Back to Blog|Security

NIS2 and Network Security: What Companies Must Do About Their VPN Now

April 5, 2026
Timo WevelsiepTimo Wevelsiep
birdhost

NIS2 and Network Security: What Companies Must Do About Their VPN Now

NIS2 mandates encryption, access control, and MFA for VPN infrastructure. Why legacy VPNs fail to meet the requirements and how Zero Trust with NetBird closes the compliance gap.

birdhost.de Blog

Content notice: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, pricing, versions, licensing models and external content are subject to change. Please verify the information independently, especially before making business-critical or security-relevant decisions. This article does not constitute individual professional, legal or tax advice.

The EU NIS2 Directive (Directive 2022/2555) is reshaping cybersecurity requirements across all 27 member states. Each country must transpose the directive into national law, and enforcement is now underway. In Germany, the NIS2 Implementation Act (NIS2UmsuCG) entered into force on December 6, 2025 — with no transition period. Around 30,000 German companies alone must now comply with ten mandatory security measures under the German implementation (§ 30 BSIG — the Federal Office for Information Security Act). The BSI (German Federal Cyber Security Authority) registration deadline passed on March 6, 2026. Result: only 38.5 percent of affected companies registered on time.

The picture is similar across Europe. Whether your national regulator is the BSI (Germany), ANSSI (France), ACN (Italy), or CCB (Belgium) — the core requirements are the same, because they stem from the same EU directive.

What many IT leaders overlook: at least three of the ten mandatory NIS2 measures directly affect VPN and network infrastructure. If you are still running Sophos SSL VPN, OpenVPN with shared credentials, or a Fortinet gateway, you very likely have an open compliance gap.

This article explains the specific network security requirements under NIS2, why legacy VPN architectures fail to meet them, and how a Zero Trust approach with NetBird closes the compliance gap.

Also worth reading: Sophos VPN Alternative 2026 · OpenVPN Alternative 2026 · Setting Up a Business Network for Remote Employees


Is My Company Affected? The Quick Check

NIS2 applies across all EU member states. Whether you are based in Germany, France, the Netherlands, or any other EU country — or even outside the EU but serving EU customers — the directive may apply to you.

Scope depends on two factors: sector and company size.

Company size: Companies with 50+ employees or €10M+ annual revenue fall under NIS2 if they operate in a regulated sector.

Sectors (selection): Energy, transport, healthcare, finance, water, digital infrastructure, IT service providers (managed service providers, managed security service providers), manufacturing, mechanical engineering, chemicals, food production, waste management, research, postal and courier services.

A critical detail: many mid-sized companies are affected for the first time — particularly IT service providers, manufacturers, and food producers. If you are a supplier to an affected company, you can be pulled into scope through the supply chain requirements.

Each EU member state has its own national authority and registration process. In Germany, this is the BSI; in France, ANSSI; in Italy, ACN. The obligations are substantively the same — only the local implementation details differ.

What Happens If You Don't Comply?

The consequences are severe. For essential entities, fines can reach €10 million or 2% of global annual turnover. For important entities, the ceiling is €7 million or 1.4% of turnover.

The most critical point: NIS2 establishes personal liability for management. Under the German implementation (§ 38 BSIG), managing directors must formally approve risk management measures, actively oversee their implementation, and personally attend cybersecurity training. This duty cannot be delegated to a CISO or IT director. A liability waiver by the company is legally excluded. Similar management accountability provisions exist in other member states' implementations.

The Ten Mandatory NIS2 Measures

The NIS2 Directive defines ten categories of security measures that affected companies must implement. The German implementation (§ 30 BSIG) closely aligns with ISO 27001 — companies already certified cover approximately 70 to 80 percent of the requirements.

The ten areas at a glance:

  1. Risk analysis and security policies
  2. Incident handling
  3. Business continuity, backup management, and crisis management
  4. Supply chain security
  5. Secure procurement, development, and maintenance of IT systems
  6. Assessment of the effectiveness of security measures
  7. Cyber hygiene and training
  8. Cryptography and encryption
  9. Access control and identity management
  10. Multi-factor authentication and secure communications

Measures 8, 9, and 10 directly affect network and VPN infrastructure. This is precisely where many companies have a problem.

