TroutTrout
NIS2 compliance for industrial OT

Pass NIS2 without stopping your plants.

Trout Access Gate is an on-site appliance for NIS2 and IEC 62443 compliance in OT. It adds segmentation, MFA, access control and audit logs, without touching a production machine.

Last updated:

Trusted by leading companies

Guichon ValvesThalesOrange CyberdefenseJohn Cockerill
SITE PLAN · NIS2 ZONESEU DIRECTIVE 2022/2555ZONE A · OTPROCESSSCADAPRODUCTIONTURBINEFIELD DEVICESPLCRTUHMIDCSSAFETY SYSSUBSTATIONTAGZONE B · ITADMINERP · EMAILSERVERSDATA CTRNETWORKVPNWIFIMGMTVENDOR ACCESSOT PERIMETERIT PERIMETERARTICLE 21RISKINCIDENTACCESSENCRYPTSUPPLYCONTINUITY
NIS2 at a glance

What NIS2 requires.

A 60-second summary: who must comply, what is required, and when.

Who must comply.

Essential and important entities across 18 sectors, energy, transport, water, healthcare, banking, digital infrastructure, manufacturing of critical products, and more. Generally any organization with 50+ employees or €10M+ annual turnover operating in scope.

What you must do.

Article 21 mandates 10 cybersecurity risk-management measures: risk policies, incident handling, business continuity, supply chain security, network security, effectiveness assessment, cyber hygiene, encryption, access control, and MFA. Article 23 requires incident reporting within 24 hours.

When it applies.

The transposition deadline was 17 October 2024. By 2026 most Member States have written NIS2 into national law; a few, including France, are still finalising theirs, and enforcement ramps up as each takes effect.

Key figures

Three NIS2 figures and their sources.

Each figure links to the primary text.

24 h, 72 h, 1 month
Early warning, incident notification and final report after a significant incident.
Directive (EU) 2022/2555, Article 23(4)
18 sectors
11 highly critical sectors in Annex I and 7 other critical sectors in Annex II.
Directive (EU) 2022/2555, Annexes I and II
15 or 20 objectives
Security objectives in France's ReCyF, published by ANSSI on 17 March 2026. Important entities have 15. Essential entities have all 20.
ANSSI, Référentiel Cyber France (ReCyF)

What Article 21 requires on the production floor.

Article 21 mandates risk management measures that apply to every asset in scope, including PLCs, HMIs, CNCs, SCADA servers, and IoT sensors on the production floor. These assets cannot run endpoint agents. Many run proprietary firmware or end-of-life operating systems. NIS2 does not exempt them.

Access Gate enforces Article 21 at the network layer. No agent installation. No firmware modification. No production downtime.

For operators with OT in several plants, Access Gate deploys plant by plant, with no dependency between them. Each plant gets its own IEC 62443 zones. Central policy management keeps every plant audit-ready from one place.

Network segmentation without rewiring

Overlay segmentation isolates OT zones from IT and from each other. No VLAN reconfiguration. No switch changes.

Control who reaches what.

MFA is checked at Access Gate before a session reaches the machine. The PLC never needs to support it. This meets the Article 21 access control measure.

Tamper-evident audit for every OT session

Every connection to every OT asset is logged: user, timestamp, protocol, session replay. Hash-chained. Ready for NIS2 audit.

OT segmentation

Does NIS2 require OT segmentation?

Yes, in practice. Article 21(2) of the directive does not use the word. It requires network security (point e), basic cyber hygiene (point g) and access control (point i). Recital 89 lists network segmentation among those cyber hygiene practices.

The implementing rules are explicit. Point 6.8 of the annex to Implementing Regulation (EU) 2024/2690 requires digital-sector entities to split systems into zones and keep safety-critical systems in secured zones. ENISA's technical implementation guidance (June 2025) explains how to apply it and test it.

National rules point the same way. In France, objective 7 of the ReCyF published by ANSSI requires essential entities to split their systems into security zones and control the traffic between them, including for providers and suppliers.

Access Gate segments OT without rewiring. It connects to your existing network and applies zone policies at the network level. Nothing is installed on machines.

On-premise appliance.

Connect Access Gate to your existing network. No re-cabling.

Control who reaches what.

Decide how servers, PLCs and HMIs connect to corporate systems. Policies apply at the network level, with nothing to install on machines.

OT ZONESCADATAGIT ZONEERPVPNMESINCIDENT LOG

Article 21 measures mapped.

Evidence for each Article 21 measure, ready when the auditor asks.

