Industry · NIS2

Industry & NIS2: securing IT/OT convergence

NIS2 extends cybersecurity obligations to the manufacture of several product categories. For industrial operators, the central challenge is securing the convergence between IT management systems and operational technology (OT), which has become a major attack surface. This guide clarifies the classification criteria, Article 21 measures applied to OT, supply chain requirements, and incident notification.

DPO / CISO team — Data Comply One Updated on 15 June 2026

In brief

  • Regulation: NIS2.
  • Manufacturers producing the covered products above the threshold are concerned as important entities.
  • Extending risk management to OT.
  • Securing IT/OT convergence.
  • Securing the supply chain.
  • For important entities, up to €7M or 1.4% of global turnover, with potential personal liability for executives.

Regulatory deadlines

The key dates of this regulation.

January 2023

Entry into force (EU directive)

In force

October 2024

Transposition deadline (EU)

In force

2026

French transposition (Resilience Act)

In force

What does NIS2 cover?

NIS2 classifies among important entities the manufacture of medical devices, computer and electronic products, machinery and equipment, vehicles, and other transport equipment. Above the size threshold, these manufacturers must apply the measures set out in Article 21.

The industrial specificity is OT: PLCs, sensors, and control systems, long isolated, now connected.

Is the 'Industry' sector concerned?

Manufacturers producing the targeted products above the threshold are affected as important entities. Operators in essential sectors (energy, water) fall under an even stricter regime, addressed in the dedicated pages.

Below the threshold, manufacturers are often indirectly affected, through the requirements of their principals subject to NIS2.

Detailed obligations

Extend risk management to OT

Apply the measures of Article 21 not only to IT but also to industrial systems: inventory, segmentation, access control, monitoring.

Secure IT/OT convergence

Segment networks, control interconnection points, and manage remote maintenance access.

Secure the supply chain.

Govern component suppliers, integrators and industrial software publishers.

Ensure continuity and recovery

Have plans adapted to production constraints (line restart, PLC backups).

Notify and govern

Notify significant incidents and ensure the mechanism is driven by senior management.

Sanctions & risks

For important entities, up to €7 million or 1.4% of global turnover, with potential personal liability for senior managers. The operational risk is significant: an OT incident can halt production or compromise operator safety.

Commercial risk also exists: principals require security guarantees from their suppliers.

Application timeline

  • 1Directive. Adopted end of 2022.
  • 2France. Transposition in progress; anticipate, particularly regarding OT, which is often behind.

Common mistakes in the sector

  • 1Forgotten OT. Secure IT while neglecting industrial systems.
  • 2Uncontrolled maintenance access. Leaving remote access open for service providers.
  • 3Unsecured chain. Failing to govern integrators and component suppliers.
  • 4Absent leadership. Treating cybersecurity as a purely technical matter.

Practical case

A machinery manufacturer suffers an incident propagated from a supplier's remote maintenance access through to its industrial controllers. NIS2 remediation involves segmenting IT/OT environments, controlling remote access, inventorying industrial systems, and formalising a recovery plan that accounts for production constraints.

Compliance roadmap

  1. 1

    Qualify. Determining status (important, essential, out of scope).

  2. 2

    Map OT assets. Inventory automated systems, sensors, and IT/OT interconnections.

  3. 3

    Segment and secure. Segment networks and control remote access.

  4. 4

    Frame vendor relationships. Secure the industrial supply chain.

  5. 5

    Equip the notification process. Implement the alert and reporting process.

Frequently asked questions

Both: risk management must cover industrial systems, which are often the most exposed once connected.

Take action on NIS2

Free assessment or a chat with an expert dedicated to industry.

They already trust us

See how organisations in the industry sector secured their compliance with DCO.

See testimonials