Regulation does not protect a plant by itself, but it structures the work, sets deadlines and defines the evidence you must be able to produce. Here, each framework is translated into what it means for OT.
The three frameworks that apply to an industrial plant
NIS2 — EU Directive 2022/2555
The framework that covers the greatest share of industry: energy, chemicals, food, water, transport and manufacturing, among others. Risk management, incident reporting within fixed deadlines and personal accountability for management.
The technical reference series for industrial automation system security. It is not law, but it is the common language: zones and conduits, security levels and role-based requirements. NIS2 audits use it as a benchmark.
The Spanish National Security Framework applies to the Spanish public sector and its suppliers. If your company operates infrastructure for a public authority—water, transport or waste—it affects you more than is often assumed.
The Cyber Resilience Act (EU Regulation 2024/2847) is aimed not at plant operators, but at manufacturers of products with digital elements: it determines CE marking and therefore access to the European market. We cover it separately because the stakeholder is different: R&D and product, not security.
ISO 27001 is the general-purpose information security management system. When an industrial organisation already has one, we extend its scope to OT; when it does not, it helps structure governance. What it means in OT.
For groups with an international presence, two others come into play: the NIST Cybersecurity Framework as a common language for maturity (identify, protect, detect, respond and recover), and NERC CIP in the North American electricity sector. They are not mandatory in Spain, but we use them as references when defining the strategy.