What NIS2 actually requires
Directive (EU) 2022/2555 — NIS2 — obliges essential and important entities across eighteen sectors to take "appropriate and proportionate technical, operational and organisational measures" to manage the risks posed to the security of network and information systems. Article 21(2) states that these measures shall be based on an all-hazards approach that protects both the systems and the physical environment of those systems from incidents.
Recital 79 spells out what the physical environment means in practice: protection against unauthorised physical access, damage and interference with information and information processing facilities — explicitly referencing the ISO/IEC 27000 series for physical and environmental security. A covert listening or video device planted in a boardroom, a server room, or an executive office is precisely such unauthorised physical interference.
Article 21(2)(j) goes further and names "secured voice, video and text communications" as a measure entities should apply where appropriate. Voice communications are not secured while an unauthorised transmitter is live in the room, whatever encryption is applied to the call itself.
Where eavesdropping risk enters your Article 21 obligations
Four of the minimum measures in Article 21(2) intersect directly with technical surveillance risk. Point (a) requires policies on risk analysis — a risk analysis that has never considered covert surveillance of the spaces where credentials, incident response plans and strategic decisions are spoken aloud is incomplete. Point (d) requires supply chain security: contractor and vendor access to your premises is the most common route by which devices are introduced.
Point (f) requires policies to assess the effectiveness of your measures — which is what a periodic technical surveillance countermeasures inspection is: an effectiveness test of your physical information security. Point (j) covers secured communications, which presumes the rooms those communications happen in are themselves clean.
None of this requires reading the word TSCM into the directive. It requires taking the all-hazards language at face value: if a threat to the confidentiality of your information exists through the physical environment, Article 21 expects you to have assessed it and, where proportionate, to have a control in place.
Management liability and penalties
Article 20 makes the management bodies of essential and important entities responsible for approving cybersecurity risk-management measures and overseeing their implementation — and provides that they can be held liable for infringements. This is personal accountability, not just corporate exposure.
The fines are substantial: for essential entities, up to at least €10,000,000 or 2% of total worldwide annual turnover, whichever is higher; for important entities, up to at least €7,000,000 or 1.4%. Member State transpositions may go further. A board that has never asked whether the rooms it makes decisions in are technically clean has an oversight gap it cannot easily defend after an incident.
What a defensible TSCM control looks like under NIS2
Start with a documented technical surveillance risk assessment covering the spaces where sensitive information is discussed or displayed: boardrooms, executive offices, incident response rooms, server and network rooms, and any space regularly used for regulated decision-making. Record threat sources, plausible attack routes, and current controls in the same risk register that carries your other Article 21 analysis.
Then set a proportionate inspection cadence with defined trigger events — before board meetings where market-sensitive matters are decided, after fit-outs or office moves, after contractor access to sensitive areas, and on suspicion of a leak. Keep dated records of each inspection, its scope, method and findings. Under NIS2 supervision, the record is the control: an undocumented sweep does not exist.
Finally, connect findings to your incident handling obligation. A discovered device is a security incident with reporting consequences under Article 23, and your response plan should say who is informed, how evidence is preserved, and how the significance assessment is made.