Cybersecurity regulations are evolving rapidly across the globe, and few have had a greater impact on organisations operating in Europe than the Network and Information Security Directive 2 (NIS2).
Replacing the original NIS Directive, NIS2 significantly expands both the scope and accountability of cybersecurity across the European Union. More organisations are now required to implement mature cybersecurity programs, management bodies must approve and oversee cybersecurity risk-management measures and may be held accountable for failures to meet applicable obligations under national law, and regulators have substantially increased penalties for non-compliance.
While NIS2 is not a product certification or technology standard, it requires organisations to implement appropriate technical, operational, and organisational cybersecurity measures. For many organisations, removable media and portable storage remain one of the largest and most overlooked security gaps.
This is where DataLocker provides significant value.
Through enterprise-grade encrypted storage devices, centralized device management, certified data erasure, and comprehensive audit capabilities, DataLocker helps organisations implement many of the technical controls expected under NIS2’s cybersecurity risk management requirements.
What is NIS2?
The Network and Information Security Directive 2 (Directive (EU) 2022/2555) is the European Union’s updated cybersecurity legislation designed to improve cyber resilience across critical sectors.
The directive dramatically expands the number of organisations required to maintain robust cybersecurity programs while strengthening governance, incident reporting, supply chain security, and executive accountability.
Unlike many regulations that prescribe specific technologies, NIS2 is intentionally risk-based.
Organisations must implement cybersecurity controls appropriate to their:
- Size
- Industry
- Threat landscape
- Operational risk
- Criticality of services
Rather than asking whether an organisation has deployed a particular product, regulators evaluate whether the organisation has implemented effective cybersecurity risk management measures that reduce the likelihood and impact of cyber incidents. Article 21 establishes ten broad categories of cybersecurity risk management measures that organisations must address.
Who Does NIS2 Apply To?
NIS2 significantly broadens the scope of the original directive, bringing thousands of additional organisations under its cybersecurity requirements. Rather than focusing primarily on operators of essential services, NIS2 now applies to a much wider range of medium and large organisations across critical and highly important sectors. The Directive covers specific essential and important sectors, including healthcare, energy, certain manufacturing activities, transport, digital infrastructure, cloud and managed service providers, data centers, telecommunications, public administration, waste management, postal and courier services, food production, and chemical manufacturing. Exact scope depends on the entity’s size, activity, applicable exceptions, sector-specific legislation, and national transposition rules. As a result, many organisations that were previously outside the scope of EU cybersecurity regulation are now expected to implement robust cybersecurity risk management practices, strengthen operational resilience, and demonstrate compliance with the directive’s requirements.
Why Removable Media Matters Under NIS2
When organisations think about NIS2 compliance, they often focus on:
- Firewalls
- Endpoint Detection and Response (EDR)
- Multi-factor authentication
- Identity management
- Security awareness training
Yet removable media remains one of the easiest methods for attackers to:
- Introduce malware
- Exfiltrate sensitive information
- Circumvent network protections
- Bypass cloud security controls
- Move laterally inside secure environments
USB devices continue to be heavily used within healthcare, manufacturing, government, defense, critical infrastructure, engineering, industrial control systems, and air-gapped environments.
Because of this, organisations cannot ignore removable media as part of their overall cybersecurity strategy.
How DataLocker Supports NIS2 Compliance
It is important to understand that DataLocker does not “certify” NIS2 compliance.
Instead, DataLocker provides technical controls that help organisations address several cybersecurity objectives relevant to Article 21.
Below is a breakdown of how DataLocker aligns with each major area.
1. Risk Management
NIS2 Requirement
Organisations must implement risk analysis and information security policies that identify and reduce cybersecurity risks.
How DataLocker Helps
DataLocker reduces one of the largest unmanaged risks inside enterprise environments:
- Uncontrolled USB devices
- Unauthorised removable media
- Shadow IT storage
- Consumer flash drives
SafeConsole enables organisations to:
- Standardize approved encrypted devices
- Enforce organisation-wide security policies
- Require hardware encryption
- Disable insecure functionality
- Restrict unauthorised removable media
Rather than relying on employee discretion, organisations can centrally enforce policy across thousands of devices.
2. Incident Prevention and Detection
NIS2 emphasizes minimizing the likelihood and impact of cybersecurity incidents.
SafeConsole provides:
- Device inventory
- Usage auditing
- Device location reporting
- Policy compliance monitoring
- Device health status
- Remote device actions
Administrators gain visibility into removable media activity that would otherwise remain invisible.
When a device is lost or stolen, organisations can remotely:
- Disable devices
- Lock devices
- Reset credentials
- Destroy encryption keys
- Recover devices
These capabilities significantly reduce incident impact.
3. Supply Chain Security
Supply chain attacks are one of NIS2’s largest focus areas.
Organisations are expected to evaluate the security posture of vendors and technology providers.
