What NIS2 actually demands from your communication stack

iconSebastián Glonek
icon5 min read
iconSeptember 18, 2026
Article hero image
NIS2 now covers your email, chat and documents. What the directive demands from communication systems, and how to meet it with one platform.

The grace period is over. With national transpositions of the EU's NIS2 directive now in force — including the Czech cyber security act, whose one-year adjustment window closed in November 2025 — thousands of organizations are discovering that their obligations aren't abstract. They're audited, and they include the tools your team uses to communicate every day.

Who's in scope

NIS2 reaches far beyond critical infrastructure. Organizations across energy, transport, health, digital services, manufacturing, public administration and more fall into "higher" or "lower" obligation regimes based on sector and size. If you're reading this because a customer, auditor or authority asked about your security measures — you're likely in scope.

The part most companies miss: communication is covered

NIS2 isn't only about firewalls and endpoints. The directive's requirements explicitly touch electronic communication — which means your email, team chat, shared documents and video meetings are part of the audited surface. For most organizations, that's the system holding the most sensitive data and the least documentation.

That creates a dual challenge:

Your CISO needs strategic assurance. Evidence of risk management: recognized certifications, business continuity plans, supply-chain documentation they can attach to their own audit file.

Your IT admin needs technical proof. Concrete controls on the communication layer itself: email authentication, encryption, access management, logging.

Most stacks answer neither well — because the communication layer is five tools from five vendors, and nobody owns the whole picture.

How IceWarp helps you meet NIS2 requirements

Certifications you can cite in your own documentation.

IceWarp holds ISO/IEC 27001 certification and an independent SOC 2 Type II audit report. Under NIS2's supply-chain due diligence requirements, your provider's certifications become part of your evidence — we'll provide the documentation your auditors need.

Data residency you control.

Unlike other cloud services, IceWarp stores your data only in the datacenter location you choose, ensuring full compliance with your legal requirements. Run IceWarp in our European data centers (Czech Republic, Germany, Italy) — with EU-hosted data staying permanently in the EEA — or self-host on your own infrastructure, inside your jurisdiction entirely.

Technical controls, built in:

Email authentication: DMARC, SPF, DKIM, plus DANE (TLSA) and DNSSEC support

Encrypted transport (STARTTLS) and S/MIME message signing

Two-factor authentication and role-based access control

Login IP restrictions per user group

Archiving and full audit logs

Anti-virus and anti-spam included in every plan — no separate security product to procure

One platform instead of a vendor chain.

Every additional tool in your stack is another supplier to assess under NIS2. Consolidating communication into one platform shrinks your supply-chain documentation burden instead of growing it.

The checklist: 8 questions to ask your current provider

1. Where is our communication data physically stored — and can we choose? 2. Can you provide ISO 27001 certification and SOC 2 reports for our audit file? 3. Is email authentication (DMARC/SPF/DKIM) enforced and monitored? 4. What encryption protects messages in transit and at rest? 5. How granular are access controls — per user, per group, per network? 6. What audit logs exist, and how long are they retained? 7. How are security incidents detected, handled and reported? 8. If we need to leave, can we export everything — and how fast?

If your current setup can't answer these in one sitting, that gap is exactly what an auditor will find.

Get ahead of the audit

IceWarp helps organizations meet NIS2 requirements with certified processes, European data residency and technical controls built into one platform — not bolted onto five.

FAQ

Does NIS2 apply to our organization? If you operate in a covered sector (energy, transport, health, digital services, manufacturing, public administration and others) above national size thresholds, likely yes — under either the higher or lower obligation regime. Your national transposition defines the details, in Czechia, that's the cyber security act in force since November 2024.

Does NIS2 really cover email? Yes — the directive's requirements explicitly include electronic communication systems. Email, team chat and shared documents are part of the audited surface.

What evidence will auditors ask for? Risk-management measures, incident-handling processes, and supply-chain security — including the certifications and controls of the platforms you depend on. Your provider's ISO 27001 certification and SOC 2 report become part of your documentation.

Does our provider's certification count toward our compliance? It counts as supply-chain evidence — you can document that a critical supplier operates under audited, certified processes. NIS2 compliance itself remains your organization's obligation, certified providers make meeting it substantially easier.

Cloud or self-hosted for NIS2? Both work. EU cloud with permanent EEA residency satisfies residency expectations for most organizations, self-hosted gives you maximum control when jurisdiction is non-negotiable.