Each of these should be worth the read whether or not you ever speak to us. Where the answer is "this is not our problem to solve," they say so.
Oil storage and transmission operators are essential entities under Annex I, which means proactive supervision rather than reactive. What the ten Article 21 measures require, the 24h/72h/one-month clock under Article 23, and why eight of the ten are answered with operational records rather than IT controls.
Audits rarely fail on missing records. They fail on records that cannot be assembled in time or traced to a source. The requests that recur, the four properties that make a record hold up, and what "days, not minutes" really costs.
Four routes into a terminal's existing systems, ordered by how little they ask of you, starting with the daily report your gauging system already emails. Plus the one architectural question that decides your OT security review.
Terminal operations glossary: the terms that appear in these guides, defined plainly.
Open the glossary →What the operational layer has done on real terminal operating data, with the limits stated.
Read the case study →Twelve questions on where your operational records actually stand. No contact details required to see the result.
Score your operation →The Terminal Intelligence Brief. One note a month on operational evidence and what it costs to lack it.
See the brief →They are not legal advice, and the NIS2 guide says so on the page. Scope determination and reporting obligations vary by member state and belong with counsel.
They are also not disguised product pages. Where a guide concludes that something is an IT control, or a document management problem, or genuinely handled by your existing CMMS vendor, it says that instead of steering toward us. A guide that finds our product to be the answer to every question would not be worth publishing, and you would recognise it immediately.