NIS2 for Manufacturers: The Complete Guide
The NIS2 Directive (EU) 2022/2555 replaced the original NIS Directive and dramatically widened its scope to include manufacturing, machinery, computer/electronics and medical device companies as "important entities." If your factory or industrial business falls within these newly named sectors, you now carry direct legal duties on cybersecurity governance, risk management and incident reporting — with personal liability for management bodies who fail to oversee compliance.
This article is general information, not legal advice. NIS2 transposition varies by EU member state and several are still finalising their national laws as of 2026. Always confirm the current requirements, deadlines and penalty figures that apply in your specific country with a qualified compliance consultant or lawyer before making decisions.
Why NIS2 matters to manufacturers now
The original NIS Directive (2016) focused narrowly on operators of essential services — energy, transport, banking, health and digital infrastructure. NIS2 expanded that list substantially and, critically for industrial businesses, introduced a formal split between two schedules of covered sectors: Annex I and Annex II.
Annex I lists sectors treated as "highly critical" — energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration and space. Annex II lists "important" sectors, and this is where manufacturing sits. Annex II explicitly names manufacturing of machinery and equipment, computers, electronic and optical products, and — significantly for many IgeraIndustria clients — the manufacture of medical devices and in vitro diagnostic medical devices. If your company makes any of these, NIS2 is not a theoretical concern; it is a direct legal obligation.
Essential vs important entity: how classification works
NIS2 sorts covered organisations into two tiers — "essential entities" and "important entities" — each carrying different levels of regulatory oversight and, in some member states, different enforcement intensity. Classification depends on a combination of two things: which sector your activity falls under (Annex I vs Annex II) and whether your organisation meets certain size thresholds, based on the EU's own definitions of company size set out in Recommendation 2003/361/EC (the standard EU framework for micro, small, medium and large enterprises, using employee headcount and turnover or balance sheet figures).
We deliberately avoid quoting one fixed employee count or turnover figure here as "the" threshold for every manufacturer, because the size bands and their effect on classification vary depending on the specific sector and sub-category involved, and because some entities can be brought into scope regardless of size in certain circumstances. Most manufacturing entities within Annex II sectors that qualify as medium or large enterprises will fall under NIS2 as important entities, but the precise cut-off for your NACE activity code and company size should be checked against your national transposition law or with a qualified adviser rather than assumed from a generic figure. We cover this classification question in full in our dedicated Article 3 entity classification deep dive.
The structural spine of NIS2: four articles every manufacturer should know
NIS2 is a long directive, but for an industrial business, four articles do most of the practical work. Think of this section as the map — each of these gets its own dedicated deep-dive article on our blog.
Article 3 — Essential vs important entity classification
Defines which entities fall in scope and under which tier, based on the Annex I/Annex II sector lists combined with the size-threshold logic described above. Getting this classification right is the first step, because it determines which supervisory regime and penalty tier applies to your organisation.
Article 20 — Management body governance and liability
This is the article that changes the conversation from "an IT problem" to "a boardroom problem." Article 20 requires the management body of an in-scope entity to approve the organisation's cybersecurity risk-management measures, oversee their implementation, and undergo training to understand and assess cyber risk. Directors and senior managers can be held personally liable for failures in this oversight duty — notably, liability provisions in NIS2 are framed in a way that does not require proof of gross negligence in every case, which is a materially stricter standard than many manufacturers are used to under general corporate governance rules.
