NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new →
NIS2 for Manufacturers: Scope and Obligations
Learn

NIS2 for Manufacturers: Scope and Obligations

·Alexander Sverdlov

NIS2 covers a manufacturer if two things are true: it carries out an activity listed in Annex I or II of Directive (EU) 2022/2555, and it is at least a medium-sized enterprise. Annex II, sector 5, lists six manufacturing subsectors: medical devices and in vitro diagnostic devices, and the NACE Rev. 2 divisions C26 computer, electronic and optical products, C27 electrical equipment, C28 machinery and equipment, C29 motor vehicles, trailers and semi-trailers, and C30 other transport equipment. Chemicals and food production sit in their own Annex II sectors, and pharmaceuticals in Annex I. Most manufacturers in scope are important entities, not essential ones, because Annex II entities are important whatever their size unless a Member State designates them otherwise.

Being important does not lighten the measures. Important entities owe the same Article 21 cybersecurity risk management measures, the same Article 23 reporting clocks and the same Article 20 management body duties as essential ones. What differs is supervision, which is ex post, and the fine ceiling. The directive had to be transposed by 17 October 2024 and applied from 18 October 2024, so the obligations reach you through your national law, and the general scope rules are in our guide to what NIS2 is and who must comply.

What you makeWhere NIS2 lists itTier if large
Computers, electronics, optical products (C26)Annex II, 5(b)Important
Electrical equipment (C27)Annex II, 5(c)Important
Machinery and equipment n.e.c. (C28)Annex II, 5(d)Important
Motor vehicles, trailers, semi-trailers (C29)Annex II, 5(e)Important
Other transport equipment (C30)Annex II, 5(f)Important
Medical devices and in vitro diagnosticsAnnex II, 5(a)Important
Substances, mixtures and articles under REACHAnnex II, sector 3Important
Food, industrial production and processingAnnex II, sector 4Important
Pharmaceuticals (C21), and devices critical in a public health emergencyAnnex I, healthEssential
Manufacturing in NIS2 Annex II, sector 5: medical devices and in vitro diagnostics, NACE C26 electronics, C27 electrical equipment, C28 machinery, C29 motor vehicles and C30 other transport equipment

Which manufacturers are in scope of NIS2?

Start with the activity. Annex II defines the manufacturing subsectors by NACE Rev. 2 division, so the test is whether you carry out any of the economic activities in divisions 26 to 30, not what your marketing says you make. The medical devices entry covers manufacturers of devices under Regulation (EU) 2017/745 and in vitro diagnostics under Regulation (EU) 2017/746, except those manufacturing devices considered critical during a public health emergency, which Annex I lists under health alongside manufacturers of basic pharmaceutical products and preparations in NACE division 21.

Two other Annex II sectors catch manufacturers that do not think of themselves as chemical or food companies. Sector 3 covers undertakings manufacturing substances and distributing substances or mixtures under REACH, and undertakings producing articles from substances or mixtures. Sector 4 covers food businesses engaged in wholesale distribution and industrial production and processing.

Does the size test apply to the plant or the group?

Article 2(1) applies NIS2 to entities that qualify as medium-sized enterprises under Article 2 of the Annex to Commission Recommendation 2003/361/EC, or exceed the medium-sized ceilings. Under that Recommendation, a small enterprise employs fewer than 50 persons and has an annual turnover and/or balance sheet total not above EUR 10 million, and the SME category ends at fewer than 250 persons with turnover not above EUR 50 million and/or a balance sheet not above EUR 43 million. In practice that means you are at least medium-sized with 50 or more staff, or with both turnover and balance sheet above EUR 10 million.

The Recommendation counts partner and linked enterprises, so a small subsidiary of a large industrial group can be counted as large. Recital 16 of NIS2 lets Member States take into account the degree of independence the entity has from its partner or linked enterprises, in particular in the network and information systems it uses and the services it provides, and treat it on its own data where appropriate. Whether your Member State does so is a national question. A plant that shares the group's domain, ERP and remote access is a weak candidate for that relief.

