October 2024 came and went. That was the transposition deadline for NIS2 — the EU’s Network and Information Security Directive 2 — and for most of Europe’s solar sector, it passed without triggering the procurement review it should have.
I have spent the past several months working with solar operators and O&M teams across the EU on how they manage, store, and govern operational data. The pattern I keep encountering is consistent: technically capable organisations, competently run, operating against a regulatory framework they either haven’t mapped to their software stack, or have mapped in a way that stops at GDPR and treats NIS2 as something for their legal team to monitor.
That is the wrong posture. And for organisations operating grid-connected solar portfolios in the EU, it is becoming an increasingly expensive one.
NIS2 does not sit beside your O&M operations. It sits inside them.
The NIS2 Directive classifies electricity operators under Annex I — the essential entities tier. This is not the softer “important entities” classification. Essential entities face proactive supervision by national competent authorities. NCAs can audit, inspect, and assess compliance without an incident trigger. They do not wait for something to go wrong before they knock on the door.
For solar operators — grid-connected IPPs, utilities with solar exposure, independent O&M service providers managing assets on behalf of clients — Annex I classification is not a grey area. The Directive defines electricity generators as essential entities. The energy sector regulators being established across EU member states have this classification on their mandate from day one.
The fines under Article 34 follow the GDPR model: up to €10 million or 2% of total worldwide annual turnover for essential entities, whichever is higher. The enforcement architecture was deliberately built to the same scale, staffed by regulators who have spent six years learning how to apply it.
Enforcement timelines vary by country. Several member states missed the October 2024 transposition deadline. Germany, Romania, Spain, Italy, Poland — each market where significant solar capacity is installed is at a different stage of building out its NCA framework. The UK is advancing parallel obligations through the Cyber Security and Resilience Bill.
The staggered transposition does not create a compliance exemption. It creates a window. What I have seen is that most O&M teams are not using that window for gap assessment. They are treating the delay as confirmation that NIS2 is not their problem yet.
It is their problem now.
The question nobody is asking in O&M procurement
Article 21 of NIS2 defines the risk management measures essential entities must implement. Supply chain security — specifically, the cybersecurity practices of direct suppliers and service providers — is one of them, under Article 21(2)(d).
This is the provision that most solar O&M procurement teams have not yet connected to their software stack.
The O&M platforms, CMMS tools, and field service portals that European solar operators rely on are, in the majority of cases, cloud-based SaaS products. The operational data they handle — SCADA integrations, work order logs, performance records, fault histories, contractor activity — lives in vendor-managed cloud environments. Not in the operator’s own infrastructure. Not under the operator’s own governance. In a third-party cloud account that the operator accesses through a portal but does not control.
That architecture has been the default for ten years. It was an efficient choice when the regulatory requirements around data governance in O&M were largely informal. That period is over.
Under NIS2, the question “where does your operational data reside?” is not a technical preference. It is a compliance variable with three distinct consequences.
First: data held outside your IT governance perimeter means your supply chain risk assessment is determined by your vendor’s security posture, not your own. You have a 24-hour incident reporting obligation to your national competent authority. If the breach originates with your O&M platform vendor, the completeness of your incident report depends on their cooperation speed. That is not a contractual gap you can close with a better SLA. It is an architectural one.
Second: EU data residency is not the same as EU legal governance. A SaaS vendor operating in an EU data centre under a non-EU corporate structure can be subject to legal access rights from outside the EU that override your data processing agreements. The GDPR DPAs that most organisations have in place were not written with NIS2’s supply chain security obligations in mind. They are not automatically sufficient.
Third: NIS2 NCAs investigating an incident can require access to logs, configurations, and data flows. If those are held in a third-party SaaS environment, access is mediated by your vendor. That is a governance gap that does not disappear because your vendor holds ISO 27001 certification.
The digital transformation conversation is incomplete
The solar industry has done serious work over the past five years building the case for operational digitalisation — better data, faster response times, reduced manual effort, automated reporting. That case is correct.
But it has been built against an efficiency argument without a full compliance architecture. NIS2 has introduced a compliance dimension into that architecture that most of the tools currently in use were not designed to satisfy.
I am not arguing that the tools are wrong. I am arguing that the question being asked at procurement stage has been too narrow. “Does this platform give us the operational visibility we need?” is a necessary question. “Does the data infrastructure underpinning this platform hold up under NIS2 Article 21 scrutiny?” is a required one.
The organisations that will navigate the enforcement window most cleanly are not the ones with the most sophisticated O&M platforms. They are the ones that have asked — and answered — where their operational data is, who controls it, and what their NIS2 supply chain assessment says about every vendor in their software stack.
IEC 62446 — the international standard for photovoltaic system documentation — is increasingly referenced alongside NIS2 in EU grid-operator guidance as the documentation baseline for solar assets. Data traceability, authentication records, and audit trails are converging as a single compliance surface. Most O&M teams are managing them as separate operational concerns, if they are managing them at all.
A direct question to IT Managers and compliance professionals in solar
If you are responsible for IT governance or compliance at a solar operator or O&M service provider anywhere in the EU or UK, I am curious about one specific thing: has your organisation formally mapped its NIS2 scope classification, and if so, what did the supply chain security assessment of your current software stack reveal?
I am not asking to sell anything. I am asking because the answers I have encountered in conversations across the sector suggest the assessment has not been done at all, or has been done in a way that stops at GDPR and does not reach the operational software layer. If your experience is different — if your organisation has worked through this rigorously — I would like to hear how you approached it.
The enforcement clock is running regardless of whether the transposition map is complete in your jurisdiction.
What are you finding hardest to answer?
This article was originally published on LinkedIn. A fuller technical analysis — covering NIS2 Article 21 obligations, transposition status by market, and the six compliance questions O&M teams need to answer — is available at fivehundred.solar.




