NIS2
NIS2 and the CRA: two clocks on one factory
NIS2 regulates the plant you run. The CRA regulates what leaves it. Two 24-hour clocks, two different triggers — and in most factories, no owner.

ENISA opened the Cyber Resilience Act’s reporting platform on 11 September 2026, and the coverage that followed was all about the product: 24 hours to report an exploited vulnerability in something you sold. For a European manufacturer already inside NIS2 scope, that is the second cyber regulator to arrive, not the first. NIS2 has covered the plant you operate for longer, and the two regimes share a deadline, a shape, and almost nothing else. The company that treats them as one duty will discharge neither.
The regime that already covers your plant
NIS2 lists manufacturing in Annex II: medical devices and in vitro diagnostics, computer, electronic and optical products, electrical equipment, machinery and equipment not elsewhere classified, motor vehicles and trailers, and other transport equipment — the last five by reference to NACE Rev. 2 divisions 26 through 30. Chemicals and food sit in the same annex. If your NACE code is in that range, the only remaining question is size.
The floor is low, and it sits well below where most people assume it does. Article 2(1) catches entities that qualify as medium-sized under the EU’s own definition or exceed it: in practice, 50 or more staff, or turnover and balance-sheet total both above €10 million. A 90-person machinery maker turning over €25 million is in scope. A 40-person one turning over €6 million is not, unless a Member State designates it.
Now the part people get backwards. Being large does not promote you. Article 3(1) reserves “essential entity” status for Annex I sectors and a short list of named providers; Article 3(2) then sweeps up everything else — “entities of a type referred to in Annex I or II which do not qualify as essential entities … shall be considered to be important entities”. No Annex II manufacturer is an essential entity by size alone. A 4,000-person automotive supplier and a 60-person electronics firm are both important entities, with the same obligations and the same €7 million or 1.4% ceiling under Article 34(5) — calculated, note, on the turnover of the undertaking the entity belongs to, not the entity itself.
NIS2 never says “operational technology”
Here is the reason this gets missed, and it is not carelessness. Search the directive for “operational technology”, “industrial control system”, “SCADA” or “programmable logic controller” and you will find nothing. Not in the articles, not in the recitals. There is no OT clause to look up, no annex of industrial requirements, nothing a plant manager can be handed.
The coverage is in a definition instead. Article 6(1)(b) defines a network and information system as, among other things, any device or group of interconnected devices which “pursuant to a programme, carry out automatic processing of digital data”. A PLC does that. So does a line controller, a robot cell, a historian. Article 21(1) then requires measures managing risk to the systems entities “use for their operations or for the provision of their services” — operations, not just services.
Put those two together and the factory floor is inside the scope by plain reading, without ever being named. That is a real conclusion, not a stretched one, but it is also the reason a NIS2 gap assessment done by an IT function comes back clean while the thing that actually stops production sits outside its inventory. IBM’s X-Force Threat Intelligence Index 2026 puts manufacturing at 27.7% of all incidents its team handled in 2025 — the fifth consecutive year the sector has ranked first. The attackers found the plant some time ago.
One manufacturer, two regimes: the plant you operate and the product you ship are regulated separately.
Two clocks, two triggers, two recipients
Both regimes give you 24 hours, then 72, then a report. The symmetry is the trap, because everything that determines whether you notice in time is different.
| NIS2 | Cyber Resilience Act | |
|---|---|---|
| What is regulated | The systems you use for your operations | The product you placed on the market |
| Your role | Important entity (Annex II) | Manufacturer (a role, not an industry) |
| What starts the clock | Becoming aware of a significant incident affecting you | Reliable evidence a vulnerability in something you sold is being actively exploited — at a customer |
| Reported to | Your national CSIRT or competent authority | ENISA’s Single Reporting Platform, routed to the coordinating CSIRT |
| Stages | 24h early warning · 72h notification · final report at one month | 24h early warning · 72h notification · final report at 14 days or one month |
| Who owns it inside the company | IT and the management body | Product and engineering |
The NIS2 threshold is worth stating precisely, because it is broader than most incident procedures assume. Under Article 23(3) an incident is significant if it “has caused or is capable of causing severe operational disruption … or financial loss”, or has affected or is capable of affecting others through considerable damage. Capable of causing. A contained intrusion on a line-control network that could have halted production is reportable on the same clock as one that did.