What NIS2 Concretely Means for VPN Infrastructure

Measure 8: Cryptography and Encryption

NIS2 requires policies and procedures for the use of cryptographic methods. The German implementation (§ 30 para. 2 no. 8 BSIG) specifies this concretely:

  • Encryption of all data in transit is mandatory
  • Algorithms must reflect the current state of the art
  • Deprecated methods such as SHA-1 or RSA with fewer than 2048 bits are no longer acceptable
  • A cryptography inventory must document which methods are used where

What this means for your VPN: WireGuard meets this requirement natively. The protocol uses exclusively modern cryptography: ChaCha20 for symmetric encryption, Curve25519 for key exchange, Poly1305 for authentication, and BLAKE2s as hash function. There are no configurable cipher suites — misconfiguration is impossible.

OpenVPN, by contrast, uses TLS/SSL with configurable cipher suites. In practice, we regularly encounter installations with outdated configurations: weak ciphers, expired certificates, disabled Perfect Forward Secrecy. Each of these misconfigurations constitutes a NIS2 violation.

Sophos SSL VPN is built on OpenVPN and inherits the same issues. After firmware updates, cipher mismatches regularly break existing VPN connections. The result: admins delay updates out of fear of regressions — further degrading the security posture.

Measure 9: Access Control

NIS2 requires policies for access control to systems and asset management. The principle of least privilege must be consistently enforced and demonstrably documented.

What this means for your VPN: Traditional VPN architectures grant access to the entire internal network after successful authentication. An employee connects via the VPN tunnel and can reach everything — file servers, ERP, databases, printers. This flat network access model is the exact opposite of least privilege and therefore a NIS2 violation.

NetBird solves this with identity-based access policies. Admins define granularly which user group may access which resource — including protocol restrictions (TCP, UDP, ICMP) and port ranges. An accountant sees the ERP system but not the development server. An external contractor sees exactly the one machine they need to maintain — and nothing else.

Additionally, NetBird offers Posture Checks: only devices meeting defined security requirements (current OS, running security software, correct NetBird version) receive access at all. This is Zero Trust in practice — and exactly what NIS2 demands.

Measure 10: Multi-Factor Authentication and Secure Communications

NIS2 requires the use of multi-factor authentication or continuous authentication, as well as secured communications within the organization.

What this means for your VPN: VPN access without MFA is no longer compliant. This affects every Sophos installation still relying on username and password, every OpenVPN server with simple certificate authentication, and every Fortinet appliance without activated FortiToken.

NetBird solves MFA through native SSO integration. Authentication runs through the company's identity provider — whether Azure AD, Google Workspace, Okta, or Keycloak. If the IdP enforces MFA (and it should), this automatically extends to VPN access. No separate token management, no additional infrastructure.

Simultaneously, NetBird fulfills the requirement for secure communications: all connections are end-to-end encrypted, directly between peers. There is no central gateway where traffic is decrypted and re-encrypted — unlike Twingate or traditional SSL VPN solutions where the connector acts as a man-in-the-middle.

Additional NIS2-Relevant VPN Aspects

Supply Chain Security

NIS2 requires the assessment of cybersecurity across suppliers and service providers. If your VPN provider is a US cloud service, immediate questions arise: Where are metadata processed? Who has access to connection data? Is the code auditable?

Tailscale runs its entire control plane as proprietary cloud software. Twingate likewise. For regulated companies — healthcare, financial sector, public administration — this is often a disqualifying factor.

NetBird is 100 percent open source. The entire codebase — client, management server, signal server, relay — is publicly available and auditable on GitHub. With birdhost, infrastructure runs in ISO 27001 and SOC 2 certified data centers across 8 regions worldwide (certifications held by the data center operators). No metadata leaves the region you select. The supply chain is transparent and verifiable.

