NIS2 Compliance Checklist for Manufacturers (Downloadable)
This checklist walks a manufacturing or industrial company through five practical stages of NIS2 readiness: confirming whether the directive applies at all, checking governance and board sign-off are on record, working through the ten Article 21 security measures item by item, testing incident response readiness against the directive's notification timeline, and reviewing the security posture of key suppliers. Use it as a working self-assessment, not as a substitute for legal or regulatory advice.
NIS2 (Directive (EU) 2022/2555) widened the scope of EU cybersecurity regulation to cover many more manufacturing and industrial companies than the original NIS Directive did, and it did so at a moment when national transposition, guidance, and enforcement practice are still settling into place in several member states. That combination — broader scope, active regulatory development — is exactly why a manufacturer's first move should be a structured self-assessment rather than a guess. This checklist is organised the way an internal readiness review typically runs: classify the entity, confirm governance is documented, work through the security measures, test incident response, and check the supply chain. Treat each section as a working document you return to as your national transposition and your own systems evolve.
A note on regulatory uncertainty: NIS2 transposition, sector guidance, and enforcement practice differ by EU member state and continue to evolve. This checklist deliberately does not state specific article numbers beyond Article 21, exact turnover or headcount thresholds, or fixed penalty figures, because these details depend on your jurisdiction, your national transposing law, and how your specific activity is classified — and because official guidance in this area is still being clarified in several countries. Confirm every classification and deadline against your national competent authority and a qualified compliance advisor before relying on it.
Stage 1 — Entity classification
Before anything else, establish whether NIS2 applies to your organisation at all, and if so, under which tier. This is the step manufacturers most often get wrong, either by assuming NIS2 doesn't apply because they think of themselves as "just a factory," or by assuming it does without checking the specific criteria in their national law.
Checklist — Entity classification
- Have you checked whether your activity falls within an Annex I ("highly critical") or Annex II ("critical") sector as defined by the directive and as transposed into your national law? Manufacturing-related activities appear across both annexes depending on sub-sector, so check the actual wording rather than assuming by industry label.
- Have you checked your organisation's size against the size-cap criteria set out in your national transposing legislation, rather than relying on a general "medium or large company" assumption? Size thresholds and how they are calculated (standalone entity vs. group) vary by member state.
- If you supply, or are a critical link in the supply chain of, an essential or important entity, have you checked whether that relationship brings obligations onto you even if your own size or sector wouldn't otherwise qualify you directly?
- Have you documented the classification decision — the sector reference, the size assessment, and the source (national law, regulator guidance, or legal advice) you relied on — so it can be revisited as guidance is clarified?
Because thresholds and sector definitions are set at national level and are still being clarified through guidance in several jurisdictions, do not treat a classification decision as permanent. Revisit it whenever your national authority publishes new guidance, your group structure changes, or you take on a new customer relationship that changes your position in a regulated supply chain.
Stage 2 — Governance
NIS2 places accountability for cybersecurity risk management squarely with the management body, not just with IT or a security function. For a manufacturer, that means the board or equivalent governing body needs to be able to show — not just claim — that it understands and oversees cybersecurity risk.
Checklist — Governance
- Has the management body received training on cybersecurity risk, sufficient to understand and assess the organisation's exposure — and is that training on record with dates and attendees?
- Has the management body formally approved the organisation's cybersecurity risk-management measures, with the approval minuted rather than assumed?
- Is there a named individual or function accountable for cybersecurity risk management day to day, with a clear reporting line up to the management body?
- Is there a defined cadence for the management body to review cybersecurity posture and incident history, rather than reviewing it only when something goes wrong?
- Can you produce, on request, a dated record of management body training and sign-off going back at least one review cycle?
This record-keeping matters beyond audit readiness. A management body that can point to genuine training and a documented sign-off is in a materially different position — both operationally and in terms of accountability — than one that approved a policy without engaging with what it means.
Stage 3 — The ten Article 21 measures
Article 21 of the directive sets out a baseline of cybersecurity risk-management measures that in-scope entities must implement, applied proportionately to the size and risk profile of the organisation. Use the following as a checkable list — for each item, the practical question is whether you have something documented and operating, not just an intention.
