Wireless Communications Blog
NIS2 and UK Industrial Wireless: What Radio Operators Need to Know
The NIS2 Directive (EU) 2022/2555 came into force in October 2024 for EU member states. The UK is no longer bound by NIS2 directly — but if your organisation operates in the EU, supplies EU clients, or operates within a regulated supply chain, NIS2 requirements will reach you regardless of your registered address. The UK’s own Cyber Security and Resilience Bill, currently progressing through Parliament, is explicitly aligned with NIS2 and is expected to bring equivalent obligations into UK law.
For most organisations thinking about NIS2, the conversation starts with IT infrastructure: firewalls, endpoint protection, incident response. Radio communications — including licensed two-way radio networks, TETRA systems, SCADA radio telemetry links, and PoC platforms — are rarely on the initial list. They should be.
Where radio networks fall under NIS2
NIS2 applies to essential and important entities across sectors including energy, transport, water, digital infrastructure, manufacturing, and public administration. If your organisation falls into one of these categories, your obligation under NIS2 is to implement appropriate technical and organisational measures to manage cybersecurity risks across your network and information systems.
The phrase “network and information systems” is broader than it might initially appear. It includes any system used to process, store, or transmit information that underpins essential services. Industrial radio networks commonly do exactly this — they carry operational voice communications, link SCADA and telemetry systems, and provide control communications for safety-critical processes.
Unencrypted radio communications
Many industrial and utility radio systems — particularly older DMR deployments — operate without encryption enabled. Unencrypted radio traffic can be monitored with commercially available equipment. Where that traffic includes operational instructions, process telemetry, or safety communications, this is a vulnerability that NIS2 risk management obligations require you to address.
SCADA and telemetry radio links
Radio-linked SCADA and telemetry systems are a common point of exposure in industrial environments. These systems frequently predate modern cybersecurity practice, operate on legacy protocols, and sit outside the scope of conventional IT security assessments. Under NIS2, they are in scope if they form part of the operational infrastructure for an essential or important service.
Supply chain and third-party radio access
NIS2 Article 21 includes supply chain security as an explicit obligation. If contractors, maintenance teams, or third-party organisations have access to your radio network — even temporarily — this access represents a supply chain risk that requires assessment and management. Radio network access controls, talkgroup permissions, and third-party handset management are all in scope.
Business continuity and radio resilience
NIS2 requires business continuity planning that covers disruption to network and information systems. If your organisation relies on radio communications for operational continuity — as most utilities, transport operators, and industrial facilities do — your business continuity plan needs to address what happens when that radio system is compromised, degraded, or unavailable.
The UK position
The UK government’s Cyber Security and Resilience Bill was introduced in 2025. It is designed to update the UK’s existing NIS Regulations (2018) to broadly align with NIS2, expanding the scope of regulated entities and strengthening requirements around risk management, incident reporting, and supply chain security.
UK organisations that dismissed NIS2 as irrelevant post-Brexit should note: the Resilience Bill is moving through Parliament, the direction of travel is clear, and organisations in the sectors covered by NIS2 will face equivalent UK obligations. The practical gap between NIS2 compliance and UK Resilience Bill compliance is narrow.
What a NIS2-aligned radio assessment covers
An industrial radio assessment for NIS2 compliance is not a spectrum survey or a signal strength check. It is a structured review of the radio network as a communications conduit — applying the zone and conduit methodology from IEC 62443 to the radio environment.
A complete assessment covers:
- Encryption status — are transmissions encrypted, and is that encryption correctly configured and verified throughout the system?
- Access control — who can transmit and receive on each talkgroup or channel, and how is that access managed and revoked?
- SCADA and telemetry radio links — identification and assessment of all radio-linked supervisory and control systems
- Zone boundary mapping — which radio communications cross security zone boundaries, and what controls are in place at those boundaries?
- Third-party and contractor access — documentation and control of all external access to the radio network
- Business continuity provisions — what happens to operational communications if the radio system is degraded or unavailable?
The output is a documented assessment with findings, risk ratings, and remediation recommendations — suitable for inclusion in your NIS2 or Resilience Bill compliance documentation.
What this means in practice
If your organisation is an essential or important entity under NIS2 or the UK Cyber Security and Resilience Bill, and you operate a licensed radio network, the question is not whether the radio system is in scope. It is whether you have assessed it, documented the findings, and addressed the risks.
Most organisations have not done this. Most radio systems in industrial environments have never received a security assessment. The gap between current state and NIS2 obligation is real — and in most cases, straightforward to close with the right assessment framework.
Yesway provides IEC 62443-aligned wireless security assessments for industrial and regulated environments. If you need to address radio network security as part of NIS2 or UK Resilience Bill compliance, the IEC 62443 wireless audit service is the right starting point.
Craig Miles is a wireless communications engineer with 30 years of RF and radio systems experience, including aerospace satellite systems at Airbus Defence & Space. He is a PGCE Level 7 qualified engineer and 2023 TEDx speaker. Yesway Communications provides manufacturer-independent wireless security assessment and radio consultancy services.
