What impact does NIS2 have on SMEs in the manufacturing industry? This is a question we are regularly asked at SBL Cyber Monitoring. The short answer is that it depends on the organisation, its size, its activities and the EU countries in which it operates. Even if your organisation does not fall directly within the scope of NIS2, you may still encounter its requirements through customers and supply chain partners.
In this article, we explain what NIS2 requires, which manufacturing companies may fall within its scope and which steps organisations can take to prepare.
NIS refers to network and information systems. NIS2 is the second EU directive aimed at achieving a consistently high level of cybersecurity across the European Union. It replaces and expands the original NIS Directive.
NIS2 entered into force in January 2023. EU Member States were required to transpose the directive into national legislation by 17 October 2024. Because NIS2 is an EU directive, the precise registration, reporting, supervision and enforcement procedures may differ between countries.
The directive expands the number of sectors and organisations covered by European cybersecurity legislation. It also introduces more detailed requirements for cybersecurity risk management, incident reporting, supply chain security and management accountability.
More information about the directive is available on the European Commission’s NIS2 information page.
The main difference between NIS1 and NIS2 is that stricter cybersecurity requirements now apply to a wider range of organisations and sectors. More organisations are expected to identify their cyber risks, implement appropriate security measures and report significant incidents.
The most important changes include:
The first consideration is the sector in which an organisation operates. NIS2 covers critical sectors such as energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space.
It also covers other critical sectors, including postal and courier services, waste management, food production and distribution, chemicals, research and the manufacture of certain critical products.
Manufacturing activities covered by NIS2 include certain organisations involved in the manufacture of:
The second consideration is the size of the organisation. As a general rule, NIS2 applies to medium-sized and large organisations in the sectors covered by the directive. The assessment is based on the EU definition of company size and considers employee numbers, annual turnover and balance-sheet total.
However, size is not the only determining factor. Certain organisations may fall within the scope of NIS2 regardless of their size, for example because they provide a particularly critical service or because disruption could have a significant impact on society or the economy. The exact scope can also depend on the way NIS2 has been implemented in the relevant EU Member State.
Supply chain security is another important consideration. Organisations that fall directly under NIS2 are required to address cybersecurity risks associated with their suppliers and service providers. A supplier may fail to deliver following a cyberattack or may provide attackers with an indirect route into a customer’s systems.
This means that many manufacturing companies will face stricter cybersecurity requirements even when they do not fall directly within the scope of NIS2. Larger or regulated customers may require suppliers to demonstrate that appropriate cybersecurity measures are in place.
“Many organisations do not yet realise how important cybersecurity will become within supply chains. A major driving force will be larger companies expecting their suppliers to demonstrate that their cybersecurity is properly managed.”
Stef Liethoff, founder of SBL Cyber Monitoring
NIS2 is an EU directive and does not automatically apply to organisations operating exclusively in the United Kingdom. The UK has its own cybersecurity legislation, including the Network and Information Systems Regulations.
However, NIS2 may still be relevant to UK organisations that:
Even where a UK organisation is not directly subject to NIS2, European customers may include comparable cybersecurity, incident-reporting and supply chain requirements in their contracts.
If your organisation falls directly within the scope of NIS2, the precise procedures will depend on the national legislation of the EU Member State in which you operate. The main obligations generally include:
NIS2 identifies a number of cybersecurity risk-management measures that organisations should address:
Organisations covered by NIS2 must report significant incidents to the relevant national authority or CSIRT. Whether an incident is considered significant depends on factors such as the severity and duration of the disruption, the number of affected customers or users and the financial or operational impact.
The reporting process generally includes:
National legislation may provide further details about how incidents must be reported and which authority should receive the report.
NIS2 gives national authorities stronger powers to supervise organisations and enforce compliance. Measures can include instructions to remedy security weaknesses, audits, inspections and administrative fines.
For essential entities, NIS2 provides for maximum administrative fines of at least €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, the maximum is at least €7 million or 1.4% of total worldwide annual turnover, whichever is higher. The exact penalties and enforcement procedures depend on national implementation.
Senior management can also be held responsible for approving and overseeing cybersecurity risk-management measures, subject to the legislation of the relevant country.
If your organisation does not fall directly within the scope of NIS2, regulatory fines may not be the most immediate concern. However, customers that are covered by NIS2 must manage risks within their supply chains. They may impose stricter cybersecurity requirements, request evidence of compliance or choose suppliers that can demonstrate stronger cyber resilience.
To determine whether NIS2 applies to your organisation, consider:
Because NIS2 is implemented through national legislation, organisations should consult the official guidance and competent authority in each relevant EU Member State. UK organisations should also assess whether their European activities or customer relationships create direct or contractual NIS2 requirements.
A cybersecurity assessment is a practical starting point for preparing for NIS2. It provides insight into your most important systems, vulnerabilities, external connections and dependencies. This should include both the IT environment and, where relevant, the OT network and connected production systems.
Important preparatory steps include:
Whether your organisation is directly covered by NIS2 or faces its requirements through customers and supply chain partners, improving cyber resilience is becoming increasingly important.
Contact SBL Cyber Monitoring to discuss how your organisation can assess its cyber risks and prepare for NIS2.