Mar 15, 2026

NIS2 compliance for manufacturing: get your OT visible and audit ready

What does NIS2 mean for manufacturing? Find out if your company is in scope, what the duty of care and reporting rules require and how OT asset visibility gets you audit ready.

NIS2 compliance for manufacturing: get your OT visible and audit ready

What is NIS2?

NIS2 is the European directive for network and information security, the successor of the first NIS directive from 2016. Its goal: raising the digital resilience of essential and important sectors across the entire EU. The directive has applied at European level since January 2023 and is being transposed into national law in every member state; in the Netherlands this happens through the Cyberbeveiligingswet, expected to enter into force in the course of 2026.

For companies in scope, NIS2 comes down to three things: a duty of care (take appropriate security measures and be able to prove them), a reporting duty (notify the supervisory authority of serious incidents quickly) and a registration duty. New compared to the old rules: management itself is responsible for compliance and can be held personally accountable in case of negligence.

Waiting for the final legal text is not a strategy. The requirements have been known in outline for years, no transition period has been announced and the measures themselves, from risk analysis to asset management, take time to implement.

Does NIS2 apply to your manufacturing company?

Unlike under the first NIS directive, manufacturing is now explicitly on the list. As an important sector, it covers producers of food, chemicals, medical devices, electronics, machinery and vehicles, among others. The rule of thumb for size: from fifty employees or ten million euros in annual turnover, you are in scope.

But even companies outside those criteria will feel NIS2. The directive obliges companies to secure their supply chain, so large customers will start asking their suppliers for demonstrable security. For many suppliers in manufacturing, the NIS2 requirements will not come from the regulator but from their own order book.

Why OT is the blind spot in NIS2

At most manufacturing companies, office IT is reasonably under control: there is an IT partner, there are backups and antivirus is running. On the factory floor, things look different. PLCs, operator panels, drives, sensors and gateways have sometimes been in service for twenty years, next to production PCs with outdated operating systems and machine vendors with remote access.

Legacy Siemens PLC in a control cabinet, an example of OT equipment that often stays out of sight

That operational technology (OT) also falls under NIS2: network and information systems include everything that touches your production. And this is where it hurts, because most companies have no current overview of what runs on the factory floor, which firmware it carries and what is connected to the network. You cannot protect what you cannot see, and during an audit you cannot prove anything about equipment that is not registered anywhere.

The NIS2 requirements in short

The NIS2 duty of care asks for appropriate measures based on a risk analysis. In practice, this includes:

  • Risk analysis and security policy: knowing where you are vulnerable and what you are doing about it.
  • Asset management: a current overview of systems, equipment and connections, including in the factory.
  • Access control: who is allowed into which system, with MFA where possible, including remote access by vendors.
  • Business continuity: backups, recovery plans and practising for outages.
  • Supply chain security: setting requirements for suppliers and service providers.
  • Incident handling and reporting: a serious incident requires an early warning within 24 hours, a full notification within 72 hours and a final report within one month.

The fines are serious: for essential entities up to ten million euros or two percent of worldwide annual turnover, for important entities up to seven million euros or 1.4 percent.

NIS2 starts with visibility: map your OT assets

Every measure above leans on the same foundation: knowing what you have. That is why a current OT asset register is the logical first step towards NIS2. Per machine and per cabinet, that register answers the questions an auditor will ask too: what is it, where is it, which software and firmware does it run, what does it communicate with and who can access it?

Such an inventory does not have to touch production. By passively monitoring the network and reading out existing PLCs, a picture emerges of all equipment and connections without changing anything in the control systems. The same connections you build for Industry 4.0 and the smart factory to unlock machine data also deliver the visibility NIS2 asks for. Security and digitalisation are two sides of the same coin here.

What matters is that the register stays alive. A one off inventory in a spreadsheet is outdated at the first change. In a platform such as MeshOS, the asset overview is part of the digital twin of your factory: changes, failures and connections are tracked continuously instead of reconstructed once a year.

From visibility to audit: demonstrably in control

NIS2 does not only ask you to take measures, it asks you to prove them. With a living asset register as the foundation, that suddenly becomes feasible:

  • Network segmentation: show which zones exist, what flows between office and factory and where the boundaries sit. This is the core of secure IT and OT integration.
  • Logging and detection: record who accessed which machine and when, and flag unusual behaviour on the network.
  • Patch policy: show per asset which version runs, what the risk is and how the decision to update or not was made. In OT, patching immediately is not always possible; a documented decision counts as well.
  • Reporting duty: in an incident you need the facts within 24 hours. A current overview of systems and connections makes the difference between guessing and reporting.

Step by step: ready for NIS2 in five steps

  1. Determine your position: is your company in scope as an essential or important entity, or do the requirements reach you through customers in the chain?
  2. Inventory your OT: map machines, control systems, networks and external access, and keep that overview current.
  3. Run a risk analysis: determine per system what the impact of outage or abuse would be and where the biggest risks sit.
  4. Take measures: segment the network, arrange access control and backups, make agreements with suppliers and set up monitoring.
  5. Anchor and practise: document policy, train staff and management, rehearse the incident process and keep evidence for the audit.

Frequently asked questions about NIS2

When does NIS2 take effect in the Netherlands?

The European directive has applied since January 2023 and should have been transposed into national law by October 2024. The Netherlands does this through the Cyberbeveiligingswet, expected to enter into force in the course of 2026. From that moment the obligations apply immediately; no transition period has been announced.

Does my manufacturing company fall under NIS2?

Manufacturing is designated as an important sector, covering producers of food, chemicals, medical devices, electronics, machinery and vehicles. The rule of thumb: from fifty employees or ten million euros in annual turnover you are in scope. Smaller suppliers often receive the requirements through their customers.

What are the fines under NIS2?

Essential entities risk fines up to ten million euros or two percent of worldwide annual turnover, important entities up to seven million euros or 1.4 percent. In addition, management can be held personally liable in case of negligence.

What is the difference between NIS1 and NIS2?

NIS2 applies to far more sectors, including manufacturing, sets stricter requirements for the duty of care and incident reporting, raises the fines considerably and places responsibility explicitly with management.

Does OT count for NIS2?

Yes. Network and information systems include the control systems on the factory floor: PLCs, operator panels, industrial networks and remote access by vendors. A risk analysis that only looks at office IT is not complete for a manufacturing company.

Conclusion: start with visibility, the rest follows

For many manufacturers NIS2 feels like a paper exercise, but the core is very practical: know what runs in your factory, protect it in proportion to the risk and be able to show you are in control. A current view of your OT assets is the first and most important step, and it directly delivers the foundation for further digitalisation as well.

Meshnex helps manufacturers map their OT and connect it securely to IT, from asset inventory to network segmentation and monitoring. Curious where your factory stands? Contact us or read more about our approach.

Back to Blog