Checklist — Article 21 measures
- 1. Risk analysis and information system security policies. Is there a documented risk analysis covering your IT and, where relevant, OT/industrial control environments, backed by written security policies?
- 2. Incident handling. Is there a documented process for detecting, managing, and recording security incidents, with clear ownership?
- 3. Business continuity and crisis management. Do you have backup management, disaster recovery, and crisis management arrangements that have actually been tested, not just written?
- 4. Supply chain security. Do you assess the security of your direct suppliers and service providers, including the security practices of each supplier relationship? (See Stage 5 below.)
- 5. Security in acquisition, development and maintenance. Are security requirements built into how you procure, develop, and maintain systems, including vulnerability handling and disclosure?
- 6. Policies to assess effectiveness. Do you have a process for evaluating whether your cybersecurity risk-management measures are actually working, not just assuming they are?
- 7. Basic cyber hygiene and training. Is there a training programme covering basic cyber hygiene for staff, appropriate to their role and access?
- 8. Cryptography and encryption. Are policies on the use of cryptography and encryption defined and applied where appropriate to protect sensitive data and systems?
- 9. Human resources, access control, and asset management. Are access control policies and asset management practices documented and enforced, including onboarding and offboarding procedures?
- 10. Multi-factor authentication and secure communications. Is multi-factor authentication (or equivalent) used where appropriate, alongside secure voice, video, and text communication and, where relevant, secure emergency communication systems?
For manufacturers specifically, two of these ten measures deserve extra attention: supply chain security, because production depends on external suppliers of components, software, and services in ways that are easy to underestimate; and business continuity, because an OT/production environment often has different recovery priorities and tolerances than a typical office IT environment. Treat both as areas where a generic corporate policy is unlikely to be sufficient on its own.
Stage 4 — Incident response readiness
NIS2 sets a notification timeline for significant incidents that in-scope entities are expected to follow, built around an early warning, a fuller incident notification, and a final report. The precise wording and deadlines of that timeline are set out in the directive and your national transposing law, and this checklist deliberately does not restate exact hour or day figures here — confirm the current requirement with your national authority or advisor, since the practical detail of how it is applied can vary. What every manufacturer can and should prepare in advance is the operational readiness to meet whatever timeline applies.
Checklist — Incident response readiness
- Is there a named individual (with a backup) responsible for recognising a reportable incident and triggering the notification process, available outside normal office hours?
- Is there a documented escalation path from whoever first detects an incident — a machine operator, an IT technician, a helpdesk ticket — up to the person who decides whether and how to notify the authority?
- Do you know which national authority you would notify, and do you have their current contact and notification channel on file rather than needing to look it up during an incident?
- Do you have draft templates ready for each stage of the notification timeline your national law sets out — an early warning, a fuller notification, and a final report — so the team is filling in facts under pressure, not drafting from a blank page?
- Has the escalation path and notification process been rehearsed at least once, even as a tabletop exercise, rather than existing only as a document?
- Is there a clear internal record of past incidents and near-misses, including what was and wasn't reported, so patterns are visible over time?
The value of pre-built templates is speed under pressure. An incident is a bad moment to be deciding who needs to approve external communications or where the authority's notification portal is. Draft the templates now, store them where the response team can find them immediately, and review them whenever your national guidance is updated.
Stage 5 — Supply chain security review
Supply chain security is one of the ten Article 21 measures, but manufacturers should treat it as its own workstream given how many external parties typically touch a production environment — component suppliers, machine vendors, software and PLC integrators, maintenance contractors, and logistics providers among them.
Checklist — Supply chain security review
- Do you have a current list of key suppliers and service providers — those with access to your systems, data, or production environment, or whose failure would materially disrupt operations?
- For each key supplier, do you know whether they have their own NIS2 obligations, and if so, whether they can evidence compliance?
- Do your supplier contracts include security requirements and, where relevant, a right to request evidence of their security practices?
- Have you assessed the security practices of suppliers with remote or network access to your systems specifically — this is where many real-world incidents originate?
- Is there a process to reassess a supplier's security posture periodically, rather than only at the point of onboarding?
