Air, rail, road, and water transport operators sit in NIS2 Annex I — large operators as essential entities, medium-sized as important. Supply chain risk in transport spans operational technology providers (signalling, traffic management), payment and ticketing platforms, and the increasingly cloud-native fleet/asset management systems. Transport often has the longest supplier replacement cycles of any regulated sector.
Supply chain assurance for transport
Air, rail, water, and road transport sit in NIS2 Annex I — large operators and infrastructure managers as essential entities, medium-sized ones as important. The scope covers the operational core of the sector: air carriers and airport operators, railway undertakings and infrastructure managers, shipping companies and port operators — and on the road side, traffic-management authorities and intelligent-transport-systems operators, rather than general hauliers. Like the other Annex I sectors, the obligations are the full Article 21 set, with supply chain security among them.
Transport arrives at NIS2 with a deeply embedded safety and inspection culture — authorisations, audits, incident investigation are normal life. What is new is the domain: the same evidentiary discipline now has to cover the cybersecurity posture of the vendors behind signalling, traffic management, ticketing, and fleet systems, most of which were procured on decade-scale cycles that predate any cybersecurity procurement requirement.
The sector-specific pressure point is the lifespan of operational systems. Signalling and interlocking, terminal operating systems, traffic-management platforms, and on-board systems are procured for decades; their vendors were selected long before supplier cybersecurity assurance existed as a discipline, and legacy contracts rarely contain evidence, notification, or audit-access clauses. Bringing that installed base into an assessed supplier register — without any leverage of a fresh procurement — is the distinctive transport problem.
NIS2 also lands on top of existing transport-specific regimes: aviation security rules, rail safety authorisation, maritime security frameworks. Cybersecurity evidence becomes one more layer in an already regulated file — which is an advantage if the supplier-assurance programme is structured to produce audit-shaped artefacts, and a burden if it lives in spreadsheets alongside everything else.
The critical-supplier list mixes very different animals: OT vendors (signalling, traffic and terminal management) with long lifecycles and privileged access to safety-relevant systems; maintenance contractors whose technicians touch those systems on site; ticketing, booking, and payment platforms processing customer data at volume; and the cloud-native telematics and fleet/asset-management systems that increasingly run daily operations. Each type needs a different evidence shape — one questionnaire does not fit an interlocking vendor and a ticketing SaaS.
Interdependence is the other pattern: ports, airports, and rail networks are ecosystems where one operator’s supplier is another operator’s dependency, and where a shared platform’s incident propagates across every entity built on it. Sub-processor visibility — who actually sits behind the platform you depend on — matters unusually much here.
Vittnor — Supply Chain Assurance for the mid-market — matches the sector’s existing audit culture: a maintained supplier register, per-supplier evidence with reviewer attribution, and a timestamped decision trace produce the same shape of file transport inspectors already expect for safety — now for supplier cybersecurity. Questionnaires are tailored per vendor type, so the interlocking vendor, the maintenance contractor, and the ticketing platform each get an evidence request that fits what they are.
For the legacy estate, review cycles put every supplier file on a calendar and reviewers flag material changes — vendor M&A, certificate expiry, sub-processor additions — prompting out-of-cycle re-reviews; automated trigger firing ships in V1.2 (2027). For operators without a dedicated security team, the one-off NIS2 Supplier Exposure Assessment maps the landscape first; the platform then carries the ongoing programme.
Where are you with NIS2 supplier work in transport?
Two ways to find out fast — a five-minute readiness check, or a practitioner-walked exposure picture in two to three weeks.