{"id":48586,"date":"2026-04-12T16:24:06","date_gmt":"2026-04-12T13:24:06","guid":{"rendered":"https:\/\/trueconf.com/blog\/?p=48586"},"modified":"2026-09-10T11:02:58","modified_gmt":"2026-09-10T08:02:58","slug":"nis2-requirements","status":"publish","type":"post","link":"https:\/\/trueconf.com/blog\/reviews-comparisons\/nis2-requirements","title":{"rendered":"NIS2 Requirements for Communication Platforms"},"content":{"rendered":"<p class=\"primary-medium-text ui-mb-sm-1\"><strong>NIS2 requirements<\/strong> cover cybersecurity risk management, incident handling and reporting, <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/business-continuity-management\" target=\"_blank\" rel=\"noopener\">business continuity<\/a>, supply chain security, access control, cryptography, vulnerability management, security governance, and management accountability. For organizations within scope, <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/secure-communication-platform-for-enterprises\" target=\"_blank\" rel=\"noopener\">communication platforms<\/a> such as video conferencing, corporate messaging, email, telephony, and unified communications may need to be addressed whenever they support operations, services, or other business-critical processes.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">NIS2 did not arrive as a routine policy update. It changed how organizations must approach cybersecurity responsibility, risk management, evidence, and management oversight. Communication platforms, often treated as productivity tools outside the core security perimeter, can become part of the systems that an organization must assess, protect, monitor, and recover.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">The practical question is not whether a communication platform describes itself as secure. Organizations need to determine whether its deployment model, configuration, supplier dependencies, monitoring capabilities, continuity arrangements, and administrative controls allow them to manage risk and demonstrate that required measures actually work.<\/p>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Executive Summary<\/h2>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Area<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Core NIS2 Requirement<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Key Implication for Communication Platforms<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Risk Management<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Appropriate and proportionate technical, operational, and organizational measures<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Include relevant communication systems and their dependencies in the risk framework<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Encryption<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Policies and procedures regarding cryptography and, where appropriate, encryption<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Document and verify how media, signaling, stored data, and administration are protected<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Access Controls<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Access-control policies and MFA or continuous authentication where appropriate<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Prioritize privileged, remote, and sensitive access and keep permissions current<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Incident Reporting<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">24-hour early warning, 72-hour notification, and subsequent reporting for significant incidents<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Detection, classification, evidence collection, and escalation must exist before an incident<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Supply Chain<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Security-related aspects of relationships with direct suppliers and service providers<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Vendor infrastructure, subprocessors, incident response, and vulnerability practices become part of the risk picture<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Governance<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Management approval and oversight of cybersecurity measures<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/enterprise-meeting-software\" target=\"_blank\" rel=\"noopener\">Platform selection<\/a> and risk acceptance become governance decisions, not only IT choices<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Resilience<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Business continuity, backup management, disaster recovery, and crisis management<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Critical communications need tested recovery and a fallback outside the same failure domain<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><strong><em>Regulatory note<\/em><\/strong><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>NIS2 is an EU directive implemented through national law. This article summarizes the Directive-level requirements and translates its risk-management themes into practical checks for communication platforms. Specific obligations, supervisory procedures, reporting channels, registration requirements, and enforcement details can vary by Member State and sector.<\/em><\/p>\n<\/div>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text\"><strong>Who is in scope:<\/strong> As a general rule, NIS2 covers medium-sized and larger entities in specified sectors, with important exceptions based on entity type, criticality, group structure, and national transposition. The commonly cited 50-employee\/\u20ac10 million threshold is a useful shortcut, not a complete scope test.<\/p>\n<\/div>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><strong><em>Insight 1. NIS2 readiness is an evidence problem as much as a control problem.<\/em><\/strong><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>It is not enough for a communication platform to support encryption, access control, logging, backup, or other security functions. The organization must also be able to show what is enabled, who owns the control, how it is monitored, when it was tested, and what happens when the control fails.<\/em><\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Why Communication Platforms Fall Under NIS2 Risk Management?<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-45626\" title=\"NIS2 Requirements\" src=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/05\/oauth-1.svg\" alt=\"NIS2 Requirements\" width=\"571\" height=\"421\" \/ loading=\"lazy\"><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Reading NIS2 as a directive about firewalls and data centers is a mistake. NIS2 requires in-scope entities to manage cybersecurity risks affecting the network and information systems used for their operations or services, including relevant dependencies within the <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/communication-software\" target=\"_blank\" rel=\"noopener\">communication stack<\/a>. By that measure, communication platforms are not peripheral. They can be central.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Think about what actually travels through a corporate communication stack on a normal working day. Negotiations happen over messaging. Strategic decisions get made on video calls. Client data moves through email threads. Operational instructions flow across <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/messaging-apps-for-business\" target=\"_blank\" rel=\"noopener\">team channels<\/a>.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">None of this is incidental to how organizations function. A breach or sustained outage affecting these channels can spread into service delivery, client relationships, regulatory exposure, incident coordination, and financial performance.