NIS2 requires covered entities to take appropriate and proportionate technical, operational and organisational measures to manage cybersecurity risk and reduce incident impact. The directive does not prescribe one product or claim that a physically isolated network creates compliance. Organisations must select measures based on their risks, size, exposure and potential consequences.
Physical isolation can contribute to that programme where continuous connectivity creates avoidable exposure for an important system. Its role should be documented alongside incident handling, business continuity, access control, asset management, supply-chain security, vulnerability management and measures that protect data and communications.
Key takeaways
The short version
- NIS2 is a risk-based governance obligation, not a checklist solved by one device.
- Physical isolation may support risk reduction, containment and resilience for selected assets.
- The organisation needs evidence linking the control to assessed risks and operating procedures.
- National law and competent-authority guidance determine an entity's specific obligations.
Start with the NIS2 risk-management requirement
Article 21 calls for appropriate and proportionate measures and lists areas including risk analysis, incident handling, business continuity, supply-chain security, secure acquisition and maintenance, effectiveness assessment, cyber hygiene, cryptography, human resources, access control and asset management. The measures should address both prevention and the impact of incidents.
The first question is therefore not whether to buy an isolation device. It is which essential services, systems and dependencies could be disrupted, which threats are credible, and what combination of controls reduces that risk to an appropriate level.
Where physical isolation may contribute
A disconnected network path may reduce exposure of critical administration, backup, OT or recovery assets. It may help contain lateral movement across that specific boundary and preserve a system that does not require constant communication. Controlled windows can also improve access governance by recording authoriser, purpose and duration.
These outcomes can support broader risk-management, incident-impact and business-continuity objectives. The mapping must remain precise: the control affects network reachability. It does not by itself manage suppliers, train staff, patch systems, report incidents or prove that recovery works.
Build evidence, not just architecture diagrams
Document the risk assessment that led to the boundary, the systems covered, normal and authorised states, responsible roles, approval method and monitoring. Keep installation records and current network diagrams. Record tests showing that the physical path opens and closes as intended and that emergency procedures work.
Review access events and exceptions. Evidence should connect policy to operation: who requested connectivity, why it was needed, how long it remained active, and whether the verified state matched the request. This also supports internal control-effectiveness reviews.
Keep the measure proportionate and usable
A physical control may be proportionate for a high-consequence asset with a low-frequency access need and unnecessary for an ordinary service that communicates continuously. Consider safety, service continuity, cost, maintenance and the consequences of control failure.
ENISA technical guidance provides practical implementation support for sectors covered by the NIS2 Implementing Regulation, but it is not a substitute for national requirements. Organisations should consult their competent authority and legal advisers for scope and compliance interpretation.
Integrate isolation into the security programme
Combine physical isolation with asset ownership, named access, segmentation, endpoint hardening, secure updates, monitoring and incident procedures. Include the device and its supplier in lifecycle and supply-chain management. Define vulnerability response and replacement processes for the control itself.
AIRGAPNET can provide a hardware-enforced Ethernet state and independent cellular authorisation path for selected use cases. Whether it is appropriate, sufficient for a particular risk or relevant to a legal obligation must be decided within the organisation's complete risk-management process.
Create a repeatable review cycle
Review the control when the protected service, network topology, supplier relationship or threat assessment changes, and at a defined interval even when no major change is reported. Examine access records, failed states, emergency use, bypasses, vulnerability information and results from continuity exercises.
Assign findings to named owners and track them through the organisation's risk process. If the protected system begins to require continuous data exchange, physical disconnection may no longer be proportionate; if consequences or exposure increase, the surrounding controls may need strengthening.
Management reporting should describe the risk outcome in plain language: which service is protected, what communication is prevented, how often access occurs and what tests support confidence. That evidence is more useful than treating the device count as a compliance metric.
Retain the review decision together with accepted residual risk and the next review date. This makes the measure traceable when auditors, incident responders or new service owners need to understand why the boundary exists.
Decision checklist
Questions to resolve before implementation
- Confirm entity scope and applicable national NIS2 implementation requirements.
- Link the protected boundary to a documented service and risk scenario.
- Record ownership, approval, monitoring and emergency procedures.
- Test the physical state and the effectiveness of surrounding controls.
- Include the device in asset, supplier and vulnerability management.
- Review proportionality when systems, threats or business dependencies change.
Common questions
Questions teams ask first
Does physical isolation make an organisation NIS2 compliant?
No. NIS2 requires a broad set of proportionate technical, operational and organisational measures. Physical isolation may address a selected risk but cannot establish compliance by itself.
Does NIS2 require air-gapped networks?
The directive sets risk-management outcomes rather than prescribing a universal air-gap requirement. A covered entity should select controls based on its assessed risks and applicable national guidance.
What evidence should be retained?
Useful evidence includes the risk decision, architecture, asset ownership, procedures, approvals, connection-state logs, test results, exceptions and periodic effectiveness reviews. Exact obligations depend on the entity and jurisdiction.
Official references