Article 21 — Risk management measures (the ten minimums)
Article 21 sets out a baseline of cybersecurity risk-management measures that in-scope entities must implement, applying an "all-hazards" approach proportionate to risk. The ten areas it covers are:
- Risk analysis and information system security policies
- Incident handling
- Business continuity, such as backup management and disaster recovery, and crisis management
- Supply chain security, including security-related aspects concerning relationships with suppliers and service providers
- Security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure
- Policies and procedures to assess the effectiveness of cybersecurity risk-management measures
- Basic cyber hygiene practices and cybersecurity training
- Policies and procedures regarding the use of cryptography and, where appropriate, encryption
- Human resources security, access control policies and asset management
- The use of multi-factor authentication or continuous authentication solutions, secured voice/video/text communications, and secured emergency communication systems where appropriate
For a manufacturer, several of these map directly onto existing quality and OT (operational technology) practices — business continuity and asset management, for instance, often already exist in some form under ISO 9001 or ISO 27001 programmes. The gap is usually documentation, formal risk analysis, and extending controls to OT/ICS environments that were historically treated as separate from IT security. We break down implementation of each of the ten measures in our dedicated Article 21 risk measures article.
Article 21(3) — Supply chain security deserves its own spotlight
Supply chain security is called out specifically within Article 21 rather than being folded silently into general risk management, and for good reason. Manufacturing businesses typically sit inside dense, multi-tier supplier networks — component suppliers, contract manufacturers, machinery vendors, software and SCADA/PLC providers. NIS2 requires entities to assess and manage cybersecurity risk arising from these relationships, not just from their own internal systems. In practice, this means procurement processes, supplier security questionnaires and contractual security clauses become part of your compliance posture, not just your IT department's.
Article 23 — Incident reporting obligations
Article 23 introduces a structured, time-bound reporting sequence for significant incidents, owed to the relevant national CSIRT (Computer Security Incident Response Team) or competent authority:
- Within 24 hours of becoming aware of a significant incident — an early warning, indicating whether the incident is suspected to be caused by unlawful or malicious acts or could have a cross-border impact
- Within 72 hours — a fuller incident notification, updating the early warning with an initial assessment of severity and impact, plus indicators of compromise where available
- Within one month of the incident notification — a final report, including a detailed description of the incident, its root cause, the mitigation measures applied and, where relevant, its cross-border impact
For a manufacturer, this timeline is demanding precisely because production-line incidents (ransomware halting an MES, a compromised PLC, a supplier breach affecting your ERP) can be hard to scope quickly. Having an incident response plan and a pre-agreed escalation chain before an incident occurs is what makes the 24-hour window realistic. Full detail on preparing for each stage is in our dedicated Article 23 incident reporting timelines article.
NIS2 sets an upper ceiling on administrative fines that is generally described as up to €10 million or 2% of a company's total worldwide annual turnover for the preceding financial year, whichever is higher, for essential entities — with a lower tier of maximum fines applying to important entities (the tier manufacturing typically falls into under Annex II). These figures come from the directive itself, but how they are transposed, calculated and enforced can differ by member state, and some national laws may apply additional conditions, aggravating factors or procedural steps before a fine of this size is imposed. Treat the €10 million / 2% figure as the EU-level ceiling to be aware of, not as a number that will apply identically, automatically or at that exact level in every country — confirm the transposed penalty regime for your jurisdiction with a qualified adviser.
Transposition deadlines: check your own country, don't assume a single EU-wide date
The NIS2 Directive set October 2024 as the deadline by which EU member states were meant to transpose it into national law. In practice, transposition has proceeded unevenly, and as of 2026 a number of member states are still in the process of finalising or refining their national implementing legislation. This matters directly for manufacturers because the specific classification thresholds, penalty amounts, supervisory authority and enforcement timeline you are subject to are defined by your national law, not by the EU directive text alone. Do not assume a single uniform EU-wide date or figure applies to your business — check the current status of transposition in the country (or countries) where your entities operate, ideally with local legal counsel.
Practical impact: what this actually changes on the factory floor
For most manufacturers, NIS2 compliance is less about buying new security tools and more about formalising, documenting and governing what may already exist informally:
- Governance shifts upward. Cybersecurity risk oversight becomes a board-level and management-body responsibility, not something delegated entirely to IT or OT engineers.
- OT and IT security converge. Industrial control systems, SCADA and PLC environments — historically managed separately from corporate IT — now need to be included in risk analysis and incident response planning.
- Supplier due diligence becomes contractual. Expect new security clauses in supplier and machinery vendor contracts, and expect your own customers to start asking you the same questions.