NIS2 ARTICLE 21Risk Management (a)PARTIncident Handling (b)FULLBusiness Continuity (c)PARTSupply Chain (d)FULLNetwork Security (e)PARTAccess Control (i)FULL
Prove every audit

How Access Gate covers each measure.

NIS2 Article 21(2) defines 10 security measures. Here is how each applies to on-premise IT and OT environments and what Access Gate covers.

Article 21(2) at a glance: each measure and the Access Gate control that answers it.
ArticleMeasureAccess Gate controlCoverage
Art. 21(2)(a)Risk analysis and information system security policiesAsset inventory and deny-by-default rules feed your risk analysis. Writing the policy stays with you.Partial
Art. 21(2)(b)Incident handlingSession logs, alerts and session replay for the 24-hour early warning.Covered
Art. 21(2)(c)Business continuity and crisis managementConnects beside the network, so production keeps running if it stops. Disaster recovery stays with you.Partial
Art. 21(2)(d)Supply chain securityPer-session vendor access with MFA, recording and automatic revocation.Covered
Art. 21(2)(e)Network and information system securityOverlay segmentation and passive discovery of unmanaged machines. Patching and vulnerability disclosure stay with you.Partial
Art. 21(2)(f)Effectiveness assessmentAccess policy audits and evidence packages on demand.Covered
Art. 21(2)(g)Cybersecurity hygiene and trainingMFA, least privilege and session timeouts enforced by policy. Staff training stays with you.Partial
Art. 21(2)(h)Cryptography and encryptionFIPS-validated TLS on every access path.Covered
Art. 21(2)(i)Access control and asset managementPassive asset inventory and identity-based access per user, machine and protocol.Covered
Art. 21(2)(j)Multi-factor authenticationMFA at the gate before any session reaches the machine, with offline TOTP.Covered
Art. 21(2)(a)Risk analysis and information system security policies Partial
What NIS2 requires

Establish and maintain risk management policies for all information systems.

How Access Gate addresses it

Access Gate provides continuous asset discovery, network mapping, and policy enforcement. Risk is managed through microsegmentation and deny-by-default rules. Policy changes are version-controlled. Writing the risk analysis and the security policy stays with your team.

Art. 21(2)(b)Incident handling Covered
What NIS2 requires

Detect, report, and respond to security incidents within 24 hours of awareness.

How Access Gate addresses it

Session anomaly detection, automated alerting, and forensic session replay. Every connection is logged with user identity, timestamp, and payload. Incident evidence is generated continuously and exportable on demand.

Art. 21(2)(c)Business continuity and crisis management Partial
What NIS2 requires

Maintain operations during and after security incidents. Backup management and disaster recovery.

How Access Gate addresses it

Access Gate deploys adjacent to the network, not inline. If the appliance is unavailable, production traffic continues. Policy configurations are exportable for backup. Disaster recovery plans remain a customer responsibility.

Art. 21(2)(d)Supply chain security Covered
What NIS2 requires

Manage cybersecurity risks in supplier and service provider relationships.

How Access Gate addresses it

Vendor access is scoped per session: specific assets, specific protocols, specific time windows. MFA enforced. Every vendor session is recorded with full audit trail. The VPN ends at the gate, and no persistent access remains. Access revoked automatically when the session ends.

Art. 21(2)(e)Network and information system security Partial
What NIS2 requires

Secure the acquisition, development, and maintenance of network and information systems. Vulnerability handling and disclosure.

How Access Gate addresses it

Overlay microsegmentation isolates assets without network redesign. Deny-by-default blocks unauthorized connections. Passive asset discovery identifies unmanaged devices. No active scanning that could disrupt OT operations. Secure development, patching and vulnerability disclosure stay with your team.

Art. 21(2)(f)Effectiveness assessment Covered
What NIS2 requires

Assess the effectiveness of cybersecurity risk management measures.

How Access Gate addresses it

Segmentation baselines, access policy audits, and session log analysis provide continuous assessment data. Evidence packages generated on demand for auditors and regulators.

Art. 21(2)(g)Cybersecurity hygiene and training Partial
What NIS2 requires

Basic cyber hygiene practices and cybersecurity training for staff.

How Access Gate addresses it

Access Gate enforces hygiene through policy: MFA required, least-privilege access, session timeouts. Training content and delivery remain a customer responsibility.

Art. 21(2)(h)Cryptography and encryption Covered
What NIS2 requires

Policies and procedures on the use of cryptography and encryption.

How Access Gate addresses it

FIPS-validated TLS cipher suites on all access paths. AES-128/256 GCM with ECDHE key exchange. Encryption enforced at the proxy layer without modifying production equipment.