DataLocker supports this through:
- Trusted hardware: Enterprise-grade encrypted devices
- Secure manufacturing: Transparent supply chain
- Independent technical assurance: FIPS validation on applicable products
Independent technical validation and enterprise-focused product controls can support technology-selection decisions, while remaining only one part of an organisation’s broader supply-chain risk-management process.
4. Access Control
Unauthorised access remains one of the primary causes of security breaches.
DataLocker devices support strong authentication options depending on the device model, deployment, and configuration, including:
- Complex passwords
- Hardware-based encryption
- Smart card authentication
- CAC/PIV authentication
- YubiKey PIV
- Windows Hello
- Touch ID
- Multi-factor authentication
Unlike software encryption, credentials never expose encryption keys to the host operating system.
Authentication occurs within the secure hardware itself.
5. Encryption and Data Protection
While NIS2 does not explicitly mandate encryption everywhere, Article 21 specifically references the use of cryptography where appropriate.
This is one of DataLocker’s strongest areas.
Features include:
- AES 256-bit hardware encryption
- Secure cryptographic processors
- Hardware-based encryption
- Automatic encryption
- Tamper-resistant architecture
- Password retry protection
- Brute-force defense
- Secure key storage
Even if a device is physically stolen, the data remains protected.
6. Asset Visibility and Device Management
One of the biggest cybersecurity challenges is simply knowing what devices exist.
SafeConsole provides centralized visibility across enterprise deployments, including:
- Device inventory
- Serial numbers
- Firmware versions
- Capacity
- Assigned user
- Policy compliance
- Device status
- Audit history
This supports asset management initiatives while reducing unmanaged endpoints.
7. Audit Logging and Compliance Reporting
NIS2 requires organisations to demonstrate that cybersecurity controls are actually operating.
SafeConsole maintains detailed audit records including:
- Device activity
- Authentication events
- Policy changes
- Administrative actions
- Compliance status
- Remote commands
- Password resets
Administrators can generate reports that simplify both internal security reviews and external compliance audits.
8. Certified Data Erasure
Although NIS2 does not prescribe a specific data-erasure technology, secure disposal and verifiable lifecycle controls can support broader risk-management, asset-management, and information-protection objectives.
When devices reach end-of-life, organisations should ensure sensitive information is securely removed in line with their policies and applicable requirements.
DataLocker’s Certified Data Erasure solution provides:
- Cryptographic erasure
- Certified destruction reports
- Immutable audit evidence
- Blockchain-backed verification through SafeLedger
- PDF destruction certificates
This allows organisations to demonstrate that sensitive data has been securely removed before reuse, resale, or disposal.
Mapping DataLocker Capabilities to NIS2 Article 21
| NIS2 Requirement | DataLocker Capability |
| Risk management | Encrypted USB standardization, SafeConsole policies |
| Incident handling | Remote lock, remote disable, device recovery, audit logs |
| Business continuity | Secure portable storage, centralized management |
| Supply chain security | Trusted hardware, independent security validation on applicable products |
| Secure acquisition and maintenance | Managed firmware, centralized policy management |
| Security assessments | Audit logs, compliance reporting |
| Cyber hygiene | Enforced password policies, device controls |
| Cryptography | AES-256 hardware encryption, secure key management |
| Human resources security | User authentication, policy enforcement |
| Access control | Smart cards, CAC/PIV, MFA, Windows Hello, Touch ID |
| Asset management | Managed-device inventory and lifecycle visibility |
| Removable media control | SafeConsole |
Beyond Compliance: Building Cyber Resilience
One of the most important aspects of NIS2 is that it shifts the conversation away from simple regulatory compliance toward operational cyber resilience.
The objective is not merely passing an audit.
It is reducing the likelihood that cyber incidents occur and minimizing their impact when they do.
DataLocker helps organisations accomplish this by:
- Reducing attack surface associated with removable media
- Standardizing secure hardware across the enterprise
- Providing centralized visibility into device usage
- Enforcing consistent security policies
- Preventing unauthorised data movement
- Protecting sensitive information with hardware encryption
- Simplifying compliance reporting
- Supporting secure device lifecycle management
When combined with broader cybersecurity initiatives such as identity management, endpoint protection, vulnerability management, and security awareness training, DataLocker becomes an important component of a defense-in-depth strategy aligned with the goals of NIS2.
NIS2 represents one of the most significant cybersecurity regulatory changes introduced by the European Union in recent years. Organizations can no longer rely on ad hoc security controls or unmanaged technology to protect critical information systems. Instead, they must implement measurable, risk-based cybersecurity practices that span governance, technical controls, operational resilience, and supply chain security. Article 21’s cybersecurity risk management measures provide the framework, while technologies like DataLocker’s encrypted storage, SafeConsole centralized management, and Certified Data Erasure help organisations implement many of the practical controls needed to reduce removable media risk. Although no single product delivers NIS2 compliance on its own, DataLocker enables organisations to address several of the directive’s most important technical objectives, strengthening cyber resilience while simplifying the path toward regulatory readiness.