- Documentation becomes evidence. Policies, training records, risk assessments and incident logs need to be maintained in a form that can be produced quickly if a supervisory authority asks — or if an incident triggers the 24-hour reporting clock.
Common mistakes manufacturers make with NIS2
- Assuming "we're too small" without checking the actual thresholds. Size-threshold rules vary by sector and category — don't self-exclude based on a rule of thumb from a different industry.
- Treating this as purely an IT department project. Article 20 puts oversight duty squarely on the management body; leaving the board out of the loop is itself a compliance gap.
- Ignoring OT/ICS systems in the risk assessment. Article 21's scope covers network and information systems broadly — production-line systems are not automatically out of scope just because they're air-gapped or legacy.
- Waiting for an incident to design the reporting process. The 24-hour early-warning clock starts the moment you become aware of a significant incident — you cannot build an escalation chain retroactively under that pressure.
- Assuming one EU-wide deadline or fine figure applies everywhere. National transposition laws differ; always verify against the specific country your entity is registered and operating in.
- Scattering the evidence across email threads and shared drives. When a supervisory authority or auditor asks for proof of a specific control, being unable to locate or cite the source document quickly is itself a red flag.
Where IgeraIndustria fits
Much of the operational burden of NIS2 compliance comes down to being able to answer, quickly and precisely, "where is the evidence for this control?" IgeraIndustria is built for exactly that: it is an AI assistant that answers directly from your own compliance, quality and risk-management documents — policies, risk assessments, supplier contracts, training records — citing the exact source document and clause behind every answer. Instead of your team hunting through shared drives when a question comes in from a client, an auditor or your own management body, IgeraIndustria surfaces the relevant passage instantly, with the citation to back it up.
Frequently asked questions
Does NIS2 apply to my manufacturing company?
It may, if your activity falls under an Annex II sector — which explicitly includes manufacturing of machinery and equipment, computers and electronics, and medical devices — and your organisation meets the relevant size thresholds under your national transposition law. Confirm your specific classification with a qualified adviser rather than assuming based on general company size alone.
What is the difference between an essential entity and an important entity?
Both categories carry cybersecurity obligations under NIS2, but essential entities (mostly Annex I sectors such as energy, transport and health) face more intensive supervisory oversight and a higher penalty ceiling than important entities, the tier most manufacturing businesses under Annex II fall into.
Can company directors be personally liable under NIS2?
Article 20 places approval and oversight duties for cybersecurity risk-management measures directly on the management body, and liability provisions in NIS2 are framed in a way that does not require proof of gross negligence in every scenario. This makes director-level engagement with compliance a genuine governance issue, not just an operational one.
How quickly do we have to report a cybersecurity incident?
Article 23 sets a three-stage timeline: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month of that notification.
What are the maximum fines for non-compliance?
The directive frames the ceiling for essential entities as up to €10 million or 2% of global annual turnover, whichever is higher, with a lower tier for important entities. How this is applied in practice depends on your national transposition law, so treat this as a general ceiling, not a guaranteed or automatic figure.
Has the NIS2 transposition deadline already passed?
The EU-level transposition deadline was October 2024, but as of 2026 several member states are still finalising their national implementing laws. Always check the current status and requirements in the specific country where your entity operates rather than assuming a single uniform EU-wide date applies.
Does supply chain security really need its own compliance effort?
Yes. Article 21(3) calls out supply chain security specifically because manufacturers typically rely on multi-tier supplier networks. NIS2 requires assessing and managing cybersecurity risk arising from suppliers and service providers, not just internal systems, which usually means new supplier questionnaires and contract clauses.
Disclaimer: This article provides general information about the NIS2 Directive and is not legal or certification advice. Cybersecurity regulation, national transposition laws, classification thresholds and penalty regimes are subject to ongoing change and vary by member state. Before making compliance decisions, consult a qualified compliance consultant or lawyer familiar with the current law in your jurisdiction.