Space suppliers: the four regimes you actually sit under

A company selling into satellite operators sits under four separate regimes at once: NIS2, the proposed EU Space Act, national space authorisation, and whatever the prime contractor writes into the contract. Only one of them will reach you this year.

Daniel Grigorovich
Daniel Grigorovich
Founder · 11 Sept 2026 · 8 min read
SpaceNIS2Supply chain
Space suppliers: the four regimes you actually sit under

Who should read this: a company under two hundred and fifty people building subsystems, payload or ground segment software, test equipment or engineering services for satellite operators, launch providers or space agencies, that has started seeing security clauses appear in tenders.

Space is the only sector where a supplier can be simultaneously out of scope of the directive everyone is talking about, inside a regulation that does not exist yet, licensed under a national law nobody outside the country has read, and already failing a customer’s security review. All four are true at once and they arrive in a specific order.

Four regimes, not one

Most guidance treats this as a NIS2 question. It is not. A space supplier sits under four separate obligations with different authors, different timelines and different enforcement.

  1. NIS2, in force now, transposed at different speeds across the Union.
  2. The EU Space Act, proposed in June 2025, still in negotiation.
  3. National space authorisation law, which licenses the activity itself.
  4. The prime contractor or operator’s contract, which has a date on it and no appeal.

They overlap, but not neatly, and the one that will actually cost you a deal this year is the fourth.

Regime one: NIS2, already live

NIS2 names space in Annex I. The entities it captures are operators of ground-based infrastructure, owned, managed and operated by member states or by private parties, that support the provision of space-based services. Note what that does and does not say. It is ground segment, not orbit. A company operating a teleport, a ground station network or mission control infrastructure is inside. A company that builds a reaction wheel is not, at least not through this door.

Size matters next. Ground segment operators above the medium enterprise threshold are essential entities, smaller ones important entities, with the practical differences set out in essential and important entities compared. If you are unsure which side of the line you fall on, the NIS2 scope and applicability guide and the NIS2 scope checker answer it faster than a legal opinion.

Manufacturers land differently. If you build spacecraft, electronic or communication equipment, or the machinery around them, you are reached through the manufacturing entries in Annex II rather than the space entry in Annex I, as an important entity rather than an essential one.

And if neither door applies, the third one usually does. Article 21(2)(d) requires in scope entities to manage risk in their own supply chains, which means their obligations travel to you by contract whether or not the directive names you. This is the same mechanism described for telecom suppliers, and the detail sits in supply chain security and vendor risk.

One practical note on timing. Transposition ran late almost everywhere: in November 2024 the Commission sent letters of formal notice to twenty three member states, Luxembourg among them, for failing to transpose by the October 2024 deadline. That is why two customers in two countries will quote you different dates for the same directive, and why the Luxembourg implementation law is worth reading directly if you are established here. If you operate across borders, which jurisdiction applies decides which regulator you answer to.

Regime two: the EU Space Act, and why it is not just more NIS2

The Commission adopted the EU Space Act proposal on 25 June 2025. It is a regulation rather than a directive, so when it passes it applies directly without twenty seven national versions. Public consultation closed in November 2025 and it is now in the ordinary legislative procedure between Parliament and Council.

Three things in the proposal matter more than the rest for a supplier.

It is designed as lex specialis, not as an extra layer. The resilience chapter is intended to take precedence over NIS2 for in scope space operators rather than sit on top of it. That is unusual and it is good news: the alternative was two incident reporting regimes with different clocks.

The clock is shorter. As proposed, significant incidents are reported within twelve hours of detection, against the twenty four hour early warning in NIS2. The NIS2 incident reporting timeline is the baseline to compare it against. Twelve hours is not a documentation problem. It is a detection problem, and we will come back to that.

Security is tested before launch, not asserted. The proposal requires threat led penetration testing by accredited assessors before launch, or before the first batch for a constellation, with re-testing on a three year cycle. Whoever supplied the flight software and the ground segment will be inside the scope of that test.

There is proportionality for small operators: small enterprises and research or education institutions apply a simplified risk management approach focused on critical assets and main risks. And the regulation reaches beyond the Union, covering third country operators providing space based data or services in the EU, in the same way GDPR reaches outside Europe.

The honest caveat: this is a proposal. Article numbers, thresholds and the twelve hour figure can all move in trilogue, and the application date is not fixed. Do not build to the article numbers. Build to the shape, because the shape is stable: shorter clocks, tested rather than declared security, and supply chain obligations that land on you through your customer.

