What We're Bringing to GreenCities 2026
On September 15 and 16, we’ll be at GreenCities 2026 in Málaga as a technological partner of Vodafone IoT Spain. We will present our NIS2Orchestrator solution, designed to help secure and ensure compliance with the NIS2 Directive across IoT ecosystems operating on GDSP, Vodafone’s IoT platform.
What is NIS2?
The NIS2 Directive is the new European cybersecurity directive (EU Directive 2022/2555), replacing the original NIS Directive of 2016. Its goal is straightforward: to raise and harmonize the level of security for networks and information systems across the EU, especially in critical sectors and public administration.
Compared with the previous directive NIS2 brings two major changes: it significantly broadens the scope of organizations required to comply and introduces much stricter requirements and penalties.
What NIS2 Requires
The scope is broad. In Italy, where the directive was transposed into national law via Legislative Decree 138/2024, it is estimated to affect more than 20,000 organizations, while the figure rises to around 350,000 across Europe. This includes organizations with more than 50 employees or annual revenues exceeding €10 million that operate in one of the 18 critical sectors, ranging from energy and transportation to water, waste management, and digital infrastructure. The directive also applies to public administrations, regions, metropolitan cities, and provincial capitals.
What does NIS2 require in practice? Organizations must implement risk management measures, access controls, supply chain security, and timely incident reporting: an initial alert within 24 hours, a report within 72 hours, and a final report within one month. These reporting requirements took effect on January 15, 2026. Responsibility also rests directly with top management.
The deadlines are approaching: basic security measures must be in place by October 31, 2026, In Italy, the National Cybersecurity Agency (ACN) will be responsible for carrying out inspections to assess compliance. Organizations that fail to comply may face fines of up to €10 million or 2% of their global annual revenue.
One detail that is often overlooked: NIS2 also extends to the supply chain. Organizations that supply regulated entities, including device manufacturers, may also be required to demonstrate compliance with the relevant security requirements.
Why This Is a Practical Problem for Smart Cities
A "smart” city is made up of cameras, smart meters, streetlights, charging stations, micromobility vehicles, and connected waste bins. Thousands of devices, often from different manufacturers, are deployed across the city, many of which cannot run security software on the device itself. They do, however, have one thing in common: they connect through IoT SIM cards.
This is where NIS2 creates a practical challenge: how do you bring a fleet of devices, on which you can’t install anything, into compliance, one by one? Traditional security solutions,which rely on software installed on the endpoint, cannot always be deployed on these types of devices. But there is another point of intervention: the network.
Traffic from these devices passes through IoT SIM cards, making the network a strategic point at which it can be monitored and protected—without installing software on every individual device.
The Solution: NIS2Orchestrator, Network-Level Compliance
NIS2Orchestrator (NIS2O) operates precisely there: across the IoT SIM and the connectivity that connects the device to the network. Not on the individual device, but upstream, where all its traffic passes through. It’s agentless, meaning no software installation or modification is required on the device itself. In practical terms, this means:
• Segmenting and isolating traffic according to the Zero-Trust principle, so that a compromised device cannot spread threats to others;
• Geofencing and IMEI blocking to prevent SIMs and devices from operating outside their designated perimeter;
• Whitelists, navigation filters, and bandwidth-limiting options to block abuse and anomalous traffic before iit can escalate into a DDoS attack;
• Immutable logs and full traceability: providing the documented evidence required by NIS2 when an incident needs to be reported;
Network segmentation, access control, and traceability are among the measures required by Article 21 of the directive. NIS2O applies these controls at the SIM and network levels, across the entire IoT ecosystem, without directly intervening on every connected device.
We Look Forward to Seeing You in Málaga!
At GreenCities, we’ll be demonstrating all of this live, together with Vodafone IoT Spain: how an urban IoT ecosystem can become more secure and compliant without rebuilding the infrastructure or modifying devices that are already deployed.
If you work in smart cities, cybersecurity, or compliance, come and visit us.