NL

NIS2 for manufacturing companies: what does it mean for your business?

Date: 04-09-2026

What impact does NIS2 have on SMEs in the manufacturing industry? This is a question we are regularly asked at SBL Cyber Monitoring. The short answer is that it depends on the organisation, its size, its activities and the EU countries in which it operates. Even if your organisation does not fall directly within the scope of NIS2, you may still encounter its requirements through customers and supply chain partners.

In this article, we explain what NIS2 requires, which manufacturing companies may fall within its scope and which steps organisations can take to prepare.
 

What is NIS2?

NIS refers to network and information systems. NIS2 is the second EU directive aimed at achieving a consistently high level of cybersecurity across the European Union. It replaces and expands the original NIS Directive.

NIS2 entered into force in January 2023. EU Member States were required to transpose the directive into national legislation by 17 October 2024. Because NIS2 is an EU directive, the precise registration, reporting, supervision and enforcement procedures may differ between countries.

The directive expands the number of sectors and organisations covered by European cybersecurity legislation. It also introduces more detailed requirements for cybersecurity risk management, incident reporting, supply chain security and management accountability.

More information about the directive is available on the European Commission’s NIS2 information page.
 

The main differences between NIS1 and NIS2

The main difference between NIS1 and NIS2 is that stricter cybersecurity requirements now apply to a wider range of organisations and sectors. More organisations are expected to identify their cyber risks, implement appropriate security measures and report significant incidents.

The most important changes include:

  • NIS2 covers more sectors than NIS1, including postal and courier services, waste management, food production, chemicals, digital services and the manufacture of certain critical products.
  • As a general rule, medium-sized and large organisations operating within the sectors covered by NIS2 fall within its scope. Certain organisations may be included regardless of their size.
  • Incident-reporting requirements have been expanded. Significant incidents must be reported within specific timeframes to the relevant national authority or Computer Security Incident Response Team.
  • NIS2 introduces stronger supervision and higher potential penalties for non-compliance.
  • Organisations must address cybersecurity risks within their supply chains and relationships with direct suppliers and service providers.
  • Senior management is responsible for approving and overseeing cybersecurity risk-management measures.
  • For manufacturing companies, relevant operational technology and connected production systems must be included when assessing and managing risks to network and information systems.
     

Does NIS2 apply to SMEs in the manufacturing industry?

The first consideration is the sector in which an organisation operates. NIS2 covers critical sectors such as energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space.

It also covers other critical sectors, including postal and courier services, waste management, food production and distribution, chemicals, research and the manufacture of certain critical products.

Manufacturing activities covered by NIS2 include certain organisations involved in the manufacture of:

  • Medical devices and in-vitro diagnostic medical devices
  • Computer, electronic and optical products
  • Electrical equipment
  • Machinery and equipment
  • Motor vehicles, trailers and semi-trailers
  • Other transport equipment


The second consideration is the size of the organisation. As a general rule, NIS2 applies to medium-sized and large organisations in the sectors covered by the directive. The assessment is based on the EU definition of company size and considers employee numbers, annual turnover and balance-sheet total.

However, size is not the only determining factor. Certain organisations may fall within the scope of NIS2 regardless of their size, for example because they provide a particularly critical service or because disruption could have a significant impact on society or the economy. The exact scope can also depend on the way NIS2 has been implemented in the relevant EU Member State.

Supply chain security is another important consideration. Organisations that fall directly under NIS2 are required to address cybersecurity risks associated with their suppliers and service providers. A supplier may fail to deliver following a cyberattack or may provide attackers with an indirect route into a customer’s systems.

This means that many manufacturing companies will face stricter cybersecurity requirements even when they do not fall directly within the scope of NIS2. Larger or regulated customers may require suppliers to demonstrate that appropriate cybersecurity measures are in place.
 

“Many organisations do not yet realise how important cybersecurity will become within supply chains. A major driving force will be larger companies expecting their suppliers to demonstrate that their cybersecurity is properly managed.”

Stef Liethoff, founder of SBL Cyber Monitoring
 

What does NIS2 mean for businesses in the UK?

NIS2 is an EU directive and does not automatically apply to organisations operating exclusively in the United Kingdom. The UK has its own cybersecurity legislation, including the Network and Information Systems Regulations.

However, NIS2 may still be relevant to UK organisations that:

  • Have offices, subsidiaries or operations within the European Union
  • Provide services covered by NIS2 within the EU
  • Supply products or services to European organisations that fall under NIS2
  • Form part of an international supply chain with European customers


Even where a UK organisation is not directly subject to NIS2, European customers may include comparable cybersecurity, incident-reporting and supply chain requirements in their contracts.
 

What obligations apply to organisations covered by NIS2?