Is your plant in scope of NIS2: find your NACE code, apply the size test, check whether the activity is in Annex I or Annex II, decide essential or important, and register nationally

Essential or important, and why it matters

Article 3(1)(a) makes Annex I entities that exceed the medium-sized ceilings essential. Article 3(2) makes every other Annex I or II entity in scope important. An Annex II manufacturer is therefore important at any size, unless it is designated essential by its Member State under Article 3(1)(e) or is a critical entity under the CER Directive, Directive (EU) 2022/2557, under Article 3(1)(f). A large pharmaceutical manufacturer is essential; a large machinery or vehicle manufacturer is important.

The tier changes two things. Supervision: Article 33 has authorities act on important entities through ex post supervisory measures when provided with evidence, indication or information of non-compliance, while Article 32 sets no such trigger for essential entities. And fines: for infringing Article 21 or 23, Article 34(5) sets a maximum of at least EUR 7 million or 1.4% of total worldwide annual turnover of the undertaking the entity belongs to, whichever is higher, against at least EUR 10 million or 2% for essential entities under Article 34(4). These are floors for the national maximum, so your national law may set higher ones. Our guide to NIS2 fines and penalties has the detail.

What do the Article 21 measures mean on a plant floor?

Article 21(1) requires appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems you use for your operations or to provide your services. Article 6(1) defines a network and information system to include any device or group of interconnected devices that carry out automatic processing of digital data under a programme. The definition draws no line between office IT and operational technology: a PLC, an HMI or a historian running your line is a device that processes digital data, and the measures are about the systems you use for your operations.

Article 21(2) sets ten measures on an all-hazards basis, which also protects the physical environment of those systems. On a plant they read like this. Risk analysis covers the lines as well as the ERP. Incident handling and business continuity have to include restarting production, not only restoring email. Supply chain security under 21(2)(d) and 21(3) takes in the machine builders and integrators with remote access to your equipment. Security in acquisition, development and maintenance includes vulnerability handling for the controllers you buy. Access control, asset management, cryptography, multi-factor authentication and training close the list. Article 21(4) requires corrective measures without undue delay where you find you do not comply. Each measure is taken point by point in our guide to NIS2 Article 21 requirements.

Venvera NIS2 gap assessment listing full assessments against the ten Article 21(2) measures with their status and score

What do Articles 20 and 23 add?

Article 20(1) requires the management body to approve the Article 21 measures, oversee their implementation, and be capable of being held liable for infringements. Article 20(2) requires its members to follow training. For a manufacturer, that is the managing board, not the plant IT lead.

Article 23 applies to significant incidents: those that have caused or are capable of causing severe operational disruption of the services or financial loss for the entity, or that affect other persons by causing considerable material or non-material damage. A ransomware outage that stops a line will usually qualify. The entity submits an early warning within 24 hours of becoming aware, an incident notification within 72 hours, an intermediate report on request, and a final report no later than one month after the incident notification. Our comparison of incident reporting deadlines by regulation sets these next to the GDPR and CRA clocks.

NIS2 figures for manufacturers: early warning within 24 hours, incident notification within 72 hours, final report within one month, and a fine ceiling for important entities of at least EUR 7 million or 1.4% of worldwide turnover

How does NIS2 relate to the Cyber Resilience Act?

They regulate different things. NIS2 is about how you secure the systems you run. The Cyber Resilience Act, Regulation (EU) 2024/2847, is about the products with digital elements you place on the market, and it applies to a machine or device you sell whether or not you are an NIS2 entity. A manufacturer of connected equipment can owe both: NIS2 for its own plants and offices, the CRA for its products. The CRA dates are in our guide to Cyber Resilience Act deadlines, and the three regimes are compared in CRA versus NIS2 versus DORA.

What the other results get wrong

The page one results are good on OT inventories and supply chain risk, and three points are easy to miss. The first is vocabulary. A guide dated March 2026 frames manufacturers as operators of essential services and cites an Article 4 on identifying them and an Article 6 on supply chains. That is the structure of the first NIS Directive, Directive (EU) 2016/1148, which NIS2 repealed. Under NIS2 the categories are essential and important entities, set in Article 3, and supply chain security is Article 21(2)(d) and 21(3).