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">For covered entities, relevant systems may include:<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/sovereign-messaging-platform\" target=\"_blank\" rel=\"noopener\">Corporate messaging platforms<\/a>, including cloud-hosted, <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/sovereign-collaboration-platform\" target=\"_blank\" rel=\"noopener\">self-hosted<\/a>, and on-premises deployments<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Email infrastructure, cloud-hosted and internally managed<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/video-conferencing-software\" target=\"_blank\" rel=\"noopener\">Video conferencing systems<\/a>, including those running on <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/sovereign-video-conferencing\" target=\"_blank\" rel=\"noopener\">private networks<\/a> or dedicated hardware<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><a href=\"https:\/\/trueconf.com\/blog\/knowledge-base\/registering-sip-devices-on-trueconf-server\" target=\"_blank\" rel=\"noopener\">VoIP and telephony infrastructure<\/a><\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/ucaas-providers-regulated-organizations\" target=\"_blank\" rel=\"noopener\">Unified communications environments<\/a> combining voice, video, messaging, and collaboration<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Identity, storage, gateways, monitoring systems, networks, and other services on which communication platforms depend<\/li>\n<\/ul>\n<\/div>\n<p class=\"primary-medium-text ui-mb-sm-1\">The deciding factor is not the product category printed on a procurement form. It is the role the system plays in the organization&#8217;s operations and the impact that its compromise or failure could have.<\/p>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><strong><em>Insight 2. The &#8220;productivity tool&#8221; exemption does not exist.<\/em><\/strong><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Many organizations still categorize video conferencing and messaging platforms as employee productivity tools and manage them separately from security-<a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/cybersecurity-for-government-applications\" target=\"_blank\" rel=\"noopener\">critical infrastructure<\/a>. NIS2 does not provide an exemption simply because a platform is described internally as a productivity tool.<\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>If a communication platform materially supports an in-scope entity&#8217;s operations or services, the defensible approach is to include it in risk assessment, asset governance, incident planning, <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/best-secure-collaboration-apps\" target=\"_blank\" rel=\"noopener\">supplier assessment<\/a>, and relevant security controls.<\/em><\/p>\n<\/div>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Communication Dependency Map<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">A communication platform rarely operates alone. One of the most important NIS2 exercises is identifying the dependencies that must remain secure and available for communication to work.<\/p>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Dependency<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>What Can Fail<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Potential Communication Impact<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Identity provider \/ directory<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Authentication outage, compromise, incorrect provisioning<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Users cannot sign in or attackers receive unauthorized access<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Network and DNS<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Routing failure, connectivity loss, DNS manipulation<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Calls, messages, or administration become unavailable<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Communication server or cloud service<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Service outage, exploitation, configuration failure<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Primary communications stop or become exposed<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Storage<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Data loss, ransomware, unauthorized access<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><a href=\"https:\/\/trueconf.com\/features\/collaboration\/office-chat-app.html\" target=\"_blank\" rel=\"noopener\">Messages, files, recordings<\/a>, or logs become unavailable or compromised<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong><a href=\"https:\/\/trueconf.com\/docs\/server\/en\/admin\/gateways\/\" target=\"_blank\" rel=\"noopener\">Gateways and integrations<\/a><\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Integration compromise or external dependency failure<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Telephony, <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/enterprise-conferencing\" target=\"_blank\" rel=\"noopener\">external conferencing<\/a>, or business workflows are affected<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Endpoints<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Malware, lost devices, unsupported clients<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Credentials and communication content may be exposed<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Monitoring and logging<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Missing telemetry or inaccessible logs<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">The incident occurs but the organization cannot detect or classify it quickly<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><strong><em>Insight 3. NIS2 applies to the communication dependency chain, not just the application.<\/em><\/strong><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>A secure messaging or <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/self-hosted-video-conferencing\" target=\"_blank\" rel=\"noopener\">video platform<\/a> can still become unavailable because the identity provider, DNS, network, storage, or gateway it depends on fails. Reviewing the application without mapping those dependencies can leave major operational risks outside the assessment.<\/em><\/p>\n<\/div>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Which Communications Are Most Critical?<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">Not every communication workload has the same business impact. Criticality classification helps organizations direct stronger controls toward channels where confidentiality, integrity, or availability matter most.<\/p>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Communication Workload<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Typical Criticality<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Primary Risk Focus<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Routine internal chat<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Moderate<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Access control and information exposure<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Executive communications<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">High<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Confidentiality and account compromise<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/out-of-band-communication\" target=\"_blank\" rel=\"noopener\">Incident-response communications<\/a><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Critical<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Availability and independence from the affected infrastructure<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Operational coordination<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">High to critical<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Availability, integrity, and recovery time<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">External meetings<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Moderate to high<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Identity, guest access, and data sharing<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Regulated or sensitive data exchange<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">High<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Confidentiality, auditability, and retention<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Risk Management and Security Measures<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-46442 size-full\" title=\"Risk management and security measures\" src=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/06\/secure-enter-2.svg\" alt=\"Risk management and security measures\" width=\"561\" height=\"335\" \/ loading=\"lazy\"><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">NIS2 Article 21 sets out the technical, operational, and organizational measures covered entities must implement. These measures form the directive&#8217;s baseline cybersecurity risk-management framework, but their implementation is risk-based and must be proportionate to the entity&#8217;s exposure, size, and potential incident impact. For communication platforms, each measure translates into something concrete and auditable.