← EuroFirewalls

NIS2 and firewalls: what an appliance really covers

NIS2 is the EU directive that raises the cybersecurity baseline for essential and important entities across 18 sectors. This page explains what it requires, and is deliberately explicit about the limits: a firewall contributes to some of the required measures, but no product makes an organisation compliant.

Who it applies to

NIS2 covers 18 sectors and over 80 types of public and private entity, split into essential and important entities according to sector and size. Companies with more than 50 employees or EUR 10 million turnover can fall in scope, so it reaches well beyond large operators. Obligations are proportionate: the directive requires account to be taken of the entity’s exposure to risk, its size, and the likelihood and severity of incidents.

Where transposition stands

NIS2 had to be transposed into national law by 17 October 2024. Several Member States missed that deadline: in July 2026 the European Commission referred France, Spain, Ireland and the Netherlands to the Court of Justice of the EU for failing to complete transposition. Italy and Germany, by contrast, already apply national law with binding deadlines. Check the rules of the country where your organisation operates, and treat national law — not the directive alone — as the operative reference.

The ten measures of Article 21

Article 21(2) sets out a minimum list, based on an all-hazards approach:

  1. policies on risk analysis and information system security
  2. incident handling
  3. business continuity, such as backup management and disaster recovery, and crisis management
  4. supply chain security, including the relationship with direct suppliers and service providers
  5. security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure
  6. policies and procedures to assess the effectiveness of the risk-management measures
  7. basic cyber hygiene practices and cybersecurity training
  8. policies and procedures on the use of cryptography and, where appropriate, encryption
  9. human resources security, access control policies and asset management
  10. multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communications

What a Netgate appliance actually covers

An honest reading, measure by measure. “Partial” means the appliance provides evidence or a technical building block, not the whole requirement.

Article 21 measureContributionWhat the appliance does
(i) human resources security, access control policies and asset managementDirectNetwork segmentation, per-zone rule sets and VLANs enforce access control between systems. It does not cover the human-resources side of the same measure.
(h) policies and procedures on the use of cryptography and, where appropriate, encryptionDirectIPsec, WireGuard and OpenVPN protect data in transit between sites and remote users. Encryption at rest stays with your systems.
(j) multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communicationsDirectMulti-factor authentication on remote access and administrative logins.
(b) incident handlingPartialLogging, detection and export to a SIEM give you the evidence and the timeline. The handling process, the roles and the notification itself remain yours.
(c) business continuity, such as backup management and disaster recovery, and crisis managementPartialHigh-availability pairs and configuration backups keep connectivity up. They are not a backup or disaster-recovery plan for your data.
(e) security in acquisition, development and maintenance of systems, including vulnerability handling and disclosurePartialMaintained pfSense Plus releases and security updates, for the appliance itself only.
(d) supply chain security, including the relationship with direct suppliers and service providersPartialGenuine hardware bought through a traceable channel with support is one input to supplier assessment, not a supply chain policy.
(a) policies on risk analysis and information system securityNoneRisk analysis is an organisational exercise. No product performs it for you.
(f) policies and procedures to assess the effectiveness of the risk-management measuresNoneAssessing whether your measures work requires audits, tests and metrics.
(g) basic cyber hygiene practices and cybersecurity trainingNoneTraining and cyber hygiene concern people, not equipment.

What no firewall can do for you

These obligations fall on the organisation and its management, and cannot be bought:

Penalties

For breaches of Articles 21 or 23, essential entities face administrative fines of a maximum of at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher; for important entities the ceiling is EUR 7 million or 1.4%.

How FRAOS helps

We supply genuine Netgate appliances with pfSense Plus and help you cover the technical measures above: segmentation, encrypted connectivity, multi-factor authentication on remote access, logging that produces usable evidence, and high-availability configurations. Tell us your sector, size and current setup and we will tell you honestly which part of the problem the hardware solves and which part it does not.

Request a quote or a technical assessment

Sources

Last verified: 2026-08-19. This page is information, not legal advice. Legislation and deadlines change: verify your position with the competent authority or a qualified advisor.