NIS2 for Manufacturers: What the Directive Actually Requires

A lot of manufacturers still think of NIS2 as something that applies to power grids, hospitals, and banks. It doesn’t stop there. The directive’s Annex II explicitly lists manufacturing sub-sectors - medical devices, computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment - as “important entities.” If your NACE code falls into one of those categories and you’re a medium or large company, NIS2 already applies to you, whether or not anyone in the business has acted on it yet.

Here’s what that actually means in practice.

1. Who’s in scope

The size thresholds are the first filter: broadly, medium enterprises (50+ employees, or turnover/balance sheet above €10m) and large enterprises (250+ employees, or turnover above €50m) in a covered sector are in scope by default. A handful of smaller entities get pulled in regardless of size if they’re the sole provider of a critical service in their country. Most component and equipment manufacturers reading this fall somewhere in that medium-to-large band once you count group headcount, not just the entity signing contracts.

Manufacturing sits in the “important entity” tier rather than “essential entity” (that’s energy, transport, health, digital infrastructure, banking). The practical difference is supervision: important entities are checked reactively, generally after an incident or a specific indication of non-compliance, rather than through proactive audits. That’s a lower probability of scrutiny, not a lower bar - the obligations themselves are identical.

2. The ten risk-management measures

Article 21 sets out a baseline set of measures every in-scope entity has to implement, “appropriate and proportionate” to its size and risk exposure. In short: risk analysis and security policies, incident handling procedures, business continuity and backup/disaster-recovery plans, supply chain security, security in system acquisition and maintenance (including vulnerability handling), policies for evaluating the measures’ own effectiveness, basic cyber hygiene and staff training, cryptography and encryption use, human resources security and access control, and multi-factor authentication plus secured communications. For most manufacturers the gaps aren’t in IT - they’re in OT: PLCs, SCADA, and machine controllers that were never designed with any of this in mind and have been running unpatched and flat-networked for a decade.

3. Incident reporting on a clock

This is the part that catches people off guard. Once you become aware of a significant incident, you have 24 hours to send an early warning to the national CSIRT or competent authority, 72 hours for a fuller incident notification, and one month for a final report. Nobody has an internal process that hits a 24-hour deadline by accident - it has to be designed and rehearsed, which means someone needs to have already decided what counts as “significant,” who gets the call, and who’s authorized to file the notification at 2 a.m.

4. Your suppliers are now your problem

Supply chain security is a named requirement, not a nice-to-have. If a machine builder, a CAD/CAM vendor, or a remote-maintenance contractor has access to your production systems, their security posture is now something you’re expected to have assessed and managed - contractually and technically. For manufacturers running third-party software on the shop floor (which is most of them), this is usually the least mature area on first assessment.

5. Management is personally on the hook

Article 20 makes the management body responsible for approving the risk-management measures and overseeing their implementation, with liability for infringements and a training obligation attached. This isn’t a policy the CISO signs off on in isolation anymore - it needs a board or ownership-level signature, and the people signing need to actually understand what they’re accountable for.

What it costs to get wrong

Important entities face fines of up to €7m or 1.4% of global annual turnover, whichever is higher - alongside the reputational and operational cost of the incident itself. In practice, the fine is rarely the biggest number; unplanned downtime on a production line during an active incident usually is.

None of this requires ripping out the shop floor and starting over. The realistic starting point is a gap assessment against Article 21’s ten measures, scoped separately for IT and OT, followed by a prioritized remediation plan - which is exactly the kind of engagement we run for manufacturing clients before it becomes an incident report instead of an audit finding.

“In practice, the fine is rarely the biggest number; unplanned downtime on a production line during an active incident usually is.”

Mateusz Konicki