Yes. The optional application-layer encryption described above is genuinely end-to-end: it uses an application key the network components never hold, so the security guideline states explicitly that the data is never available unencrypted on its way through the mioty network when this is used. For devices with over-the-air attachment, a fresh application session key is derived for every session, and perfect forward secrecy can additionally be applied so that even a future key compromise cannot expose previously recorded traffic. This matters most where the network is operated as a service by a third party, which is a common arrangement in metering.