has never asked whether the rooms it makes decisions in are technically clean has an oversight gap it cannot easily defend after an incident.

What a defensible TSCM control looks like under NIS2

Start with a documented technical surveillance risk assessment covering the spaces where sensitive information is discussed or displayed: boardrooms, executive offices, incident response rooms, server and network rooms, and any space regularly used for regulated decision-making. Record threat sources, plausible attack routes, and current controls in the same risk register that carries your other Article 21 analysis.

Then set a proportionate inspection cadence with defined trigger events — before board meetings where market-sensitive matters are decided, after fit-outs or office moves, after contractor access to sensitive areas, and on suspicion of a leak. Keep dated records of each inspection, its scope, method and findings. Under NIS2 supervision, the record is the control: an undocumented sweep does not exist.

Finally, connect findings to your incident handling obligation. A discovered device is a security incident with reporting consequences under Article 23, and your response plan should say who is informed, how evidence is preserved, and how the significance assessment is made.

Primary sources

This guidance is general information, not legal advice. Regulatory obligations depend on your entity classification, jurisdiction and facts — confirm specifics with your counsel or compliance function.

Common questions

Does NIS2 explicitly require TSCM?
No — the directive never uses the term. But Article 21(2) requires an all-hazards approach protecting the physical environment of network and information systems, recital 79 spells out unauthorised physical access and interference, and Article 21(2)(j) names secured voice and video communications. If covert surveillance is a plausible threat to your entity, ignoring it leaves a visible gap in the risk analysis Article 21(2)(a) requires.
We are an important entity, not essential. Does this still apply?
Yes. Articles 20 and 21 apply to both categories; the differences are supervisory intensity and fine ceilings — up to at least €7,000,000 or 1.4% of worldwide turnover for important entities, versus €10,000,000 or 2% for essential entities. Management liability under Article 20 applies to both.
What evidence would a supervisor expect to see?
The same evidence pattern as every other Article 21 measure: the risk documented in your analysis, a proportionate written control (policy, scoped spaces, cadence, triggers), records that the control operated, and integration with incident handling for the case where something is found.

Scope an assessment

A short conversation establishes scope and a fixed price. Assessments run across the UK, Europe and the US.

Speak to a specialist