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Encryption<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">NIS2 requires policies and procedures regarding cryptography and, where appropriate, the use of encryption. In practice, organizations should evaluate encryption in transit, encryption at rest, and stronger protection for sensitive communication where justified by risk rather than treating a specific algorithm or protocol as a universal statutory minimum.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">The question is not simply whether a platform supports encryption somewhere in its configuration. It is whether the organization knows which traffic is encrypted, where encryption terminates, which exceptions exist, and how the configuration can be verified.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">For organizations running their own <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/unified-communication-and-collaboration-tools\" target=\"_blank\" rel=\"noopener\">communication infrastructure<\/a>, encryption and certificate management are separate considerations. Direct infrastructure control can improve visibility, but it also places more responsibility on internal administrators to configure and maintain the environment correctly.<\/p>\n<\/div>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Access Controls<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">Compromised credentials are among the most common entry points into corporate systems, and communication platforms are valuable targets because access can expose sensitive conversations, files, recordings, contact networks, and meeting information.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-sm-1\">NIS2 requires a systematic response:<\/p>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\"><a href=\"https:\/\/trueconf.com\/docs\/server\/en\/admin\/security\/\" target=\"_blank\" rel=\"noopener\">Multi-factor authentication or continuous authentication<\/a> where appropriate based on risk, with particular attention to privileged, remote, and sensitive access<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Role-based access controls built around current operational reality rather than years of accumulated permissions<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Regular, documented access reviews with attention to former employees, contractors, partners, and internal role changes<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Separate protection and logging for privileged administrative access<\/li>\n<\/ul>\n<p class=\"primary-medium-text ui-mb-sm-1\">The practical test is whether the organization can demonstrate that accounts and privileges correspond to a current legitimate need at the level of access granted.<\/p>\n<\/div>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Data Minimization and Retention<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">Holding communication data indefinitely creates two compounding problems. Operationally, every historical archive represents an expanded attack surface: more messages, files, recordings, and metadata to expose if a breach occurs. From a compliance perspective, unmanaged retention can also intersect with <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/data-leakage-prevention-best-practices\" target=\"_blank\" rel=\"noopener\">data-protection and sector-specific obligations<\/a>.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">NIS2 does not prescribe one universal retention period for communication content or logs. Organizations should define retention based on risk, investigation requirements, applicable national and sector-specific rules, contractual obligations, and data-protection requirements.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Retention policies need to correspond to technical reality. If policy says data is deleted after a defined period while production systems or backups retain it indefinitely, the organization has a control and evidence gap.<\/p>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Vulnerability Management<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">Every unpatched vulnerability in a communication platform creates avoidable exposure. NIS2 requires a structured approach: an accurate inventory of communication tools and components, active tracking of relevant security updates, and remediation processes tied to risk and severity rather than administrative convenience alone.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-sm-1\"><a href=\"https:\/\/trueconf.com\/blog\/news\/security-fixes-updates-and-advisories\" target=\"_blank\" rel=\"noopener\">Vendors that are slow to release patches, lack a responsible disclosure process, or fail to communicate vulnerabilities clearly<\/a> create supply chain risk that reflects on the customer&#8217;s own security posture.<\/p>\n<\/div>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Network Security<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">Communication platforms require integration into the broader network-security architecture. Treating them as standalone applications with an independent security perimeter can create gaps between the application, identity environment, storage, gateways, and network.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-sm-1\">Depending on the architecture and risk assessment, relevant measures may include:<\/p>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\"><a href=\"https:\/\/trueconf.com\/blog\/productivity\/communication-security\" target=\"_blank\" rel=\"noopener\">Network segmentation<\/a> to contain the spread of a compromise<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Traffic monitoring capable of identifying unusual connections, access patterns, or data volumes<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Restricted administrative interfaces<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Controlled remote access through appropriate network or zero-trust mechanisms<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Documented port and firewall requirements rather than unnecessary broad exposure<\/li>\n<\/ul>\n<\/div>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Cyber Hygiene and Training<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">Basic cyber hygiene and cybersecurity training are also part of the NIS2 risk-management framework. Communication systems deserve specific attention because many attacks exploit user behavior rather than software vulnerabilities.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Relevant scenarios include credential phishing, fraudulent meeting invitations, malicious attachments, accidental external sharing, social engineering through corporate messaging, unauthorized recording, and misuse of administrator privileges. Administrators need additional training covering privileged access, certificates, patching, backups, integrations, and incident evidence.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Business Continuity<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">Where communication infrastructure is important to the delivery or continuity of an in-scope entity&#8217;s services, it should be addressed within the organization&#8217;s NIS2 business-continuity and crisis-management measures.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">The organization needs to answer, in writing and with evidence from testing: what happens when the primary communication system fails? How do teams coordinate? How long does recovery take? Which functions recover first? What communication method remains available while recovery proceeds?<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Appropriate redundancy, backup, disaster recovery, and crisis-management measures should be selected according to risk and continuity requirements. A plan that exists as a document but has never been exercised provides limited assurance.