Effectiveness Assessment

NIS2 requires regular assessments of the effectiveness of security measures. This means: logging, auditability, and demonstrable control.

NetBird logs every connection, every policy change, every login — including timestamp, source IP, and associated identity. These are exactly the records that regulators want to see during audits.

Traditional VPN solutions often provide only rudimentary logging: connection establishment and teardown, perhaps transferred data volume. Who accessed which resource? Which policy was active at that time? With Sophos, OpenVPN, or Fortinet, this is not verifiable without additional tools.

Why Legacy VPNs Have a Structural NIS2 Problem

The issue is not that Sophos, OpenVPN, or Fortinet are inherently insecure. The problem is architectural: these solutions were built for a world where "inside" was trusted and "outside" was hostile. NIS2 demands the opposite — Zero Trust.

Central gateway as single point of failure: With Sophos, Fortinet, and OpenVPN, all VPN traffic flows through a central server. This server simultaneously acts as performance bottleneck, preferred attack target, and single point of failure. If it goes down, the entire network is offline.

Open ports as attack surface: SSL VPN portals must be reachable from the internet. This reachability makes the appliance a target. The Fortinet CVEs of recent months clearly demonstrate what happens when SSL VPN gateways are compromised: admin accounts are created, VPN configurations exported, networks infiltrated. The situation becomes fully untenable once the appliance no longer receives patches at all: support for the Cisco ASA 5506-X, 5508-X, and 5516-X ends on August 31, 2026, and every vulnerability discovered after that date remains permanently unpatched.

Vendor dependency as concentration risk: When an appliance ecosystem tips over, it does not hit one company but tens of thousands at once. The FortiBleed leak affecting more than 73,000 FortiGate credentials makes that risk measurable and puts it squarely into the supply chain assessment NIS2 demands.

No identity-aware access control: Traditional VPNs authenticate the user at the gate and then grant broad network access. Once you are in, you are in. Granular, identity-based access control with device posture checks must be retrofitted — if it is even possible.

NetBird inverts this architecture. No open ports: connections are coordinated via NAT traversal, data flows directly between peers. No central decryption: WireGuard tunnels are end-to-end. No flat network access: every access is verified by identity and logged.

Checklist: NIS2-Compliant VPN Infrastructure

Review your current VPN solution against these points. Each item corresponds to a specific NIS2 requirement:

Cryptography:

  • Are only current encryption methods in use (no SHA-1, no RSA < 2048 bit)?
  • Is a cryptography inventory documented?
  • Are cipher suites configured so that misconfiguration is impossible?

Access control:

  • Is the least privilege principle enforced — or do VPN users get access to the entire network?
  • Are access rules identity-based and granularly definable?
  • Are there device posture checks (OS version, antivirus status)?

MFA:

  • Is multi-factor authentication activated for all VPN connections?
  • Does authentication run through a central identity provider with MFA enforcement?

Logging and auditability:

  • Are all connections, policy changes, and logins recorded?
  • Can you demonstrate who accessed which resource and when?

Supply chain and data sovereignty:

  • Is the VPN product's source code auditable?
  • Are metadata and connection data processed within your required jurisdiction?
  • Is there a data processing agreement (DPA) with the VPN provider?

If more than two points are open, there is an urgent need for action.

How birdhost Covers the NIS2 Requirements

birdhost offers managed NetBird hosting, a fully managed Zero Trust VPN solution designed to meet NIS2 requirements.

Cryptography: WireGuard with ChaCha20, Curve25519, Poly1305, BLAKE2s. No configurable cipher suites, no misconfiguration possible. State of the art, fully documentable.

Access control: Identity-based access policies with groups, protocol restrictions, and posture checks. Least privilege out of the box. Since version 0.65, with integrated Reverse Proxy for secure service exposure without port forwarding.

MFA: Native SSO integration with Azure AD, Google Workspace, Okta, Keycloak, and Authentik. MFA enforcement via the identity provider. Automatic on-/offboarding via SCIM.