If your organisation falls directly within the scope of NIS2, the precise procedures will depend on the national legislation of the EU Member State in which you operate. The main obligations generally include:

  • Registration: Organisations may be required to register with the competent authority in the relevant EU Member State. Registration procedures and responsible authorities differ between countries.
  • Cybersecurity risk management: Organisations must assess cybersecurity risks and implement appropriate and proportionate technical, operational and organisational measures. Senior management must approve and oversee these measures and may be required to complete relevant training.
  • Incident reporting: Significant incidents must be reported to the relevant national authority or CSIRT. NIS2 includes an initial early-warning deadline of 24 hours, followed by additional reporting obligations as more information becomes available.
  • Supervision: Organisations covered by NIS2 are subject to supervision and enforcement. The responsible supervisory authority and exact procedures depend on the sector and the national legislation of each EU Member State.


NIS2 identifies a number of cybersecurity risk-management measures that organisations should address:

  • Measure 1: Policies for risk analysis and the security of information systems. 
  • Measure 2: Human resources security, access control policies and asset management. 
  • Measure 3: Business continuity measures, including backup management, disaster recovery and crisis management. 
  • Measure 4: Incident prevention, detection, response and recovery. 
  • Measure 5: Basic cyber hygiene practices and cybersecurity training. 
  • Measure 6: Security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure. 
  • Measure 7: Supply chain security, including security-related aspects concerning direct suppliers and service providers. 
  • Measure 8: Policies and procedures concerning the use of cryptography and encryption. 
  • Measure 9: The use of multi-factor authentication or continuous authentication solutions and secure voice, video, text and emergency communication systems, where appropriate. 
  • Measure 10: Policies and procedures for assessing the effectiveness of cybersecurity risk-management measures.

 

What are the NIS2 incident-reporting requirements?

Organisations covered by NIS2 must report significant incidents to the relevant national authority or CSIRT. Whether an incident is considered significant depends on factors such as the severity and duration of the disruption, the number of affected customers or users and the financial or operational impact.

The reporting process generally includes:

  • An early warning within 24 hours of becoming aware of a significant incident
  • An incident notification within 72 hours, including an initial assessment of the incident
  • Intermediate updates when requested by the competent authority or CSIRT
  • A final report, generally no later than one month after the incident notification


National legislation may provide further details about how incidents must be reported and which authority should receive the report.
 

What happens if your organisation does not comply with NIS2?

NIS2 gives national authorities stronger powers to supervise organisations and enforce compliance. Measures can include instructions to remedy security weaknesses, audits, inspections and administrative fines.

For essential entities, NIS2 provides for maximum administrative fines of at least €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, the maximum is at least €7 million or 1.4% of total worldwide annual turnover, whichever is higher. The exact penalties and enforcement procedures depend on national implementation.

Senior management can also be held responsible for approving and overseeing cybersecurity risk-management measures, subject to the legislation of the relevant country.

If your organisation does not fall directly within the scope of NIS2, regulatory fines may not be the most immediate concern. However, customers that are covered by NIS2 must manage risks within their supply chains. They may impose stricter cybersecurity requirements, request evidence of compliance or choose suppliers that can demonstrate stronger cyber resilience.
 

How do you determine whether your organisation falls under NIS2?

To determine whether NIS2 applies to your organisation, consider:

  • The EU Member States in which your organisation operates or provides services
  • The sector and manufacturing activities of your organisation
  • The number of employees, annual turnover and balance-sheet total
  • Whether your organisation provides services considered critical under national legislation
  • Whether a national authority has specifically identified your organisation as an essential or important entity


Because NIS2 is implemented through national legislation, organisations should consult the official guidance and competent authority in each relevant EU Member State. UK organisations should also assess whether their European activities or customer relationships create direct or contractual NIS2 requirements.
 

How can your organisation prepare for NIS2?

A cybersecurity assessment is a practical starting point for preparing for NIS2. It provides insight into your most important systems, vulnerabilities, external connections and dependencies. This should include both the IT environment and, where relevant, the OT network and connected production systems.

Important preparatory steps include:

  • Identifying critical systems, data and business processes
  • Conducting a cybersecurity risk assessment
  • Reviewing access rights and implementing multi-factor authentication
  • Keeping software, systems and production equipment up to date
  • Separating IT and OT networks where appropriate
  • Protecting and testing backups
  • Assessing cybersecurity risks within the supply chain
  • Preparing and testing an incident response plan
  • Implementing continuous monitoring and effective detection and response
  • Documenting security measures and management responsibilities


Whether your organisation is directly covered by NIS2 or faces its requirements through customers and supply chain partners, improving cyber resilience is becoming increasingly important.

Contact SBL Cyber Monitoring to discuss how your organisation can assess its cyber risks and prepare for NIS2.