In September 2025, Jaguar Land Rover shut down production across the UK, Slovakia, and Brazil for five weeks after a ransomware attack. Reuters reported losses of around £50 million a week, with 33,000 staff sent home and hundreds of suppliers unable to operate. The intrusion started in IT, but what stopped production was how deeply the manufacturing floor depended on that IT. If you manufacture in Europe, that story is also a preview of your regulatory reality. Manufacturing is explicitly in scope under NIS2. The real challenge is not reading the directive. It is bridging decades of OT technical debt with a security framework designed for IT, the same gap that any serious digital manufacturing programme has to close anyway. If your OT network is invisible to your IT team, you are already non-compliant.

NIS2 in 60 seconds

  • Manufacturing is in scope, and size decides. NIS1 left manufacturing out; NIS2 covers chemicals, food, medical devices, electronics, electrical equipment, machinery, and transport equipment. You are in if you have 50 or more employees or €10 million or more in annual turnover. Nobody has to designate you as critical first, which is why the scope jumped from roughly 15,000 entities to an estimated 160,000.
  • Your deadline comes from national law, not from Brussels. Registration windows, supervisory authorities, and enforcement dates differ from country to country, and a group with plants in three member states will face three different timetables.
  • The clock on an incident is 24 hours. An early warning within 24 hours of becoming aware of a significant incident, a fuller report within 72 hours, a final report within one month. A halted production line qualifies as significant.
  • Your board is personally on the hook. Under Article 20, senior management must approve and oversee the cybersecurity measures, and executives who neglect this can be suspended from management roles. Fines reach €10 million or 2% of global turnover for essential entities, €7 million or 1.4% for important entities, where most manufacturers land.

Who Must Comply: Manufacturing Is Now Explicitly in Scope

The NIS2 directive (EU Directive 2022/2555) replaced NIS1 in October 2024, raising the baseline for cyber resilience across the European Union. Your exact deadlines depend on where you manufacture: see where your country stands.

Manufacturing was a notable NIS1 absence. The NIS2 directive fixed that. It now covers chemicals, food products, medical devices, computer, electronic and optical products, electrical equipment, machinery, and transport equipment, alongside energy, water, transport, banking, health, and digital infrastructure. If your plant produces any of these and you meet the size threshold, you are covered.

The threshold is based on company size, not designation by authorities (unlike NIS1). You are in scope if you are medium-sized (50+ employees OR €10M+ turnover) or larger, operating in a covered sector. This size-based rule is why the scope jumped from roughly 15,000 entities under NIS1 to an estimated 160,000 essential and important entities under NIS2.

Essential Entity or Important Entity: Which Category Is Your Plant?

The NIS2 directive splits covered organisations into two tiers. Essential Entities (EE) face stricter supervision, proactive audits, and fines up to €10 million or 2% of global annual turnover, whichever is higher. Important Entities (IE) face reactive supervision and fines up to €7 million or 1.4% of global turnover.

Most manufacturing companies land in the Important Entity category. Essential Entity status is reserved for specific large producers in critical sub-sectors or companies providing essential services to the broader economy. But watch national transpositions. Germany’s law (NIS2UmsuCG) is broader than the base directive, Austria’s NISG 2026 introduces its own national variations, and Poland’s KSC Act has sector-specific additions. If you operate across multiple EU countries, your classification may differ from plant to plant.

Where NIS2 Stands in Your Country

NIS2 is a directive, not a regulation. Your obligations, registration deadlines, and penalties do not come from Brussels: they come from your national transposition law. That is why a manufacturer with plants in three countries can face three different registration windows, three supervisory authorities, and three enforcement timetables for the same directive.

Last verified: 11 August 2026. Transposition status changes frequently; confirm with your national authority before acting.

Enforcement is live

CountryNational lawIn force sinceWhat is due nextAuthority
BelgiumLaw of 26 April 202418 Oct 2024Essential entities had to submit conformity evidence (CyFun verification or ISO 27001) by 18 Apr 2026; full CyFun target level by 18 Apr 2027CCB
CroatiaCybersecurity Act (OG 14/2024)15 Feb 2024Entity categorisation complete; supervision runningNCSC (SOA)
ItalyLegislative Decree 138/202416 Oct 2024Cohort-based phase-in: incident reporting since Jan 2026, security measures by Oct 2026 for the first ACN listACN
FinlandCybersecurity Act 124/20258 Apr 2025Registration and risk-management arrangements already dueTraficom / NCSC-FI
DenmarkNIS2 Act (No 434 of 6 May 2025)1 Jul 2025Registration via Virk.dk closed 1 Oct 2025; supervision runningDanish Agency for Societal Security
CzechiaAct No 264/2025 Coll.1 Nov 2025Self-identification to NÚKIB was due within 60 days of entry into forceNÚKIB
GermanyNIS2UmsuCG6 Dec 2025BSI registration portal open; statutory deadline for day-one entities has expiredBSI
SwedenCybersecurity Act (SFS 2025:1506)15 Jan 2026Self-identification and registration via the national notification service; sector-based supervisionNCSC-SE and sector authorities
PolandKSC Act amendment (Dz.U. 2026 poz. 252)3 Apr 2026Registration by 3 Oct 2026; information security management system (SZBI) by 3 Apr 2027Sector authorities / CSIRT
PortugalDecree-Law 125/2025 (RJC)3 Apr 2026Phased self-identification on the CNCS platformCNCS
LuxembourgLaw of 5 May 202610 May 2026Self-registration via ILR closed 10 Jul 2026ILR (CSSF for finance)