The CRA’s trigger is stranger still, and we covered it in full in CRA reporting is live. You may be the manufacturer.: the event happens somewhere else, to somebody else, in a product that left your building years ago. No monitoring you own will see it. It arrives as a phone call.
The component counted once
This is where the two regimes stop being parallel and start colliding, and it is the failure we see most often in a manufacturing estate.
Take one embedded controller. Your maintenance team runs a fleet of them on the production line — that is an asset, it belongs in the NIS2 inventory, and Article 21 risk measures apply to it. Your product team ships the same controller inside a machine sold under your own badge — that makes it a component of a product with digital elements, and the CRA duty attaches to it.
One part number, two regimes, two entirely separate evidence trails. In practice it gets counted once, in the asset register, by the people who maintain it — and never in a product file, by anyone. When a CVE lands against that controller’s firmware, the maintenance side patches the line and closes the ticket. Nobody asks the second question, which is whether the same firmware is running in the units at customer sites and whether anyone is exploiting it there.
That is not a tooling gap. It is an ownership gap, and it is structural: NIS2 lands on the management body, the CRA lands on engineering, and in most mid-sized manufacturers those two have no shared forum, no shared register, and no agreed definition of “our products”. The first time they meet is during the incident.
Nobody is coming to audit you, and that is the problem
Supervision of important entities is reactive by design. Article 32(2) gives authorities standing power to subject essential entities to regular and targeted audits, on-site inspections and random checks. Article 33(1) applies a different standard to important entities: authorities act “when provided with evidence, indication or information” of alleged non-compliance, through ex post supervisory measures. No routine audit, no scheduled inspection, no letter.
One correction worth making, because the opposite is widely repeated. The temporary ban on a named executive exercising managerial functions — Article 32(5)(b) — applies to essential entities only, and only after other enforcement has failed. It is not available against an important entity. What does reach you is Article 20(1): the management body approves the risk-management measures, oversees implementation, and can be held liable for infringements. And Article 20(2) makes training for management-body members a requirement, not a suggestion — the encouragement applies to employees. So the board’s exposure is real; the headline sanction is not the one the trade press keeps citing.
The practical consequence of ex post supervision is not relief. It means the first contact with your regulator is the notification you file during your worst week, and it will be read by someone who has never seen your estate before. For an important entity, the independent readiness review is the only audit that happens on your own timetable rather than someone else’s.
Four questions and one rehearsal — the 30-day test that buys nothing.
Four questions and one rehearsal
Nothing here is a purchase, and none of it takes a quarter.
One. Look up your NACE division. If it is 26 to 30, or chemicals or food, and you are at 50 staff or €10 million on both financial measures, you are an important entity — write that sentence down with a date on it, because it is the sentence a regulator will ask you to produce. If you would rather have it worked through than write it yourself, our free NIS2 readiness assessment runs the same scoping test we use in the first phase of a paid engagement, and returns a score, your priority gaps and a 90-day roadmap as a PDF. It takes about eight minutes.
Two. Ask whether your NIS2 asset inventory contains the line. Not the office estate, not the ERP — the controllers, the historians, the engineering workstation with the vendor’s remote-access client on it.
Three. Ask whether anything you sell carries digital elements under your own name or trademark. If yes, read the Cyber Resilience Act obligations properly: the role is defined by what you do to a product, not by what industry you are in. The free CRA readiness assessment settles the scope question for one product — answer for the most important thing you sell, not the portfolio, because the CRA attaches its duties product by product.
Four. Name one person for each duty, and make them meet. If the same name goes in both boxes, that is fine. If one box is empty, you have found the gap.
Then rehearse the call. Not the ransomware tabletop you have already run — the other one, where a customer’s security team tells you a vulnerability in your product is being exploited at their site, and you have 24 hours. If that conversation takes longer than a morning to reach a decision about who files what, to whom, you learned it cheaply.
Take the next step
Talk to a security practitioner, not a salesperson.
Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.


