{"id":48619,"date":"2026-06-03T09:33:18","date_gmt":"2026-06-03T06:33:18","guid":{"rendered":"https:\/\/trueconf.com/blog\/?p=48619"},"modified":"2026-08-13T15:44:57","modified_gmt":"2026-08-13T12:44:57","slug":"nis2-compliance","status":"publish","type":"post","link":"https:\/\/trueconf.com/blog\/reviews-comparisons\/nis2-compliance","title":{"rendered":"NIS2 Compliance Guide for Secure Communications"},"content":{"rendered":"<p><a href=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/05\/oauth.svg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"aligncenter wp-image-45445 size-full\" title=\"NIS2 compliance with TrueConf\" src=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/05\/oauth.svg\" alt=\"NIS2 compliance with TrueConf\" width=\"515\" height=\"380\" \/ loading=\"lazy\"><\/a><\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text\"><strong><em>NIS2 (Network and Information Security Directive 2)<\/em><\/strong> is the EU&#8217;s updated cybersecurity framework, which entered into force on 16 January 2023 replacing the original NIS Directive from 2016. Member states had until 17 October 2024 to transpose it into national legislation, with the rules applying from 18 October 2024, and many organizations are still working out what it means for their day-to-day operations.<\/p>\n<\/div>\n<p class=\"primary-medium-text ui-mb-sm-1\">The directive draws a clear line between two types of organizations:<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><b>Essential entities<\/b>: large organizations in sectors like energy, transport, banking, healthcare, digital infrastructure, and public administration. These face the most rigorous supervision and mandatory incident reporting requirements.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><b>Important entities<\/b>: mid-sized organizations spread across a broader range of sectors. Oversight is somewhat lighter, but the underlying security obligations are largely the same.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-sm-1\">What NIS2 actually requires organizations to do:<\/p>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Maintain risk analysis and information security policies<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Handle and report incidents within defined timeframes<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Plan for business continuity and crisis scenarios<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Assess <a href=\"https:\/\/trueconf.com\/blog\/productivity\/security-policies-for-an-organization\" target=\"_blank\" rel=\"noopener\">supply chain security<\/a><\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Ensure secure acquisition, development, and maintenance of systems<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Run cybersecurity training and awareness programs<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Apply <a href=\"https:\/\/trueconf.com\/features\/core\/encryption.html\" target=\"_blank\" rel=\"noopener\">cryptography and encryption<\/a> where appropriate<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Enforce access controls and manage assets properly<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Implement multi-factor authentication (MFA) across secure communications<\/li>\n<\/ul>\n<\/div>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><em>For important entities, the maximum fine is \u20ac7 million or 1.4% of global annual turnover, whichever is higher. Notably, NIS2 also introduces direct management liability, meaning executives can be held personally accountable.<\/em><\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Why Your Communication Stack Is a Compliance Risk?<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">Here&#8217;s something that often gets overlooked: NIS2 risk-management obligations apply to the network and information systems organizations use to store, process, and transmit data, including communication tools that carry sensitive organizational information.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">These systems touch strategic decisions, client communications, and internal data that organizations genuinely cannot afford to expose.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Where standard communication tools tend to fall short:<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Unauthorized access to live meetings or archived message histories<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Video, audio, and file transfers sent without encryption in transit<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Data sovereignty gaps when content is processed or stored by non-EU cloud providers<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Weak access controls that let unauthorized participants into calls or file repositories<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Absent audit trails that make incident investigation, and NIS2 reporting, practically impossible<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Uncontrolled third-party integrations that quietly expand your attack surface<\/li>\n<\/ul>\n<\/div>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><em>NIS2 holds organizations accountable for the security posture of their technology vendors. If your cloud conferencing provider suffers a breach that exposes your data, that&#8217;s your compliance problem too. Deploying on your own infrastructure cuts out this third-party dependency entirely.<\/em><\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Security Risks Broken Down by Communication Channel<\/h2>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Video Conferencing<\/h3>\n<table style=\"overflow-x: auto; display: block;\">\n<thead style=\"background: #F7F9FC;\">\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Risk<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>What It Means in Practice<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Uncontrolled external sharing<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Consumer-grade file tools routinely bypass corporate security policies<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Missing access controls<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Files without role-based permissions create broad, unnecessary data exposure<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>No integrity verification<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Without versioning, spotting unauthorized modifications is extremely difficult<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Insecure sync