<\/p>\n<\/div>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><strong><em>Insight 4. A fallback channel only works if it is outside the same failure domain.<\/em><\/strong><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Two communication platforms do not provide true redundancy if both depend on the same identity provider, Internet connection, cloud environment, device-management service, or corporate network. An incident affecting the shared dependency can disable both at the same time.<\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Continuity planning should therefore test dependency independence, not simply count the number of available applications.<\/em><\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Incident Reporting and Monitoring<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">The incident reporting requirements in NIS2 impose operational pressure that organizations can underestimate until they test the timelines in practice.<\/p>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Reporting Timeline<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">The staged reporting timeline below reflects the Directive-level framework for significant incidents. National procedures and reporting channels are defined through Member State implementation.<\/p>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Timeframe<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Required Action<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Within 24 hours<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Early warning after becoming aware of a significant incident<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Within 72 hours<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Incident notification with an initial assessment of severity and impact and, where available, indicators of compromise<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>On request<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Intermediate status report where requested by the competent authority or CSIRT<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Within one month<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Final report following the incident notification, subject to the rules applicable when an incident is still ongoing<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Communication platform incidents that may reach the significance threshold include major unauthorized access, large-scale data exfiltration, ransomware disabling unified communications infrastructure, or attacks that materially prevent an organization from coordinating its operations.<\/p>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Building the Capability Before It Is Needed<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">The 24-hour early warning deadline cannot be met reliably through improvisation after the fact. Detection, internal escalation, preliminary assessment, evidence collection, and regulatory notification all compete for time within the same response window.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-sm-1\">For communication platforms, the necessary foundations include:<\/p>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Centralized logging of relevant authentication, administrative, configuration, and security events<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Real-time or near-real-time alerting for defined high-risk behaviors where justified by risk<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Escalation procedures with defined paths from detection to decision-makers authorized to classify and report incidents<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Integration with broader monitoring or SIEM environments where appropriate<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Known supplier contacts and procedures for obtaining incident information when evidence sits outside the organization&#8217;s infrastructure<\/li>\n<\/ul>\n<\/div>\n<p class=\"primary-medium-text ui-mb-sm-1\">These capabilities should be tested through exercises that include realistic communication-platform failure or compromise scenarios. The objective is to find gaps while the stakes are low enough to correct them.<\/p>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><strong><em>Insight 5. Supplier notification speed is part of your own incident-response capability.<\/em><\/strong><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>With a cloud communication platform, critical evidence may initially exist only inside the provider&#8217;s environment. If the provider is slow to disclose an incident or deliver relevant information, the customer may have to classify and report the event with an incomplete picture.<\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Supplier notification commitments should therefore be evaluated against the customer&#8217;s regulatory response window, not only against ordinary service-level terminology.<\/em><\/p>\n<\/div>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Monitoring as a Continuous Obligation<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">NIS2 requires organizations to assess the effectiveness of cybersecurity risk-management measures. For communication infrastructure, monitoring depth should reflect risk and criticality. Formal audits and penetration testing provide structured checkpoints, but they do not replace operational visibility into relevant security events.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">The 24-hour clock starts at awareness, not at complete forensic confirmation. Organizations should predefine classification criteria, escalation responsibilities, and notification authority so that investigation and regulatory reporting can proceed in parallel when a potentially significant incident is identified.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Management Accountability<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">The governance shift embedded in NIS2 means cybersecurity cannot be treated solely as a technical matter delegated to IT. Management bodies must approve cybersecurity risk-management measures, oversee their implementation, and undertake training sufficient to understand relevant cybersecurity risks.<\/p>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">What the Directive Requires?<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">Boards, executive leadership, or equivalent management bodies need enough information to understand material cybersecurity risks, approve the measures used to address them, and oversee their implementation.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">National transposition determines precise supervisory mechanisms and potential consequences for management members, so organizations should assess the rules applicable in each relevant jurisdiction.<\/p>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">What This Means for Communication Platforms Specifically?<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">Decisions about which communication tools an organization deploys and which risks it accepts can become management-level governance decisions. Choosing a platform for sensitive or operationally critical communication without assessing access, supplier dependence, resilience, and auditability creates a decision trail that may later matter during supervision or incident investigation.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Organizations therefore need governance structures that treat platform selection, configuration standards, security exceptions, and periodic review as formal risk decisions rather than informal preferences.<\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Supply Chain Security<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">Supply chain security is treated in NIS2 as a primary obligation, not an afterthought. For organizations using third-party communication platforms, the implications are direct.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">When an organization deploys a <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/enterprise-collaboration-software\" target=\"_blank\" rel=\"noopener\">cloud-based communication platform<\/a>, the vendor&#8217;s infrastructure decisions, security practices, operational resilience, and service dependencies become part of the customer&#8217;s risk profile. Outsourcing operation of the platform does not outsource the entity&#8217;s own NIS2 accountability.