Adopted, not yet applicable

CountryNational lawApplies fromWhat this means now
NetherlandsCyberbeveiligingswet15 Aug 2026Adopted by the Senate on 7 July 2026. Registration and reporting duties start with entry into force
AustriaNISG 2026 (BGBl. I Nr. 94/2025)1 Oct 2026Registration within three months of applicability and no later than 31 Dec 2026; a new Federal Office for Cybersecurity takes over supervision

Still legislating

CountryStatusWhat this means now
FranceThe resilience bill was adopted by the Senate in March 2025 and cleared its special commission in September 2025, but no plenary vote has been recorded and no law has been promulgated. Referred to the Court of Justice of the EU on 8 July 2026You cannot register yet. ANSSI published the Référentiel Cyber France (ReCyF) on 17 March 2026: not binding until the implementing decrees, but already the working reference
IrelandNational Cyber Security Bill still in drafting; referred to the CJEU on 8 July 2026The NIS1 regime remains in effect
SpainFull transposition not notified; referred to the CJEU on 8 July 2026No national NIS2 registration route yet

Outside the EU, still in your supply chain

CountryFrameworkStatus
United KingdomCyber Security and Resilience BillCleared the Commons in June 2026, Lords second reading 14 July 2026, committee stage from September 2026. Royal Assent expected in 2026, with obligations phased in through secondary legislation. It brings 24-hour and 72-hour reporting and turnover-based penalties into the NIS Regulations 2018
NorwayDigital Security Act (digitalsikkerhetsloven)In force since 1 Oct 2025 at NIS1 level. NIS2 alignment follows incorporation into the EEA Agreement; verify current scope with NSM
SwitzerlandInformation Security Act (ISG) and Cybersecurity OrdinanceMandatory 24-hour reporting of cyberattacks on critical infrastructure to the NCSC since 1 Apr 2025, with a 14-day follow-up report. Penalties up to CHF 100,000 apply since 1 Oct 2025

What the NIS2 Directive Actually Requires from Your OT Environment

Article 21 of the NIS2 directive lists ten cybersecurity measures that essential and important entities must implement. The directive does not prescribe specific tools. It demands appropriate security measures proportionate to the risk, and tells EU member states to translate that into national supervision and enforcement measures.

For manufacturing, four of those cybersecurity measures are where the operational pain lives: incident reporting, network segmentation, supply chain security, and vulnerability management. The rest, including cryptography, access control, training, business continuity and crisis management, are mandatory but more familiar to IT teams.

Four NIS2 cybersecurity requirements for OT environments: incident reporting (Art. 23), network segmentation (Art. 21), supply chain security (Art. 21), and vulnerability management (Art. 23)

A practical note. The NIS2 directive tells you what to achieve. It does not tell you how. This is why IEC 62443 keeps appearing as the de facto implementation framework for OT. It gives you the zones and conduits model, maturity levels, and concrete technical controls that map onto the directive’s risk-based language. Treat the NIS2 directive and IEC 62443 as complementary, not competing.

Incident Reporting: 24 Hours Is Not Much Time in a Plant

The NIS2 directive mandates a three-stage reporting cadence for significant security incidents:

1

Detection

2
24h
Early warning within 24 hours of becoming aware of a significant incident
3
72h

Incident report within 72 hours with initial assessment of impact

4
1 month

Final report within one month
Where NIS2 Stands in Your Country

NIS2 is a directive, not a regulation. Your obligations, registration deadlines, and penalties do not come from Brussels: they come from your national transposition law. That is why a manufacturer with plants in three countries can face three different registration windows, three supervisory authorities, and three enforcement timetables for the same directive.

Last verified: 11 August 2026. Transposition status change

A „significant incident” is one that causes substantial operational disruption, financial loss, or affects third parties. A halted production line qualifies.