The second is the fine. Another guide gives fines of up to EUR 10 million or 2% of global turnover for manufacturers. That is the essential entity figure. An Annex II manufacturer is an important entity unless designated otherwise, so the Article 34(5) ceiling of at least EUR 7 million or 1.4% applies. The same guide says NIS2 came into effect in December 2020. It was adopted on 14 December 2022 and has applied since 18 October 2024, when it repealed the first NIS Directive.

The third is the size test, which none of the pages we read spell out. Recommendation 2003/361 needs 50 staff, or both turnover and balance sheet above EUR 10 million, not revenue alone, and it counts linked enterprises unless your Member State uses the recital 16 relief.

An illustrative NIS2 Article 21 readiness view per manufacturing site: OT assets in the inventory, remote access paths with multi-factor authentication, critical suppliers assessed, and board members trained

Where does your company stand?

Fill this in per legal entity. A blank cell is the next piece of work.

QuestionYour answerWhy it matters
Which NACE Rev. 2 divisions does each entity carry out?Annex II defines manufacturing by division.
Is each entity medium-sized or larger once linked enterprises are counted?Art. 2(1) and Recommendation 2003/361.
Has any entity been designated essential or identified as a critical entity?Art. 3(1)(e) and (f) move it out of the important tier.
Have you registered with the national authority, and who updates the details?Art. 3(4): changes within two weeks.
Does your risk analysis cover production systems as well as office IT?Art. 6(1) and Art. 21(1).
Which suppliers and integrators have remote access to your equipment?Art. 21(2)(d) and 21(3).
When did the management body approve the measures and last train?Art. 20(1) and (2).
Who sends the early warning within 24 hours, including at night?Art. 23(4)(a).

If most of the column is empty, start with scope and then the risk analysis. Our guide to what to expect from an NIS2 audit covers the supervisory side, the free compliance check gives you a baseline, and the NIS2 framework page shows how the Article 21 measures, registration and the 24 hour clock are tracked as controls with owners and evidence.

Venvera crosswalk matrix mapping controls across frameworks so evidence for NIS2 Article 21 also counts toward ISO 27001 and other frameworks
The bottom line on NIS2 for manufacturers: the directive draws no line between the office network and the plant floor, so neither should your programme

Frequently asked questions

Is manufacturing covered by NIS2?

Yes. Annex II, sector 5, lists medical devices and in vitro diagnostics and NACE Rev. 2 divisions C26 to C30. Chemicals and food production are separate Annex II sectors, and pharmaceuticals are in Annex I.

Are manufacturers essential or important entities?

Annex II manufacturers are important entities at any size, unless a Member State designates them essential or they are critical entities under Directive (EU) 2022/2557. Large pharmaceutical manufacturers in Annex I are essential.

Does NIS2 apply to OT and industrial control systems?

The Article 6(1) definition of a network and information system covers any device that processes digital data under a programme, and Article 21 applies to the systems you use for your operations. It does not carve out operational technology.

Do small manufacturers have to comply?

Generally not. Article 2(1) applies NIS2 to medium-sized enterprises and larger, measured under Recommendation 2003/361, which counts linked enterprises. But Article 2(2) applies it regardless of size in defined cases, for example where the entity is the sole provider in a Member State of a service essential for critical societal or economic activities, or where disruption of its service could have a significant impact on public safety, public security or public health.

What are the reporting deadlines for a manufacturer?

Under Article 23(4), an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of the notification.

Primary sources

Scope, tiers and duties are taken from Articles 2 to 4, 6, 20, 21, 23, 32 to 34 and 41, recital 16 and Annexes I and II of Directive (EU) 2022/2555, and the size categories from Article 2 of the Annex to Commission Recommendation 2003/361/EC. NIS2 is a directive, so the obligations reach you through national transposing law, which can add registration details and set higher fines. Confirm the current text and your national law before relying on a specific provision.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING