NIS2 applied to the plant
EU Directive 2022/2555 dramatically expands both the companies in scope and what is required of them. If you operate in energy, chemicals, water, food, transport or manufacturing, it will most likely affect you.
NIS2 classifies organisations as essential or important according to their sector and size, and imposes almost the same requirements on both; the supervisory regime and maximum penalties differ. The sectors listed in its annexes cover most process and manufacturing industries from medium-sized enterprises upwards.
Two features set it apart from everything before it. First, management is accountable: it must approve and oversee the measures and receive training; Article 20 allows personal liability to be enforced. Second, reporting deadlines are fixed and short, and begin when the organisation becomes aware of an incident, not when it fully understands it.
| Requirement | What it means in OT |
|---|---|
| Art. 21.1 — Risk management | The risk analysis must also cover the control network, which requires something almost no one has: an accurate inventory of OT assets and their connections. |
| Art. 21.2.a — Risk analysis and information system security policies | Policies that explicitly name control systems, rather than generic “information systems”. A procedure that ignores PLCs does not cover the plant. |
| Art. 21.2.b — Incident handling | A response plan that knows what can and cannot be isolated. Containment without process awareness may cause more damage than the attack. |
| Art. 21.2.c — Business continuity and backups | Industrial backups too: PLC configurations, SCADA projects and recipes. Restoring the ERP will not restart the plant. |
| Art. 21.2.d — Supply-chain security | Integrators and manufacturers with remote access to your plant form part of your risk. You need to know who connects, how and with which permissions. |
| Art. 21.2.e — Security in acquisition and development | Require security specifications when purchasing a new control system; once it is commissioned, remediation costs ten times more. |
| Art. 21.2.f — Assessment of effectiveness | Having measures is not enough: they must be tested. Audits, technical tests and exercises, with evidence that they were performed. |
| Art. 21.2.g — Cyber hygiene and training | Training for operations and maintenance too, not only office staff. The contractor technician brings the USB drive through the plant door. |
| Art. 21.2.h/i — Cryptography and access control | MFA for remote OT access and named accounts wherever possible. The shared “maintenance” account with a password from 2009 is incompatible with this. |
| Art. 23 — Incident reporting | Early warning to the authority within 24 hours, notification within 72 hours and a final report within one month. Without OT detection and assigned owners, these deadlines cannot be met. |
| Art. 20 — Management accountability and training | Management bodies approve the measures, oversee their implementation and must receive training. Non-compliance may result in personal liability. |
| Arts. 32–36 — Supervision and penalties | Fines of up to €10 million or 2% of global turnover for essential entities (€7 million or 1.4% for important entities), in addition to inspection powers. |
There is no “NIS2 product”. Compliance comes from structured work, and almost everything the directive requires in OT corresponds to services we already provide:
- OT assessment — the Article 21 risk analysis begins with knowing what is there.
- IT/OT segmentation — the most significant technical measure in Article 21.2 and the first one auditors examine.
- Managed IT/OT services — without detection, there is no way to discover an incident in time to report it.
- IT and OT incident response — playbooks, process-aware containment and readiness for the Article 23 deadlines.
- Training — including the training Article 20 requires for management bodies.