hero-bg

The NIS2 directive in the manufacturing sector: a guide for companies

The manufacturing sector has been undergoing an intense digital transformation for years. Automation, robotization, MES systems, integration of IT with OT and the concept of Industry 4.0 are increasing efficiency, but they also bring challenges related to cyber risks. It is in this context that NIS2 is becoming one of the key topics for manufacturing companies in Europe.

The NIS2 directive is not just another abstract regulation “for the IT department.” For industry, it means real requirements that directly affect the continuity of production, the safety of people and the stability of supply chains. It’s an area close to my and explitia‘s philosophy, where technology should support business and production, not generate chaos and uncontrollable risk.

What is NIS2 and why does the manufacturing sector need to take it seriously?

NIS2 is an updated directive on network and information systems security, adopted by the European Union in response to the growing number of cyber attacks targeting critical infrastructure and key economic sectors.

Compared to the original NIS directive, the new regulation:

For manufacturing plants, this means that cybersecurity is becoming part of production management, not just a technology issue.

Who is affected by the NIS2 directive in the manufacturing sector?

Many manufacturers still assume that the NIS2 directive only covers energy or large critical infrastructure operators, which is a false assumption.

It concerns, among other things:

Importantly, even if an organization is not formally classified as a “key entity,” it may be subject to it indirectly, as a supplier to regulated companies. In such cases, security requirements are often transferred directly into supplier contracts and audits.

NIS2 directive in a manufacturing plant

NIS2 requirements: what do they look like in the reality of a manufacturing plant?

One of the most frequently asked questions in the context of this directive is “What are the requirements of NIS2?” In the manufacturing sector, they have a very practical dimension. A cyber incident is not just a reputational problem, but a real risk:

Key NIS2 requirements from a manufacturing perspective:

This means combining technology, processes and people, which may not be easy without the right technological expertise.

IT and OT under the magnifying glass of the NIS2 directive

One of the biggest challenges for manufacturing plants is integrating directive requirements with OT realities. Industrial systems:

The directive does not impose specific technologies or solutions. Instead, it requires an informed, documented and proportionate approach to risk. This means that even older production lines can comply if the organization can demonstrate that risks are known, managed and monitored.

Production planning under the NIS2 directive

Continuity of production as the foundation of NIS2

For industry, a key issue in the context of NIS2 is business continuity. Cyber security cannot be separated from manufacturing realities.

The directive enforces:

This means that a cyberattack is treated similarly to a technical failure, that is, as an event for which the organization must be prepared operationally, not just formally.

The most common mistakes of manufacturing companies with NIS2

In many manufacturing plants, NIS2 is still treated as a side topic or purely formal. This leads to several repetitive errors that significantly increase operational risk.

1. nis2 is IT only

The most common mistake is the belief that the NIS2 directive applies only to the IT department. In practice, it also includes OT, production, maintenance and management. Without their involvement, requirements are implemented piecemeal.

2. skip OT and production lines

Companies often secure office systems and ignore PLC, SCADA or MES. Meanwhile, NIS2 requirements apply to the entire IT/OT environment, and it’s OT that’s critical to production continuity.

3. the BCP only “on paper”

Having a document does not mean preparedness. Lack of testing for emergency scenarios and cyber incidents is a common problem in manufacturing plants.

4. ignoring suppliers and integrators

Manufacturing relies on outside technologies. The lack of supplier security assessments and contract provisions is a gap that NIS2 pays particular attention to.

5. lack of training beyond IT

Training limited to IT is not enough. Operators, engineers and maintenance also need to understand the risks and their role in security.

By avoiding these mistakes, NIS2 can be approached as a tool to help strengthen production continuity, not just as a regulatory obligation.

Książka Adriana Stelmacha "15 kroków do zakupu systemu informatycznego" - dowiedz się więcej o tym, jak wybrać odpowiedni system IT dla swojej fabryki!

 

Get 5 chapters of the book for free!

Join the newsletter and gain access to 40% of the book
15 Steps to Buying an Information System.

How to prepare a manufacturing company for NIS2 step by step?

Implementation of the NIS2 directive in industry should not be a one-time “under audit” project. An evolutionary approach yields the best results. Implementing NIS2 in a manufacturing company requires a different approach than in classic IT.

Recommended path of action:

  1. Determine whether the organization falls under NIS2 directly or indirectly.
  2. IT and OT security audit in the context of manufacturing processes.
  3. Gap analysis against NIS2 requirements.
  4. Identification of risks with the greatest impact on production continuity.
  5. Develop a realistic roadmap for action.
  6. Implement processes, policies and technical safeguards.
  7. Training of employees at all levels of the organization.
  8. Regular testing, review and improvement of the system.

This approach will help the production facility meet regulatory requirements without crippling production and excessive investment.

Why is NIS2 an opportunity and not just an obligation?

While NIS2 is sometimes seen as yet another regulatory burden, for manufacturing companies it could provide the impetus to clean up the cyber security area. Many plants today operate based on the expertise of individuals, informal procedures and historical solutions.

Directive:

This is exactly the direction I try to promote individually and with explitia: technology as a stable foundation for business, not a source of uncontrollable risk.

NIS2 compliance is a necessary step to secure your business

For the manufacturing sector, NIS2 is much more than “compliance.” The NIS2 directive touches the very heart of industrial operations: production continuity, human safety and supply chain stability.

Companies that approach NIS2 requirements strategically, combining IT, OT, processes and management, can gain a real competitive advantage. In an industry where every hour of downtime can cost thousands or millions, cyber security stops being a cost and becomes an investment in stability and growth. Every manufacturing company is different, so NIS2 is worth translating to the realities of a specific plant.

If you still have doubts about the implementation of NIS2 in production, leave a message, I will help you get rid of them.

    .
    This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.