NIS2 and firewalls: what an appliance really covers
NIS2 is the EU directive that raises the cybersecurity baseline for essential and important entities across 18 sectors. This page explains what it requires, and is deliberately explicit about the limits: a firewall contributes to some of the required measures, but no product makes an organisation compliant.
Who it applies to
NIS2 covers 18 sectors and over 80 types of public and private entity, split into essential and important entities according to sector and size. Companies with more than 50 employees or EUR 10 million turnover can fall in scope, so it reaches well beyond large operators. Obligations are proportionate: the directive requires account to be taken of the entity’s exposure to risk, its size, and the likelihood and severity of incidents.
Where transposition stands
NIS2 had to be transposed into national law by 17 October 2024. Several Member States missed that deadline: in July 2026 the European Commission referred France, Spain, Ireland and the Netherlands to the Court of Justice of the EU for failing to complete transposition. Italy and Germany, by contrast, already apply national law with binding deadlines. Check the rules of the country where your organisation operates, and treat national law — not the directive alone — as the operative reference.
The ten measures of Article 21
Article 21(2) sets out a minimum list, based on an all-hazards approach:
- policies on risk analysis and information system security
- incident handling
- business continuity, such as backup management and disaster recovery, and crisis management
- supply chain security, including the relationship with direct suppliers and service providers
- security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure
- policies and procedures to assess the effectiveness of the risk-management measures
- basic cyber hygiene practices and cybersecurity training
- policies and procedures on the use of cryptography and, where appropriate, encryption
- human resources security, access control policies and asset management
- multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communications
What a Netgate appliance actually covers
An honest reading, measure by measure. “Partial” means the appliance provides evidence or a technical building block, not the whole requirement.
| Article 21 measure | Contribution | What the appliance does |
|---|---|---|
| (i) human resources security, access control policies and asset management | Direct | Network segmentation, per-zone rule sets and VLANs enforce access control between systems. It does not cover the human-resources side of the same measure. |
| (h) policies and procedures on the use of cryptography and, where appropriate, encryption | Direct | IPsec, WireGuard and OpenVPN protect data in transit between sites and remote users. Encryption at rest stays with your systems. |
| (j) multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communications | Direct | Multi-factor authentication on remote access and administrative logins. |
| (b) incident handling | Partial | Logging, detection and export to a SIEM give you the evidence and the timeline. The handling process, the roles and the notification itself remain yours. |
| (c) business continuity, such as backup management and disaster recovery, and crisis management | Partial | High-availability pairs and configuration backups keep connectivity up. They are not a backup or disaster-recovery plan for your data. |
| (e) security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure | Partial | Maintained pfSense Plus releases and security updates, for the appliance itself only. |
| (d) supply chain security, including the relationship with direct suppliers and service providers | Partial | Genuine hardware bought through a traceable channel with support is one input to supplier assessment, not a supply chain policy. |
| (a) policies on risk analysis and information system security | None | Risk analysis is an organisational exercise. No product performs it for you. |
| (f) policies and procedures to assess the effectiveness of the risk-management measures | None | Assessing whether your measures work requires audits, tests and metrics. |
| (g) basic cyber hygiene practices and cybersecurity training | None | Training and cyber hygiene concern people, not equipment. |
What no firewall can do for you
These obligations fall on the organisation and its management, and cannot be bought:
- Registering with the national competent authority within the applicable deadline.
- Reporting significant incidents on the statutory timeline: an early warning within 24 hours, a notification within 72 hours and a final report within one month.
- Governance: management bodies must approve and oversee the risk-management measures and can be held personally liable.
- Risk analysis, staff training and periodic assessment of the effectiveness of the measures.
Penalties
For breaches of Articles 21 or 23, essential entities face administrative fines of a maximum of at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher; for important entities the ceiling is EUR 7 million or 1.4%.
How FRAOS helps
We supply genuine Netgate appliances with pfSense Plus and help you cover the technical measures above: segmentation, encrypted connectivity, multi-factor authentication on remote access, logging that produces usable evidence, and high-availability configurations. Tell us your sector, size and current setup and we will tell you honestly which part of the problem the hardware solves and which part it does not.
Request a quote or a technical assessment