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Vendor Due Diligence<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">For communication platforms, a credible supplier assessment addresses:<\/p>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\"><strong>Security assurance:<\/strong> What certifications, independent assessments, penetration testing, or other evidence are available, and what infrastructure do they actually cover?<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><strong>Encryption practices:<\/strong> What mechanisms protect signaling, media, stored information, administration, and integrations?<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><strong><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/data-residency\" target=\"_blank\" rel=\"noopener\">Data location<\/a>:<\/strong> Where are relevant categories of data stored and processed?<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><strong>Incident notification:<\/strong> How quickly must the vendor notify customers and provide useful evidence?<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><strong>Subprocessor chain:<\/strong> Which additional providers participate in service delivery?<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><strong>Patch and disclosure practices:<\/strong> How are vulnerabilities assessed, corrected, and communicated?<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><strong>Continuity:<\/strong> How are redundancy, backup, and disaster recovery implemented and tested?<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><strong>Exit capability:<\/strong> Can the organization migrate data, identities, and workflows if supplier risk becomes unacceptable?<\/li>\n<\/ul>\n<\/div>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Cloud vs. On-Premises: Supply Chain Risk Comparison<\/h3>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Dimension<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Cloud-Hosted Platform<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>On-Premises \/ Self-Hosted Platform<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Infrastructure control<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Primarily provider-operated<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Primarily organization-operated<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Data-location control<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Depends on provider architecture and contractual options<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Organization selects the hosting environment<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Audit evidence<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Mix of customer-visible telemetry and supplier evidence<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">More evidence can originate from organization-controlled infrastructure<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Patch responsibility<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Provider manages service infrastructure<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Organization controls deployment timing and assumes direct patch responsibility<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Supplier dependency<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Includes provider and relevant service-chain dependencies<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Infrastructure dependency is reduced, but software-supplier risk remains<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Operational resilience<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Shared with provider architecture and availability<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Depends directly on internal infrastructure and operational maturity<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">The Case for Infrastructure Ownership<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">A structural alternative to depending on provider-operated communication infrastructure is to deploy the platform within the organization&#8217;s own environment. On-premises or privately hosted systems such as <a href=\"https:\/\/trueconf.com\/products\/server\/video-conferencing-server.html\" target=\"_blank\" rel=\"noopener\">TrueConf Server<\/a> give organizations direct control over where the platform operates, how network access is designed, how authentication is <a href=\"https:\/\/trueconf.com\/features\/integration.html\" target=\"_blank\" rel=\"noopener\">integrated<\/a>, and which operational data remains inside their environment.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">This does not eliminate supply chain considerations. The software still originates with a vendor and requires its own diligence. What changes is the distribution of control and operational responsibility.<\/p>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><strong><em>Insight 6. Deployment model changes who must produce the evidence.<\/em><\/strong><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Cloud deployment transfers substantial infrastructure operation to the provider but leaves the customer dependent on provider evidence for parts of its assessment. Self-hosting gives the organization greater direct visibility but makes it responsible for generating evidence through its own logging, configuration, patching, backup, and recovery processes.<\/em><\/p>\n<\/div>\n<div class=\"accent-note ui-mb-sm-1\">\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Contractual Requirements<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">Vendor contracts should be built around security requirements, not just commercial terms. For communication platforms, useful contractual provisions include:<\/p>\n<ol class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px; margin-left: 20px;\">\n<li class=\"ui-list__item\">Defined minimum security requirements with verifiable criteria<\/li>\n<li class=\"ui-list__item\">Incident-notification obligations that support the customer&#8217;s own NIS2 reporting timelines<\/li>\n<li class=\"ui-list__item\">Rights to obtain relevant security and incident evidence<\/li>\n<li class=\"ui-list__item\">Rules governing material changes and subprocessors<\/li>\n<li class=\"ui-list__item\">Defined exit, migration, and data-return or deletion arrangements<\/li>\n<\/ol>\n<p class=\"primary-medium-text ui-mb-sm-1\">Contractual protections do not transfer NIS2 obligations to vendors. The organization remains accountable, but strong contracts reduce uncertainty and create evidence that supplier risk has been actively managed.<\/p>\n<\/div>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Ongoing Vendor Oversight<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">Vendor security posture is not static. Organizations should maintain awareness of disclosed vulnerabilities, incidents, infrastructure changes, acquisitions, new subprocessors, and end-of-support announcements affecting platforms they rely on.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">The organization should define triggers for reassessment rather than treating the procurement-stage security questionnaire as permanent evidence.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">On-premises deployment shifts, rather than eliminates, the compliance burden. Self-hosting can reduce dependency on a cloud provider for core communication infrastructure, but it transfers responsibility for deployment, patch management, infrastructure hardening, backup, monitoring, capacity, and disaster recovery to the organization.<\/p>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">What to Ask a Communication Platform Vendor Before Procurement?<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">This procurement stage should focus on information that only the supplier or product architecture can answer. Internal implementation checks belong later, after the organization has selected and deployed the platform.<\/p>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Buyer Criterion<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Question for the Vendor<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Decision Impact<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Deployment ownership<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Which infrastructure components are operated by the vendor, the customer, or another provider?