Logging: Complete audit trail for connections, policy changes, and authentication events.

Data sovereignty: Infrastructure hosted in ISO 27001 and SOC 2 certified data centers across 8 regions worldwide (certifications held by the data center operators). GDPR-compliant. DPA available. 100 percent open source — fully auditable.

Cost: Flat rate from €99.90 per month. No per-user fees. Unlimited users and devices included. 7-day free trial via the merkaio self-service portal.

Conclusion: NIS2 Makes Zero Trust Mandatory

NIS2 is not an abstract compliance exercise. The directive demands concrete technical measures — state-of-the-art encryption, identity-based access control, multi-factor authentication, comprehensive logging. Legacy gateway VPNs fail to meet these requirements by design.

The good news: the transition does not have to be disruptive. NetBird can run alongside an existing VPN solution. Employees can be migrated step by step while the legacy VPN remains active as a fallback. With birdhost as a managed service, the operational overhead for setup, monitoring, and updates is eliminated.

Companies that act now are not just closing a compliance gap — they are getting a faster, more secure, and easier-to-manage network.


Further reading:

Sources:

Frequently Asked Questions

Which NIS2 measures affect VPN infrastructure?
At least three of the ten mandatory measures under the EU NIS2 Directive directly affect VPN infrastructure: cryptography and encryption, access control and identity management, and multi-factor authentication with secure communications. Supply chain security and effectiveness assessment requirements are also relevant.
Is my company affected by NIS2?
Companies with 50+ employees or €10M+ annual revenue operating in one of the 18 regulated sectors (including energy, IT service providers, manufacturing, healthcare, finance) fall under NIS2. Suppliers to affected companies can also be pulled into scope through supply chain requirements. This applies across all EU member states.
What are the penalties for NIS2 non-compliance?
For essential entities, fines up to €10 million or 2% of global annual turnover. For important entities, up to €7 million or 1.4% of turnover. Critically, management is personally liable — this obligation cannot be delegated to a CISO or IT director.
Why do legacy VPNs fail to meet NIS2 requirements?
Traditional gateway VPNs (Sophos, OpenVPN, Fortinet) grant access to the entire network after authentication (flat network access), often use outdated cryptography, lack identity-based access control, and have the VPN gateway as a single point of failure and attack target.
How does NetBird help with NIS2 compliance?
NetBird meets NIS2 requirements natively: state-of-the-art WireGuard encryption, identity-based access policies with least privilege, MFA via SSO integration, full audit logging, and 100% open-source code for supply chain transparency.
Can I run NetBird alongside my existing VPN?
Yes. NetBird runs alongside Sophos, OpenVPN, Fortinet, or any other VPN solution. Employees can be migrated gradually while the legacy VPN remains active as a fallback.
When did NIS2 take effect in the EU?
The EU NIS2 Directive (2022/2555) required member states to transpose it into national law by October 17, 2024. Implementation timelines vary by country — Germany's NIS2 Implementation Act (NIS2UmsuCG) entered into force on December 6, 2025 with no transition period. Companies in all EU member states must comply with their national implementation now.
What does a NIS2-compliant VPN solution cost with birdhost?
birdhost offers Managed NetBird Hosting from €99.90 per month as a flat rate — no per-user fees, unlimited users and devices. 7-day free trial available.
Timo Wevelsiep

Written by

Timo Wevelsiep

Founder, merkaio

Founder of merkaio. Managed NetBird VPN hosting. Focused on network security, zero-trust architecture and scalable VPN infrastructure.

LinkedIn

Request Managed NetBird

We operate your dedicated NetBird instance including hosting, updates, monitoring and support. Tell us how many users, sites or devices you want to connect. We'll get back to you within 24 hours with a suitable proposal.

Timo Wevelsiep

Your Contact

Timo Wevelsiep

Founder, merkaio

Discuss your project with Timo

By submitting, you agree to our Privacy Policy.