Here is where manufacturing stumbles. Most plants have OT incident procedures oriented around safety and downtime, not cyber threats. A SCADA anomaly at 02:00 rarely triggers a call to a national CSIRT. The operations team isolates the issue, restores production, and moves on. Under the NIS2 directive, that same anomaly, if caused by unauthorised access or malicious code, starts a 24-hour clock you may already have missed.

You need a classification workflow that connects OT events (abnormal PLC behaviour, unexpected HMI activity, unknown device on the control network) to regulatory reporting, before an incident happens. Retrofitting this under pressure is how plants miss deadlines.

Network Segmentation and IT-OT Zones

Segmentation is where the NIS2 directive’s theoretical requirements collide with twenty years of accumulated plant architecture. The directive expects logical separation between OT and IT networks, with monitored boundaries.

In practice, most plants have informal IT-OT connectivity nobody documented. A remote maintenance laptop that plugs into the PLC rack. An ERP integration that pulls production data over a flat network. A supervisory PC that also has corporate email installed. The Purdue Model zones you drew on a whiteboard five years ago rarely match what is actually running on your shop floor today.

The JLR case made this vivid. Attackers entered through an IT-side supplier, moved laterally, and reached systems that, on paper, should have been isolated from production. Once lateral movement reached the OT boundary, a purely IT incident became a five-week manufacturing halt.

Proper segmentation under the NIS2 directive means an enforceable DMZ between OT and IT, firewalls or data diodes at zone boundaries, documented data flows, and continuous monitoring of crossing traffic. In most plants, this starts with a painful asset discovery exercise.

The Real Challenge: OT Was Never Built for Compliance

This is where manufacturing differs from every other sector covered by the NIS2 directive.

The average industrial control system has a lifecycle of 15 to 25 years. PLCs commissioned in 2008 are still running production lines in 2026. Many run unsupported operating systems (Windows CE, Windows 7, even XP for HMI panels). The industrial protocols they speak (Modbus, DNP3, legacy OPC) have no built-in authentication. They were engineered for reliability and determinism, not against modern cyber threats. The ransomware surge in manufacturing, a 56% increase year-on-year in 2025 per Check Point, is not happening because factories are careless. It is happening because the installed base was never built to defend itself, and the cost of disruption makes manufacturers attractive ransom targets.

Vulnerability management is one of the ten Article 21 measures, and in IT the answer is simple: apply the patch, close the gap, move on. In OT it breaks immediately.

That PLC from 2008 may carry an unpatched vulnerability that has been public knowledge for six years. The vendor knows. Your IT team knows. The reason it has not been patched is not negligence. It is that patching it requires a planned production stop, a vendor engineer on-site, a full regression test of the control logic, and in some cases re-certification of the safety system under IEC 61511. The cost and disruption can easily run to six figures for a single asset. Multiply that across a plant floor with 40 controllers and the economics stop the conversation before it starts.

The situation is worse for HMI panels running Windows XP or Windows CE, where no patch exists at all. Microsoft stopped issuing security updates for Windows XP in 2014. The HMI vendor may have certified their software against that specific OS version and will not support an upgrade. The plant is left with a known, unresolvable vulnerability on a networked system, and a NIS2 obligation to manage risk on it.

This is the patching paradox: the directive requires you to address risk on assets that the industry’s primary risk-management tool cannot touch.

IEC 62443 resolves this explicitly, and the NIS2 directive’s risk-based language accepts the resolution: compensating controls. When you cannot eliminate a vulnerability at the asset level, you contain it at the network level. Isolate the unpatched PLC behind an industrial firewall. Apply virtual patching, a rule at the network boundary that blocks traffic patterns known to exploit the vulnerability, without touching the controller itself. Enforce application whitelisting so only known-good processes can execute on the HMI. Use passive anomaly detection that monitors OT traffic without sending packets that could disrupt deterministic control loops.

 Compensating controls for unpatched legacy OT assets: network isolation, virtual patching, application whitelisting, and passive anomaly monitoring

Done properly, compensating controls do not just neutralise individual vulnerabilities. They produce something more important: an architectural layer between your fragile legacy assets and everything else on the network. That layer is also the foundation of real OT visibility – which is where the compliance story and the operational modernisation story start to converge.

The Architecture Argument: Compliance as a By-Product, Not a Project

There is a way through the OT compliance puzzle that does not require a separate compliance programme running indefinitely on the side of your operations.

The same project that modernises your plant connectivity – establishing proper asset visibility, creating a plant-wide data layer, segmenting OT zones – produces exactly the evidence base the NIS2 directive requires: a complete asset inventory, documented data flows, access logs, and a defensible risk management story you can present to your supervisory authority.

This is not a rationalisation. It is how real OT security is built. Layering controls onto a fragile architectural foundation produces a compliance checklist, not cyber resilience. Fixing the foundation – clean network segmentation, a unified data layer that makes OT visible to IT without collapsing the boundary between them, proper access management for vendor remote sessions – produces both.