integrations<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Tools that connect to personal cloud storage are a persistent data leakage risk<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Messaging<\/h3>\n<table style=\"overflow-x: auto; display: block;\">\n<thead style=\"background: #F7F9FC;\">\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Risk<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>What It Means in Practice<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Plaintext storage<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Messages stored without encryption at rest are fully exposed in any breach scenario<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>No transit encryption<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Messages routed via external servers can be read by the provider or intercepted en route<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Uncontrolled retention<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Without configurable policies, sensitive conversations accumulate without limit<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Missing <a href=\"https:\/\/trueconf.com\/products\/monitor.html\" target=\"_blank\" rel=\"noopener\">audit logs<\/a><\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Reconstructing communications during an incident investigation becomes impossible<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">File Sharing<\/h3>\n<table style=\"overflow-x: auto; display: block;\">\n<thead style=\"background: #F7F9FC;\">\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Risk<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>What It Means in Practice<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Uncontrolled external sharing<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Consumer-grade file tools routinely bypass corporate security policies<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Missing access controls<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Files without role-based permissions create broad, unnecessary data exposure<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>No integrity verification<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Without versioning, spotting unauthorized modifications is extremely difficult<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Insecure sync integrations<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Tools that connect to personal cloud storage are a persistent data leakage risk<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">How TrueConf Server Addresses NIS2 Requirements?<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-45446 size-full\" title=\"How TrueConf Server Addresses NIS2 Requirements\" src=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/05\/34.png\" alt=\"How TrueConf Server Addresses NIS2 Requirements\" width=\"467\" height=\"382\" \/ loading=\"lazy\"><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">TrueConf Server is a self-hosted unified communications platform that organizations deploy on their own infrastructure, whether that&#8217;s on-site servers, a private cloud environment, or a fully air-gapped network. The organization controls the deployment environment, security configuration, data flows, and integration choices, which can make the communications layer easier to align with internal security and compliance policies.<\/p>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Data Sovereignty<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">In an on-premises or isolated deployment, video conferences, chats, files, and recordings can remain within the organization\u2019s own infrastructure. This reduces reliance on third-party cloud processing and supports NIS2 supply-chain risk management, although external integrations, federation, streaming, SMTP, and push-notification flows should still be reviewed as part of the organization\u2019s security assessment.<\/p>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Encryption<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">TrueConf Server protects communications traffic with encryption mechanisms built into its architecture:<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text\">\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\"><em>TLS-based protection<\/em> for signaling and control data<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><em>AES-256<\/em> for media traffic in the TrueConf protocol<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><em>DTLS\/SRTP<\/em> for WebRTC media paths<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><em>H.235<\/em> for H.323 scenarios<\/li>\n<\/ul>\n<\/div>\n<p class=\"primary-medium-text ui-mb-sm-1\">These protections are part of the platform\u2019s communications architecture. For stored recordings, chat files, and other data at rest, organizations should also apply appropriate infrastructure-level controls, such as disk or partition encryption, retention policies, and access restrictions.<\/p>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Access Control and Multi-Factor Authentication<\/h3>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text\">\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Integration with <a href=\"https:\/\/trueconf.com\/blog\/wiki\/active-directory-ldap\" target=\"_blank\" rel=\"noopener\">Active Directory and LDAP<\/a> for centralized enterprise identity management<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><a href=\"https:\/\/trueconf.com\/features\/types\/role.html\" target=\"_blank\" rel=\"noopener\">Role-based access controls<\/a> applied consistently across all platform functions<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">MFA support for all users, directly aligned with NIS2&#8217;s explicit MFA requirement<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Administrator-defined permissions governing who can schedule meetings, access recordings, share files, and manage the system<\/li>\n<\/ul>\n<\/div>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Audit Logging<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">TrueConf Server provides reports and logs covering user connections, calls, messages, conference recordings, server events, and settings-change history:<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text\">\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Ongoing internal security monitoring<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Meeting NIS2&#8217;s incident reporting obligations<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Providing the evidentiary record needed for post-incident forensic reconstruction<\/li>\n<\/ul>\n<\/div>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Isolated and Air-Gapped Deployment<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">TrueConf Server can operate in completely isolated environments with zero internet connectivity. For organizations in defense, critical infrastructure, government, and other high-assurance environments where strict network segregation may be required, this capability is essential rather than optional.