NIS2 · Sector deep-dive

NIS2 for Manufacturing

Manufacturing sits in Annex II of NIS2, the list of other critical sectors, which means in-scope manufacturers are normally supervised as important entities. The annex covers five manufacturing sub-sectors defined by their NACE classification: medical devices and in vitro diagnostic medical devices; computers, electronic and optical products; electrical equipment; machinery and equipment not elsewhere classified; and motor vehicles, trailers, semi-trailers and other transport equipment. Within those categories, the obligations apply to medium-sized manufacturers — 50 or more employees, or turnover and balance sheet total above €10 million — and to large ones.

Why manufacturing is in scope

The plant floor is no longer an island. Production lines, quality systems and maintenance platforms are increasingly connected to corporate IT and to the internet — for scheduling, telemetry, predictive maintenance and remote support. Every one of those links is a route between an environment built for uptime and an environment exposed to ordinary internet threats, and a ransomware incident that begins in the office network now routinely stops physical output.

Manufacturers also sit on top of deep, multi-tier supplier networks and depend heavily on system integrators, machine builders and remote-support vendors who hold privileged access to production equipment. Compromise of one integrator can propagate across many plants that never had a direct relationship with the attacker's entry point.

Behind both of these is the simple economic argument the EU legislator made: manufacturing is a substantial share of the Union's output and employment, and prolonged disruption in the listed sub-sectors — medical devices and vehicle production in particular — has consequences well beyond the affected company.

Where manufacturers typically have the biggest gaps

  • Legacy OT and SCADA systems. Control systems with a fifteen- or twenty-year service life were designed for availability and determinism, not for authentication, encryption or patching. Many run unsupported operating systems and cannot be updated without re-validating the process around them.
  • Weak IT/OT segmentation. Flat networks, shared domain accounts and engineering laptops that move between both worlds mean a foothold in the office environment often reaches the production environment without any further effort from the attacker.
  • Incomplete asset inventories. IT assets are usually catalogued; PLCs, HMIs, sensors, test rigs and vendor-supplied cells frequently are not. You cannot patch, monitor or risk-assess equipment nobody has written down.
  • Limited visibility into equipment vendors. Machine builders and integrators are selected on capability, price and lead time. Their own security practices — how they manage remote access, how they handle vulnerabilities in embedded software, how long they support a product — are rarely assessed or written into the contract.

What this means for the Article 21 measures

  • Supply chain security — Article 21(2)(d). Assess the security of equipment and component suppliers, not just software vendors. Cover remote-access arrangements for machine builders, vulnerability handling for embedded firmware and the support horizon of the equipment you are buying.
  • Asset management — Article 21(2)(i). Inventory industrial control systems alongside IT assets, with owner, criticality, network location and patchability recorded, so the plant floor is visible in the same risk picture as the server room.
  • Business continuity — Article 21(2)(c). Plan for production downtime, not only for IT outages: manual fallback procedures, spare controller configurations, recovery order between lines, and tested restoration of engineering workstations and process configurations.

These sit inside the same ten-measure framework every in-scope entity has to satisfy — see the full Article 21 requirements page — and, as an important entity, a manufacturer is supervised reactively rather than proactively, but the obligations themselves are identical.

Documentation

The NIS2 Starter Kit's templates apply to manufacturing environments — adapt the asset inventory and supply chain templates to your production systems.

View the NIS2 Starter Kit

Related reading

Frequently asked questions