The practical implication for project sequencing: your NIS2 gap assessment should inform your modernisation roadmap, and your modernisation roadmap should be sequenced so that compliance milestones land as outputs of work you were already going to do. That alignment is where the real budget argument lives when you take this to the board.

Management Liability: This Is a Board-Level Issue

If only one point from this article reaches your leadership, make it this one.

Article 20 of the NIS2 directive makes senior management personally responsible for approving cybersecurity measures and overseeing their implementation, including crisis management arrangements. Executives who neglect this can be suspended from management roles. Training for management bodies is explicitly required. The Dutch transposition (Cyberbeveiligingswet, which took effect in August 2026) spells out that delegating entirely to IT without active oversight creates direct personal exposure.

The rough analogue is the General Data Protection Regulation, which did to data protection what the NIS2 directive is doing to OT cybersecurity. Five years ago, a CIO could tell the board „we have it handled.” That answer no longer works under a directive that names individuals. Much like the General Data Protection Regulation, NIS2 puts accountability on specific people, not just processes.

Splunk’s 2026 CISO report found that 78% of security leaders are concerned about personal liability. They are right to be. And in manufacturing, where the CISO often has limited visibility into the plant floor, the liability is shared with COOs, plant managers, and operations directors who actually control OT decisions.

Practical implication: OT cybersecurity is no longer an IT line item. It is a board risk that needs a budget, an owner, and a reporting cadence.

Common Misconceptions About the NIS2 Directive in Manufacturing

  1. „We’re not critical infrastructure, so NIS2 doesn’t apply.” Manufacturing is explicitly in scope as of October 2024. Size-based thresholds, not critical-infrastructure designation, determine applicability. Many manufacturers now fall into the same compliance bracket as operators in traditional critical infrastructure sectors such as energy and water.
  2. „Our OT is air-gapped, we’re safe.” Air-gapped in 2010, maybe. In 2026, almost every plant has some form of IT-OT connectivity: remote maintenance, MES integration, cloud analytics, predictive maintenance platforms. The first step of any NIS2 project usually reveals that the air gap is marketing, not architecture.
  3. „ISO 27001 covers us.” It helps but does not equal NIS2 compliance. ISO 27001 is an IT-centric information security standard. The NIS2 directive specifically demands OT coverage, concrete responses to industrial cyber threats, and stricter incident reporting timelines.
  4. „We’ll deal with it when enforcement hits.” Enforcement is already live in Germany, Belgium, Italy, and the Nordics. Belgium’s first conformity deadline passed in April 2026, and Poland’s registration window closes on 3 October 2026. France is the outlier, not the rule. Check the table above for your own country.

Urgency: The Enforcement Curve Is Steepening

The window between „NIS2 exists” and „NIS2 is enforced against manufacturers” is closing fast across Europe. EU member states that transposed in 2024 are now conducting systematic supervisory assessments and applying the first enforcement measures. Those transposing in 2025 and 2026 have compressed enforcement ramps because the Commission is applying pressure through infringement proceedings.

Meanwhile, the threat environment is not waiting. Manufacturing has been the most-targeted sector for cyber threats four consecutive years. Dragos tracked 119 ransomware groups targeting industrial organisations in 2025 – a 49% increase year on year – collectively impacting more than 3,300 organisations. Manufacturing accounted for more than two-thirds of all victims. Of the ransomware incidents Dragos responded to, 75% led to partial OT shutdown and 25% to a full production halt.

The manufacturers who move first have time to run proper gap assessments, sequence remediation into planned shutdowns, and align compliance work with already-budgeted modernisation. The ones who wait will be doing all of this under regulatory scrutiny, after their first significant incident, or both.

Where to Start

Before any remediation work, you need a clear picture of where you actually stand. A structured OT Security Assessment gives you four things:

  • A gap map against Article 21, showing where your current environment meets the requirements and where it does not
  • Your three highest-priority gaps, ranked by risk rather than by ease of fixing
  • A remediation roadmap sequenced around your production calendar, not against it
  • A document you can hand to your board and to your supervisory authority, grounded in the actual state of your plant rather than a theoretical framework

One point worth flagging. An assessment run by a pure cybersecurity auditor finds security gaps. An assessment run by an IT-OT integration partner with hands-on plant experience also finds the architectural opportunities, where the same project can fix technical debt, improve operational visibility, and deliver compliance as a by-product. In manufacturing, where every intervention has to fit around production, that distinction matters.

Start with a conversation, not a project
One session with an OT security architect tells you where your gaps are and what a realistic scope looks like. A full assessment for a single plant runs three to four weeks.
Book a call

Frequently Asked Questions