<\/p>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Secure External Collaboration<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">Guests and external participants can join TrueConf meetings through a browser-based WebRTC client, without installing a dedicated conferencing application or creating accounts on external conferencing platforms. Access is controlled through:<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text\">\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Guest permissions<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Conference-level access restrictions<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Registration and approval settings<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Administrator-defined policies for external users<\/li>\n<\/ul>\n<\/div>\n<p class=\"primary-medium-text ui-mb-sm-1\">There&#8217;s no dependency on external authentication providers or third-party identity systems.<\/p>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Business Continuity<\/h3>\n<p class=\"primary-medium-text ui-mb-sm-1\">TrueConf Server can support <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/business-continuity-management\" target=\"_blank\" rel=\"noopener\">business continuity<\/a> planning by giving organizations control over the deployment environment and operational procedures:<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text\">\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Backup and restore of server settings<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Real-time and historical server monitoring<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Organization-controlled maintenance windows<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Disaster recovery planning based on the organization\u2019s own infrastructure architecture<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">NIS2 Requirement Mapping<\/h2>\n<table style=\"overflow-x: auto; display: block;\">\n<thead style=\"background: #F7F9FC;\">\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>NIS2 Requirement<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>TrueConf Server Capability<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Cryptography and encryption<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">TLS-based protection for signaling\/control data, AES-256 for TrueConf media traffic, DTLS\/SRTP for WebRTC, SRTP for SIP, H.235 for H.323 scenarios<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Access control and MFA<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">AD\/LDAP integration, group-based permissions, role-based administration, and 2FA\/MFA support depending on configuration<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Incident handling and audit<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Reports and logs for connections, calls, messages, recordings, server events, and settings-change history<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Supply chain security<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">On-premises or isolated deployment reduces third-party cloud processing, external integrations still require risk assessment<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Business continuity<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Backup and restore, monitoring, organization-controlled maintenance, and infrastructure-level disaster recovery planning<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Data protection<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Communications data can remain within the organization\u2019s infrastructure in properly configured on-premises or isolated deployments<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Secure communications policy<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Security settings, access rules, authentication options, and user permissions can be configured and enforced at platform level<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div style=\"background: #00B3CD; border-radius: 12px; padding: 24px;\">\n<h2 class=\"h4--main h4--thick white-text center-text ui-mb-xs-3\">Empower your video conferencing experience with TrueConf!<\/h2>\n<div class=\"button-group-container button-group-container--center\"><a class=\"primary-smallest-text to-page to-page--rarr white-icon white-text\" role=\"link\" href=\"https:\/\/trueconf.com\/products\/server\/video-conferencing-server.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Learn more<\/a><\/div>\n<\/div>\n<section id=\"faq\">\n<h2 class=\"h3--main h3--thick black-text ui-mb-md-1\">FAQ<\/h2>\n<div class=\"faq__container ui-mb-md-1\">\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Does TrueConf Server guarantee NIS2 compliance?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">No single product can guarantee NIS2 compliance, and any vendor that claims otherwise is oversimplifying. Compliance depends on how an organization implements, configures, and operates its systems, alongside broader internal policies and governance. TrueConf Server provides technical controls that can help organizations address NIS2 requirements at the communications layer; overall compliance remains the organization&#8217;s responsibility.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Is TrueConf Server appropriate for NIS2 essential entities?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">Yes, the on-premises deployment model, encryption, MFA support, role-based access controls, comprehensive audit logging, and air-gapped deployment capability make TrueConf Server a strong candidate for organizations classified as essential entities, provided it is configured, governed, and operated in line with the organization\u2019s broader NIS2 compliance program.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Does TrueConf Server work with existing security infrastructure?