<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Defines the operational and supplier-risk boundary<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Security evidence<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">What logs, configuration evidence, assessments, and incident information can customers obtain?<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Determines how much of the NIS2 evidence chain depends on the supplier<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Incident notification<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">How quickly will the vendor notify customers and provide usable incident information?<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Must fit the customer&#8217;s own regulatory response window<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Subprocessors<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Which third parties are required to deliver the service, and how are changes communicated?<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Reveals hidden dependencies and concentration risk<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Identity integration<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Can the platform use the organization&#8217;s authoritative identity, MFA, and lifecycle-management systems?<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Reduces isolated accounts and access drift<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Resilience architecture<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Which dependencies remain shared across primary and recovery paths?<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Shows whether apparent redundancy survives a real failure<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Vulnerability handling<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">How are security advisories, patches, disclosure, and end-of-support handled?<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Affects remediation speed and long-term supplier risk<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Exit capability<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">How can identities, data, configurations, and workflows be migrated if the supplier becomes unacceptable?<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Prevents security risk from becoming contractual lock-in<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Configuration Gaps vs. Architectural Gaps<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">One of the most useful ways to prioritize remediation is to distinguish controls that are incorrectly configured from capabilities the platform or operating model does not provide.<\/p>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Gap Type<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Example<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Typical Response<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Configuration gap<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">MFA exists but is not enabled for privileged accounts<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Change configuration, document it, and verify enforcement<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Process gap<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Logs exist but security-relevant events are not reviewed<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Assign ownership and define monitoring and escalation procedures<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Governance gap<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">A critical communication platform has never been risk-assessed<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Add it to formal asset, risk, and management-review processes<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Contractual gap<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">A cloud supplier has no defined security-incident notification timeframe<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Change contractual terms or introduce compensating controls<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Architectural gap<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">The platform cannot provide the required deployment control, resilience, or evidence<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Evaluate architectural changes or migration<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"primary-medium-text ui-mb-sm-1\">Configuration gaps are usually the fastest to correct. Architectural gaps deserve earlier attention because remediation may involve procurement, migration, infrastructure changes, user transition, and new operating procedures.<\/p>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><strong><em>Insight 7. Configuration debt and architecture debt require different remedies.<\/em><\/strong><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>A missing setting can often be corrected without replacing the platform. A missing architectural capability \u2014 for example, required deployment control, independent recovery, or access to evidence \u2014 may require a different operating model or migration. Treating both problems as configuration issues delays the harder decision.<\/em><\/p>\n<\/div>\n<div class=\"accent-note ui-mb-sm-1\">\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">NIS2 Implementation Checklist for Communication Platforms<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-46445\" title=\"NIS2 security checklist for communication platforms\" src=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/06\/seamless-authorization.svg\" alt=\"NIS2 security checklist for communication platforms\" width=\"521\" height=\"493\" \/ loading=\"lazy\"><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">This checklist is for validating an environment after deployment. It focuses on whether controls are actually configured, owned, monitored, and tested rather than whether the product merely supports them.<\/p>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Risk and Asset Management<\/h3>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">The deployed platform and its critical dependencies appear in the current asset inventory<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Business impact and realistic failure scenarios have been documented<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Named system, security, and business owners have been assigned<\/li>\n<\/ul>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Security Configuration<\/h3>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Encryption and certificate settings have been verified in the deployed configuration<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">MFA or continuous authentication is enabled where required by the risk assessment<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Privileged interfaces and remote administration are restricted appropriately<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Firewall, network segmentation, and exposed-service requirements match the approved architecture<\/li>\n<\/ul>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Identity and Access Lifecycle<\/h3>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Joiner, mover, and leaver workflows are tested rather than assumed<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Former employees and contractors lose access according to defined timelines<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Privileged accounts are separately inventoried and periodically reviewed<\/li>\n<\/ul>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Monitoring and Incident Response<\/h3>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Relevant authentication, administrative, configuration, and security events are collected<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Security teams can retrieve the evidence required to investigate the platform<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Escalation and incident-classification procedures have been exercised<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Reporting timelines are represented in operational response playbooks<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Supplier escalation contacts have been