Art. 21(2)(i)Access control and asset management Covered
What NIS2 requires

Human resources security, access control policies, and asset management.

How Access Gate addresses it

Article 21(2)(i) names asset management. The asset inventory lists every machine from the traffic already on your network, with its history of changes. Access is identity-based, with MFA and RBAC per user, per asset and per protocol. Access policies are enforced at the network layer.

Art. 21(2)(j)Multi-factor authentication Covered
What NIS2 requires

Use of MFA, continuous authentication, and secured communications.

How Access Gate addresses it

MFA enforced at the proxy boundary before any session reaches the asset. TOTP tokens work offline for air-gapped environments. Secured communications via FIPS-validated TLS.

What non-compliance costs.

Up to €10M or 2% of global annual turnover for essential entities, whichever is higher. Up to €7M or 1.4% for important entities. Source: Directive (EU) 2022/2555, Article 34.

How Guichon Valves secured OT and IT for NIS2.

Guichon Valves
100%

of OT-IT flows segmented and auditable for NIS2 compliance. Deployed without production disruption.

Trusted by leading companies

Thales
Orange Cyberdefense
John Cockerill
NeverHack
Kyron
Eden Cluster
Ciberlogic
Datasheet

Download the Access Gate Datasheet.

Get the complete product overview with technical capabilities, deployment model, compliance alignment, and customer references.

Done

What's Inside

Product architecture, deployment model, key capabilities (proxy enforcement, micro-DMZs, identity-based access), compliance alignment, and real-world customer deployments.

2 pages

See It in Action

Request a live demo to see how the Access Gate deploys on your network without rewiring or downtime.

Request a demo
FAQ

Common questions about NIS2 compliance.

10

Article 21 cybersecurity measures enforced and continuously monitored. Audit-ready evidence generated on demand.

NIS2 is the EU directive on cybersecurity for essential and important entities, energy, transport, manufacturing, water, digital infrastructure, and more. If you operate in these sectors within the EU above the size thresholds (typically 50+ employees or €10M turnover for important entities, 250+ or €50M for essential entities), it applies.

Article 21 requires risk management measures including network segmentation, access control, incident handling, supply chain security, cryptography, and tamper-evident audit logging. These obligations apply to every asset in scope, including PLCs, HMIs, CNCs, SCADA servers, and IoT sensors on the production floor. NIS2 does not exempt OT.

Yes, and for many essential entities, on-premise is the only path that preserves data sovereignty under the CLOUD Act and FISA 702. Access Gate is an appliance that runs entirely inside your perimeter. No SaaS dependency, no foreign control plane, no data leaves your network. Article 21(2)(d) supply-chain risk management makes the cloud-jurisdiction question a board-level concern.

Up to €10M or 2% of global annual turnover for essential entities, whichever is higher. Up to €7M or 1.4% for important entities. Beyond fines, Article 32(5) authorizes competent authorities to impose temporary bans on senior managers personally for gross negligence. Personal liability is built into the directive.

NIS2 widened the scope from a short list of operators of essential services to 18 sectors, and to the medium and large entities in them. It introduced personal liability for management bodies (Articles 20 and 32), stricter incident reporting deadlines (24-hour early warning, 72-hour notification, final report within a month), and concrete supply-chain security obligations under Article 21(2)(d). The original NIS directive left these to member-state interpretation; NIS2 codifies them at the EU level.

The CLOUD Act gives US authorities legal power to compel American cloud providers to disclose data, including data physically stored in European data centers. Jurisdiction follows the corporate parent, not the server location. An EU data center option from a US vendor does not eliminate exposure. For NIS2 essential entities, structural sovereignty is the only durable defense, which is why Access Gate runs on-premise under your jurisdiction with no remote control plane.

Installed in a day. Access Gate connects to your existing network, with no re-cabling, no IP changes and no production downtime. Guichon Valves segmented their production and IT networks without stopping production. One appliance covers Article 21 access control, segmentation, MFA and audit logging, ready for audit on day one.

Yes. IEC 62443 zone-and-conduit architecture is exactly how Access Gate enforces segmentation, every OT zone is its own protected enclave with explicit conduit policies between zones. The same evidence Access Gate generates for NIS2 Article 21 audit also documents IEC 62443 compliance. One architecture covers both frameworks without duplication of effort.

In practice, yes. Article 21(2) requires network security, cyber hygiene and access control, and recital 89 of the directive names network segmentation as a cyber hygiene practice. Implementing Regulation (EU) 2024/2690 makes segmentation explicit for digital-sector entities, and France's ReCyF requires essential entities to split their systems into security zones. Access Gate applies zone policies at the network level, with nothing to install on machines.