TroutTrout
Back to Blog
NIS2ComplianceICS networks

NIS2 Directive Explained: Requirements, Scope, and Who Must Comply in 2026

Trout Team9 min read

The NIS2 Directive, Directive (EU) 2022/2555, is the European Union's cybersecurity law for "essential" and "important" entities in 18 sectors. It requires them to take ten minimum security measures (Article 21), report significant incidents within 24 hours (Article 23), and hold senior management accountable (Article 20), backed by fines up to 10 million EUR or 2% of global turnover. It replaced the 2016 NIS Directive and widened both the sectors covered and the obligations on each entity.

If you run plants, the hard part is applying those measures to machines that cannot run security software. Our NIS2 compliance for OT page maps each Article 21 measure to the control that answers it, and says plainly where a measure stays with your team.

What is the NIS2 directive?

. NIS2 is the second Network and Information Security directive. The full text is on EUR-Lex. It entered into force in January 2023. Member States had to write it into national law by 17 October 2024, and each national law sets its own enforcement dates.

The directive has four goals:

  1. Harmonize cybersecurity rules across Member States.
  2. Widen the scope to more sectors and to medium-sized organizations.
  3. Set concrete security measures instead of leaving them to national interpretation.
  4. Speed up incident reporting and cooperation between national authorities.

Who must comply with NIS2?

. NIS2 applies to medium and large organizations in the sectors listed in its two annexes. Some entities are in scope regardless of size, such as DNS providers or a sole provider of a critical service in a Member State.

CategorySectorsTypical sizeMaximum fine
Essential entityLarge organizations in Annex I: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space250+ employees, or over 50 million EUR turnover10 million EUR or 2% of global annual turnover
Important entityMedium organizations in Annex I, and medium or large ones in Annex II: postal services, waste management, chemicals, food, manufacturing (medical devices, electronics, electrical equipment, machinery, vehicles), digital providers, research50+ employees, or over 10 million EUR turnover7 million EUR or 1.4% of global annual turnover

Annex I holds 11 highly critical sectors and Annex II holds 7 other critical sectors, which is where the "18 sectors" figure comes from. Entities already covered by the first NIS Directive stay in scope. Many manufacturers, food producers and chemical plants are covered for the first time.

The obligations are almost the same for both categories. The difference is supervision: essential entities face proactive audits, important entities are supervised after the fact.

What are the NIS2 requirements?

.

The ten Article 21 security measures

. Article 21(2) lists ten minimum measures. They must be proportionate to your risk, your size and the likely impact of an incident. The right-hand column says what each one means on an industrial site.

ArticleMeasureWhat it means on an industrial site
21(2)(a)Risk analysis and information system security policiesStart from an up-to-date inventory of machines. In OT you listen to traffic instead of scanning devices.
21(2)(b)Incident handlingKeep access logs for every machine, so you can rebuild the timeline within the reporting deadlines.
21(2)(c)Business continuity, backups, crisis managementBack up PLC programs and configurations, not only servers. Test the restore.
21(2)(d)Supply chain securityControl integrator, maintainer and machine-builder access, including 4G routers left in cabinets.
21(2)(e)Security in acquisition, development and maintenance, including vulnerability handlingPut security clauses in machine specifications. Plan for equipment that will never get a patch.
21(2)(f)Assessing the effectiveness of the measuresMeasure, then show the numbers. A written policy alone is not evidence.
21(2)(g)Basic cyber hygiene and trainingInclude production teams. They plug in USB drives and open vendor access.
21(2)(h)Cryptography and encryptionModbus, S7 and DNP3 run in clear text. Encryption has to come from the network around the machines.
21(2)(i)Human resources security, access control, asset managementPLCs have no notion of a user. A shared workshop password gives no named audit trail.
21(2)(j)Multi-factor authentication and secured communicationsA legacy HMI cannot do MFA. Put strong authentication in front of the machine.

For how Trout Access Gate answers each line, with an honest "partial" where part of the work stays with you, see the Article 21 mapping on our NIS2 page.

Incident reporting (Article 23)

. When a significant incident hits, the clock starts when you become aware of it.

  1. Within 24 hours: an early warning to your CSIRT or competent authority.
  2. Within 72 hours: an incident notification with a first assessment of severity and impact.
  3. Within one month: a final report.

An incident is significant when it causes, or could cause, severe disruption or financial loss, or considerable damage to others. The 24-hour window is the one that catches most organizations off guard.

Governance and accountability (Article 20)

. Management bodies must approve the security measures, oversee how they are applied, and follow cybersecurity training. They can be held liable for failures. For essential entities, authorities can temporarily ban a manager from leadership duties (Article 32). Our post on NIS2 management liability covers this in detail.

What does NIS2 mean for ICS and OT networks?

. NIS2 does not exempt industrial control systems. In energy, water, transport and manufacturing, the Article 21 measures land on PLCs, HMIs, RTUs and SCADA servers. Most of these machines cannot run an agent, and many run end-of-life operating systems. Four areas need OT-specific work.

Asset management

. Keep an up-to-date inventory of every machine, its firmware and its data flows. Build it passively from network traffic, so you never disturb a running process. Our guide to NIS2 asset inventory requirements lists what to track.