A full third-party security audit of every supplier is rarely realistic. Prioritise the review by access and criticality: suppliers with direct network or system access, and suppliers whose failure would stop production, come first.
Making internal policies and audit evidence instantly searchable
Working through a checklist like this one usually surfaces the same problem: the evidence you need — risk assessments, security policies, supplier contracts, training records, past incident reports — exists somewhere, but finding the right document and the right clause takes time. IgeraIndustria is built to answer questions directly from a manufacturer's own internal security policies and audit evidence, with an exact citation back to the source document, so a compliance lead can ask "when was the management body last trained on cybersecurity risk?" or "which supplier contracts include a security clause?" and get a traceable answer instead of an afternoon spent searching shared drives.
Common mistakes manufacturers make
- Assuming NIS2 doesn't apply without checking the national transposition. Sector scope and size criteria are set at member-state level and can differ in detail from the directive's general framing — a self-assessment against your own national law is not optional.
- Treating governance as a signature on a policy document. A management body that approved a policy without training or genuine engagement is a governance gap, not a governance control.
- Securing IT and overlooking OT. Production environments — PLCs, SCADA systems, industrial networks — often sit outside the scope of a standard corporate IT security review, yet are frequently the most operationally critical systems on site.
- Writing an incident response plan and never rehearsing it. A plan that hasn't been tested tends to reveal its gaps for the first time during an actual incident, which is the worst possible moment.
- Reviewing supplier security once, at onboarding, and never again. A supplier's security posture can change; a review process needs a cadence, not a single checkpoint.
- Relying on last year's guidance. Because transposition and enforcement practice are still developing in several member states, a classification or process that was correct twelve months ago may need revisiting.
Frequently asked questions
Does NIS2 apply to all manufacturers?
Not automatically. Applicability depends on your sector classification under Annex I or Annex II of the directive as transposed into your national law, and on size criteria set at member-state level, so each manufacturer needs to check its own position rather than assume based on industry label alone.
What is the difference between an Essential Entity and an Important Entity?
NIS2 creates two broad tiers of in-scope organisation with different supervision and enforcement approaches, and which tier applies depends on sector and size criteria defined in the directive and refined by national transposing legislation. Confirm your own tier against your national law rather than a general industry assumption.
How quickly must a significant incident be reported under NIS2?
The directive establishes a staged notification timeline for significant incidents — an early warning followed by a fuller notification and, later, a final report — but the precise deadlines and their practical application are set out in the directive text and your national transposing law. Confirm the current requirement with your national competent authority or a qualified advisor, since guidance in this area continues to be clarified.
Who in the organisation is accountable for NIS2 compliance?
The directive places accountability for approving and overseeing cybersecurity risk-management measures with the management body itself, which is why documented board-level training and sign-off matters — accountability cannot simply be delegated to an IT or security team without management body engagement.
Does this checklist cover OT and industrial control systems specifically?
The checklist prompts you to consider OT alongside IT within several Article 21 measures — particularly risk analysis and business continuity — because production environments often carry different risks and recovery priorities than office IT. It is not, however, a substitute for a dedicated OT security assessment carried out by a qualified specialist.
What happens if a manufacturer is not itself in scope but supplies a company that is?
Supply chain security is one of the ten Article 21 measures, so an in-scope customer may reasonably ask its suppliers — including manufacturers not themselves directly in scope — for evidence of their security practices as part of that customer's own compliance obligations. Confirm expectations directly with the relevant customer or partner.
How often should this checklist be reviewed?
Because national transposition, guidance, and enforcement practice are still developing in several member states, treat this as a living document: revisit it whenever your national authority issues new guidance, your organisation's structure or supplier relationships change, or at a minimum on a defined annual cycle.
Disclaimer: This checklist is provided for general informational purposes only and does not constitute legal, regulatory, or certification advice. NIS2 transposition, thresholds, deadlines, and enforcement practice vary by EU member state and are still being clarified in several jurisdictions. Before making any decision that affects your organisation's compliance status, consult the current text of your national transposing legislation, your national competent authority, and a qualified compliance consultant or lawyer.