Regime three: your national authorisation

Space activity is licensed nationally, and the licence is a separate channel from any of the above. Luxembourg operates an authorisation regime for space activities administered through the national space agency, with conditions attached to the licence that can include security, continuity and reporting duties. Those conditions are enforceable independently of NIS2 and independently of whatever the Space Act becomes.

For a supplier this matters indirectly but concretely. Your customer’s licence conditions become your contract terms. A licensed operator that has committed to a regulator about the integrity of its command and control chain will pass that commitment to whoever supplies any part of it.

Regime four: the prime contractor, which arrives first

Everything above is a future dated obligation with a legislative process attached. The regime that will actually cost you revenue this quarter is a questionnaire from a prime contractor or an operator, attached to a tender, with a return date two weeks out.

Agency and prime contractor flow-down does not wait for regulation. It has its own standards lineage, its own vocabulary, and it asks questions that are more specific than anything in NIS2: how command links are authenticated, how flight software is signed and verified, who has physical access to the integration facility, how long telemetry is retained and who can read it, what happens to a subcontractor’s access when the subcontract ends.

If you have received one of these and found you could not answer half of it, that experience is the subject of the security questionnaire you cannot answer. The uncomfortable part is that the questionnaire is not really asking whether you are secure. It is asking whether you can demonstrate it, which is a different capability and usually a missing one.

Which one reaches you first

In order of arrival for a typical supplier: the customer’s questionnaire, then the customer’s contract clauses at renewal, then NIS2 if you operate ground infrastructure or manufacture equipment, then national licence conditions if you hold a licence, then the Space Act somewhere beyond that.

That ordering has a practical consequence. Building for the regulation that is furthest away is the wrong sequence. Building for the questionnaire that arrives next, in a way that also satisfies the regulation later, is the right one.

What to build once

The four regimes ask overlapping questions in different words. The common core is smaller than the combined page count suggests.

  • An asset inventory that includes the ground segment, not just the corporate estate. Every regime asks what you have before it asks how you protect it, and the ground segment is where most inventories stop.
  • A supplier register with security terms and review dates. You are in someone’s supply chain and someone is in yours. Both directions are assessed.
  • Access control with an expiry discipline, particularly for contractors and integration facilities, which is where space specific questionnaires concentrate.
  • Logging with retention that survives an investigation, not retention that satisfies a default. A twelve hour reporting clock is meaningless if the evidence rolls off in seven days.
  • An incident process rehearsed against the shortest clock you face, which today is twenty four hours and may become twelve.
  • Evidence that regenerates. The difference between passing one questionnaire and passing all of them is whether the answers are produced by a system or assembled by a person each time.

A company that builds this is audit-ready against NIS2, answerable to a prime contractor, and positioned for the Space Act without rebuilding. A company that builds four separate compliance efforts will do the same work three extra times. The general argument for doing this once is in ISO 27001 and NIS2 once instead of twice, and the practical starting point for a company with no security team is ISO 27001 without a security team.

The technical reality

Every one of these four regimes sets a clock and says almost nothing about the instrument that starts it.

Twelve hours from detection is the proposal’s language. Twenty four hours from awareness is the directive’s. Both sentences contain a hidden assumption: that something detects. A supplier with no log aggregation, no alerting on its build pipeline and no retention beyond the default on its ground segment systems does not have a reporting problem. It has a discovery problem, and the reporting clock never starts because nobody ever knows.

That is the gap the regulation leaves open, and it is specific enough to close. Telemetry from the systems that matter, retention long enough to reconstruct a compromise rather than to satisfy a checkbox, alerting tuned to the handful of things that are genuinely abnormal in a small engineering estate, and an evidence record that a customer, a regulator and an auditor can all read without three separate assembly jobs.

Regulation asks you to declare. Space customers, increasingly, ask you to demonstrate. The gap between the two is where the work actually is. If you want it measured rather than estimated, an independent security audit does that, and our space sector page sets out what the obligations look like end to end.

Daniel Grigorovich

Daniel Grigorovich · Founder

I believe that no business should suffer from "compliance checklists" or navigating vague regulatory text. While I still stand by the principle that all software products should be reliable and secure, I want to give companies a way to overcome the challenges faced when implementing these requirements.