Risk management

. Assess cyber and physical risk together, because an OT incident can stop a line or harm people. Rank the machines by what their failure would cost. Review the analysis when the plant changes.

Incident response

. Name an incident team with clear roles. Write a plan for OT incidents and test it in drills with production staff. Agree in advance who reports to the authority, so the 24-hour warning does not wait on a meeting.

Business continuity

. Plan failover for critical processes. Keep offline copies of PLC programs and HMI projects. Check that the plan still matches the plant after each change.

Access control and segmentation

. This is usually the hardest gap. Legacy machines cannot authenticate a user or record a session, and the riskiest path in is remote vendor access. The directive's recital 89 names network segmentation as a basic cyber hygiene practice, and national frameworks such as France's ReCyF require essential entities to split their systems into security zones.

Trout Access Gate connects to your existing network and puts a gate in front of those machines. Every session, including third-party maintenance, is tied to a named user, limited to the machines it needs, and recorded. Nothing is installed on machines. See NIS2 compliance for OT and secure OT remote and vendor access.

Which standards help you meet NIS2?

. There is no NIS2 certificate. You prove compliance to your national authority with evidence. Existing standards give you that evidence faster.

  • IEC 62443 gives the technical model for industrial networks: zones and conduits, security levels and supplier requirements.
  • ISO/IEC 27001 covers the management system: risk process, policies and continual improvement.
  • National frameworks turn Article 21 into checkable objectives, such as the ReCyF published by France's ANSSI.

Map each Article 21 measure to a control you already run, so you do not do the work twice. If you also sell to the US defense sector, see one architecture for CMMC and NIS2.

How to prepare for NIS2 compliance

.

  1. Confirm your category. Check whether you are an essential or an important entity, and register with your national authority.
  2. Run a gap analysis. Compare your current controls with the ten Article 21 measures, plant by plant.
  3. Build a roadmap. Give every gap an owner, a date and a budget. Fix the highest-risk gaps first.
  4. Get ready to report. Test that you can send a 24-hour early warning, including on a weekend.
  5. Secure the supply chain. Add security clauses to supplier contracts and control vendor remote access.
  6. Put controls in front of OT. Segmentation, named access, MFA and session logs, without changing the machines.
  7. Train people. Include operators and maintenance staff, not only office users.
  8. Measure and improve. Review the measures regularly and keep the evidence ready for an audit.

Three challenges come up often. Security controls must not block legitimate production work. Smaller entities need to spend where the risk is highest. And your suppliers' security becomes part of yours, so plan supplier reviews from the start.

When does NIS2 apply?

. The transposition deadline was 17 October 2024. By 2026 most Member States have written NIS2 into national law. A few, including France, are still finalizing theirs, and enforcement ramps up as each national law takes effect. Check your national authority for the date that applies to you. Our post on NIS2 enforcement tracks what changed.

Where to start

. Identify your category, map your controls to Article 21, and test your 24-hour reporting. For plants, start with access control on the machines that cannot protect themselves.

FAQ

Frequently Asked Questions

What is the NIS2 Directive?
NIS2 is the European Union's updated cybersecurity directive, Directive (EU) 2022/2555. It entered into force in January 2023 and Member States had to transpose it into national law by 17 October 2024. It replaces the 2016 NIS Directive and requires essential and important entities across 18 sectors to manage cybersecurity risk, secure their supply chains, report significant incidents quickly, and hold senior management accountable.
Who must comply with NIS2?
Medium and large organizations in 18 sectors must comply. They are split into essential entities (mostly large organizations in highly critical sectors such as energy, transport, water, health and digital infrastructure) and important entities (other in-scope organizations, including manufacturing, food, chemicals and digital providers). Size generally means at least 50 employees or 10 million EUR turnover, though some entities are in scope regardless of size. The obligations are similar for both classes; the supervision and penalties differ.
What are the main NIS2 requirements?
Article 21 requires ten minimum security measures, from risk analysis and incident handling to supply chain security, access control and multi-factor authentication. Article 23 requires an early warning within 24 hours of a significant incident, a notification within 72 hours and a final report within one month. Article 20 makes management bodies accountable. Fines reach 10 million EUR or 2% of global annual turnover for essential entities.
What does Article 21 of NIS2 require?
Article 21(2) lists ten measures every essential and important entity must take: risk analysis and security policies, incident handling, business continuity, supply chain security, security in acquisition, development and maintenance, effectiveness assessment, cyber hygiene and training, cryptography, human resources security with access control and asset management, and multi-factor authentication with secured communications. The measures must be proportionate to the entity's risk.
How does NIS2 apply to OT and industrial systems?
NIS2 does not exempt operational technology. Many NIS2 sectors run PLCs, HMIs and SCADA, and the access control, supply chain and incident requirements apply to them directly. For industrial operators the practical gap is usually controlling and recording who reaches those machines, especially remote vendors, on equipment that cannot run security software. Trout Access Gate closes that gap at the network level, with nothing to install on machines.
Is there a NIS2 certification?
No. NIS2 is a legal obligation, not a certification scheme. You show compliance to your national authority with evidence: registration, the ability to report incidents on time, and documentation of the Article 21 measures. ISO/IEC 27001 covers the management-system side and IEC 62443 gives the technical vocabulary for industrial networks, but neither replaces NIS2.