tested where evidence depends on an external provider<\/li>\n<\/ul>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Vulnerability and Supplier Operations<\/h3>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">The actual deployed versions and components are known<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Security advisories are mapped to owned remediation actions<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Material supplier and subprocessor changes trigger reassessment<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Patch delays and accepted vulnerabilities have documented owners and risk decisions<\/li>\n<\/ul>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Resilience Testing<\/h3>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Recovery objectives exist for <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/business-continuity-communication-tool\" target=\"_blank\" rel=\"noopener\">critical communication workloads<\/a><\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Backup restoration has been tested, not merely scheduled<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Fallback communication has been tested during failure of the primary environment<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">The fallback path does not depend entirely on the same identity, network, cloud, or device-management failure domain<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">How TrueConf Fits a NIS2 Communication Strategy?<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-46646\" title=\"TrueConf Server\" src=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/06\/all-communication-in-one-app-4.png\" alt=\"TrueConf Server\" width=\"628\" height=\"464\" \/ loading=\"lazy\" srcset=\"https:\/\/trueconf.com/blog\/wp-content\/uploads\/2026\/06\/all-communication-in-one-app-4.png 810w, https:\/\/trueconf.com/blog\/wp-content\/uploads\/2026\/06\/all-communication-in-one-app-4-637x470.png 637w, https:\/\/trueconf.com/blog\/wp-content\/uploads\/2026\/06\/all-communication-in-one-app-4-768x567.png 768w\" sizes=\"auto, (max-width: 628px) 100vw, 628px\" \/><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">TrueConf does not make an organization automatically compliant with NIS2. Compliance depends on scope, national implementation, organizational processes, configuration, infrastructure security, supplier governance, monitoring, continuity planning, and management oversight.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Its relevance lies mainly in deployment and administrative control. TrueConf Server can be deployed on infrastructure controlled by the organization and used within private corporate networks. This model can reduce dependence on external communication infrastructure where direct control, restricted network access, or local operation is part of the organization&#8217;s risk strategy.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">TrueConf can also be integrated with <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/unified-communications-for-enterprise\" target=\"_blank\" rel=\"noopener\">enterprise identity and administrative environments<\/a>, while organizations remain responsible for configuring access, monitoring, patching, backups, resilience, and related infrastructure according to their own requirements.<\/p>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><strong><em>Insight 8. The main TrueConf decision is architectural, not certification-based.<\/em><\/strong><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>The strongest reason to consider TrueConf in a NIS2-oriented architecture is not a claim of automatic compliance. It is the ability to choose a self-hosted communication model when direct infrastructure control, private-network operation, reduced cloud dependency, and internally generated operational evidence are material requirements.<\/em><\/p>\n<\/div>\n<div class=\"accent-note ui-mb-sm-1\">\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Best For \/ Strengths \/ Limitations at a Glance<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\"><strong>Best for:<\/strong> Essential and important entities that rely heavily on business communications and need a documented, auditable approach to access, supplier risk, incident response, and resilience. Self-hosted platforms such as TrueConf are particularly relevant where infrastructure control or private-network operation is an explicit requirement.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><strong>Strengths:<\/strong><\/p>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Brings communication platforms and their dependencies into the formal risk-management process<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Creates clearer evidence for access, incidents, suppliers, and configuration<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Connects platform selection with business continuity and governance<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Makes architectural and supplier dependencies visible before they become incident-response problems<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Separates supplier selection criteria from post-deployment implementation controls<\/li>\n<\/ul>\n<p class=\"primary-medium-text ui-mb-sm-1\"><strong>Limitations:<\/strong><\/p>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">NIS2 scope and implementation require jurisdiction-specific analysis<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">A security feature does not replace the process needed to configure, monitor, test, and document it<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Architectural gaps may require migration rather than configuration changes<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Self-hosting increases direct operational responsibility<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Cloud deployment retains supplier and service-chain dependencies that require ongoing oversight<\/li>\n<\/ul>\n<\/div>\n<div style=\"background: #00B3CD; border-radius: 12px; padding: 24px;\">\n<h2 class=\"h4--main h4--thick white-text center-text ui-mb-xs-3\">Empower your video conferencing experience with TrueConf!<\/h2>\n<div class=\"button-group-container button-group-container--center\"><a class=\"primary-smallest-text to-page to-page--rarr white-icon white-text\" role=\"link\" href=\"https:\/\/trueconf.com\/products\/server\/video-conferencing-server.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Learn more<\/a><\/div>\n<\/div>\n<section id=\"faq\">\n<h2 class=\"h3--main h3--thick black-text ui-mb-md-1\">FAQ<\/h2>\n<div class=\"faq__container ui-mb-md-1\">\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Which organizations fall within NIS2 scope?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">Scope depends on sector, size, entity type, group structure, and the applicable national legislation, so the common 50-employee\/\u20ac10 million rule should not be used as the only test. TrueConf can support the communication-security architecture of an organization once its scope and obligations have been determined, but the platform itself does not determine whether the entity falls under NIS2.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Do NIS2 requirements apply to cloud communication tools?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">Yes, relevant cloud communication services can fall within an in-scope entity&#8217;s cybersecurity risk-management framework when they support its operations or services. Organizations that need greater control over infrastructure and supplier dependencies can also evaluate a self-hosted model such as TrueConf Server.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Does NIS2 require MFA for every communication-platform account?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">NIS2 refers to multi-factor authentication or continuous authentication where appropriate rather than imposing one identical authentication rule for every user and scenario. Organizations should prioritize authentication controls according to risk, and TrueConf can be incorporated into an enterprise authentication strategy where stronger access controls are required.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">What qualifies as a significant communication-platform incident?