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">Yes, TrueConf Server integrates with enterprise identity providers via LDAP and Active Directory, can support SIEM workflows through log or report export, depending on the organization\u2019s integration approach, and deploys behind existing firewalls and network security controls without requiring architectural changes.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">How does TrueConf Server support NIS2 incident reporting?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">The platform&#8217;s audit logs provide the evidentiary foundation that incident investigation and regulatory reporting depend on. Reports and logs covering connections, calls, messages, recordings, server events, and settings-change history can help security teams investigate communications-layer activity and prepare incident evidence where relevant.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">How should organizations evaluate TrueConf Server for their NIS2 requirements?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">The most effective starting point is a technical consultation with TrueConf focused on your organization\u2019s sector, infrastructure model, communication workflows, and applicable NIS2 obligations. TrueConf specialists can help assess deployment options, security controls, integration requirements, and compliance-related configuration scenarios for your environment.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<div class=\"accent-note accent-note--special ui-mb-sm-1\">\n<p class=\"primary-medium-text\"><strong><i>About the Author<\/i><\/strong><br \/>\n<i>Diana Shtapova is a product specialist and technology writer with three years of experience in the unified communications industry. At TrueConf, she leverages her deep product expertise to create clear and practical content on video conferencing platforms, collaboration tools, and enterprise communication solutions. With a strong background in product research and user-focused content development, Diana helps professionals and businesses understand core product features, adopt new technologies, and unlock the full potential of modern collaboration software.<\/i><\/p>\n<p><a class=\"primary-small-text to-page to-page--rarr cyan-icon\" role=\"link\" href=\"https:\/\/www.facebook.com\/shtapovadiana\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\"><i>Connect with Diana on Facebook<\/i><\/a><\/p>\n<\/div>\n<p><script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Does TrueConf Server guarantee NIS2 compliance?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"No single product can guarantee NIS2 compliance, and any vendor that claims otherwise is oversimplifying. Compliance depends on how an organization implements, configures, and operates its systems, alongside broader internal policies and governance. TrueConf Server provides technical controls that can help organizations address NIS2 requirements at the communications layer; overall compliance remains the organization's responsibility.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Is TrueConf Server appropriate for NIS2 essential entities?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Yes, the on-premises deployment model, encryption, MFA support, role-based access controls, comprehensive audit logging, and air-gapped deployment capability make TrueConf Server a strong candidate for organizations classified as essential entities, provided it is configured, governed, and operated in line with the organization\u2019s broader NIS2 compliance program.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Does TrueConf Server work with existing security infrastructure?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Yes, TrueConf Server integrates with enterprise identity providers via LDAP and Active Directory, can support SIEM workflows through log or report export, depending on the organization\u2019s integration approach, and deploys behind existing firewalls and network security controls without requiring architectural changes.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"How does TrueConf Server support NIS2 incident reporting?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"The platform's audit logs provide the evidentiary foundation that incident investigation and regulatory reporting depend on. Reports and logs covering connections, calls, messages, recordings, server events, and settings-change history can help security teams investigate communications-layer activity and prepare incident evidence where relevant.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"How should organizations evaluate TrueConf Server for their NIS2 requirements?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"The most effective starting point is a technical consultation with TrueConf focused on your organization\u2019s sector, infrastructure model, communication workflows, and applicable NIS2 obligations. TrueConf specialists can help assess deployment options, security controls, integration requirements, and compliance-related configuration scenarios for your environment.\"\n      }\n    }\n  ]\n}\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>NIS2 (Network and Information Security Directive 2) is the EU&#8217;s updated cybersecurity framework, which entered into force on 16 January 2023 replacing the original NIS Directive from 2016. Member states had until 17 October 2024 to transpose it into national legislation, with the rules applying from 18 October 2024, and many organizations are still working [&hellip;]<\/p>\n","protected":false},"author":78,"featured_media":48632,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[32],"tags":[386,393,387],"class_list":["post-48619","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-reviews-comparisons","tag-security","tag-unified-communications","tag-video-conferencing","wpautop"],"_links":{"self":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts\/48619","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/users\/78"}],"replies":[{"embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/comments?post=48619"}],"version-history":[{"count":15,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts\/48619\/revisions"}],"predecessor-version":[{"id":48649,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts\/48619\/revisions\/48649"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/media\/48632"}],"wp:attachment":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/media?parent=48619"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/categories?post=48619"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/tags?post=48619"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}