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">A significant incident is one that causes or can cause severe operational disruption or financial loss, or considerable material or non-material damage to other persons. With an on-premises platform such as TrueConf Server, the organization can retain direct access to more of its own infrastructure evidence, but it still needs predefined incident-classification and reporting procedures.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Does self-hosting automatically make a communication platform NIS2 compliant?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">No. Self-hosting changes the distribution of control and supplier dependency but also makes the organization directly responsible for infrastructure security, patching, monitoring, backup, and resilience. TrueConf Server provides a self-hosted deployment model, while compliance depends on how that environment is governed and operated.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">What should an organization do if its current communication platform has NIS2 gaps?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">First determine whether the problem is a configuration, process, contractual, governance, or architectural gap. If the architecture itself cannot provide the required control, resilience, or evidence, migration may need to be considered; TrueConf is one option where a self-hosted target architecture fits those requirements.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Is TrueConf NIS2 compliant?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">NIS2 compliance applies to organizations and their cybersecurity risk-management obligations rather than being a simple product certification. TrueConf provides capabilities that can support a NIS2-oriented communication architecture, particularly where self-hosting, private-network operation, infrastructure control, and enterprise administration are required, but the organization remains responsible for its complete compliance framework.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<div class=\"accent-note accent-note--special ui-mb-sm-1\">\n<p class=\"primary-medium-text\"><strong><i>About the Author<\/i><\/strong><br \/>\n<i>Diana Shtapova is a product specialist and technology writer with three years of experience in the unified communications industry. At TrueConf, she leverages her deep product expertise to create clear and practical content on video conferencing platforms, collaboration tools, and enterprise communication solutions. With a strong background in product research and user-focused content development, Diana helps professionals and businesses understand core product features, adopt new technologies, and unlock the full potential of modern collaboration software.<\/i><\/p>\n<p><a class=\"primary-small-text to-page to-page--rarr cyan-icon\" role=\"link\" href=\"https:\/\/www.facebook.com\/shtapovadiana\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\"><i>Connect with Diana on Facebook<\/i><\/a><\/p>\n<\/div>\n<p><script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Which organizations fall within NIS2 scope?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Scope depends on sector, size, entity type, group structure, and the applicable national legislation, so the common 50-employee\/\u20ac10 million rule should not be used as the only test. TrueConf can support the communication-security architecture of an organization once its scope and obligations have been determined, but the platform itself does not determine whether the entity falls under NIS2.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Do NIS2 requirements apply to cloud communication tools?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Yes, relevant cloud communication services can fall within an in-scope entity's cybersecurity risk-management framework when they support its operations or services. Organizations that need greater control over infrastructure and supplier dependencies can also evaluate a self-hosted model such as TrueConf Server.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Does NIS2 require MFA for every communication-platform account?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"NIS2 refers to multi-factor authentication or continuous authentication where appropriate rather than imposing one identical authentication rule for every user and scenario. Organizations should prioritize authentication controls according to risk, and TrueConf can be incorporated into an enterprise authentication strategy where stronger access controls are required.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What qualifies as a significant communication-platform incident?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"A significant incident is one that causes or can cause severe operational disruption or financial loss, or considerable material or non-material damage to other persons. With an on-premises platform such as TrueConf Server, the organization can retain direct access to more of its own infrastructure evidence, but it still needs predefined incident-classification and reporting procedures.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Does self-hosting automatically make a communication platform NIS2 compliant?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"No. Self-hosting changes the distribution of control and supplier dependency but also makes the organization directly responsible for infrastructure security, patching, monitoring, backup, and resilience. TrueConf Server provides a self-hosted deployment model, while compliance depends on how that environment is governed and operated.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What should an organization do if its current communication platform has NIS2 gaps?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"First determine whether the problem is a configuration, process, contractual, governance, or architectural gap. If the architecture itself cannot provide the required control, resilience, or evidence, migration may need to be considered; TrueConf is one option where a self-hosted target architecture fits those requirements.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Is TrueConf NIS2 compliant?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"NIS2 compliance applies to organizations and their cybersecurity risk-management obligations rather than being a simple product certification. TrueConf provides capabilities that can support a NIS2-oriented communication architecture, particularly where self-hosting, private-network operation, infrastructure control, and enterprise administration are required, but the organization remains responsible for its complete compliance framework.\"\n      }\n    }\n  ]\n}\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>NIS2 requirements cover cybersecurity risk management, incident handling and reporting, business continuity, supply chain security, access control, cryptography, vulnerability management, security governance, and management accountability. For organizations within scope, communication platforms such as video conferencing, corporate messaging, email, telephony, and unified communications may need to be addressed whenever they support operations, services, or other business-critical [&hellip;]<\/p>\n","protected":false},"author":78,"featured_media":49520,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[32],"tags":[386,393,387],"class_list":["post-48586","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-reviews-comparisons","tag-security","tag-unified-communications","tag-video-conferencing","wpautop"],"_links":{"self":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts\/48586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/users\/78"}],"replies":[{"embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/comments?post=48586"}],"version-history":[{"count":43,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts\/48586\/revisions"}],"predecessor-version":[{"id":49522,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts\/48586\/revisions\/49522"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/media\/49520"}],"wp:attachment":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/media?parent=48586"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/categories?post=48586"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/tags?post=48586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}