NIS2 is the European Union directive that strengthens cybersecurity requirements across a broad set of sectors. It expands who is covered, raises expectations for risk management, and tightens incident reporting compared with its predecessor.

For organizations that run operational technology, NIS2 is not just an IT compliance exercise. Many of its expectations land directly on the industrial systems that keep essential services running, which makes OT security a board-level concern rather than a niche one.

01Key takeaways

  1. 01

    NIS2 broadens the scope of regulated entities and raises the baseline for cybersecurity risk management in the EU.

  2. 02

    It applies to essential and important entities across many sectors, several of which are heavily OT-dependent.

  3. 03

    Obligations include risk-management measures, incident reporting and accountability at management level.

  4. 04

    Technical controls that reduce reachability, such as segmentation and one-way transfer, support several of those measures.

  5. 05

    NIS2 aligns naturally with existing frameworks such as IEC 62443 and NIST guidance, rather than replacing them.

02What NIS2 is and who is in scope

NIS2 is the updated Network and Information Security Directive in the European Union. It widens the range of sectors and organizations covered and distinguishes between essential and important entities, both of which carry obligations.

Many in-scope sectors, including energy, water, manufacturing, transport and digital infrastructure, depend on operational technology to deliver their services. For those organizations, meeting NIS2 expectations is impossible without addressing OT security directly.

NIS2 is implemented through national law in each member state, so the precise obligations and timelines follow local transposition.

03Risk-management and reporting obligations

At a high level, NIS2 expects covered entities to manage cybersecurity risk through appropriate measures and to report significant incidents within defined timeframes.

  • Risk-management measures covering the security of network and information systems, proportionate to the risk.
  • Incident handling and reporting of significant incidents to the relevant authorities within set deadlines.
  • Supply chain and supplier security considerations as part of overall risk management.
  • Business continuity and recovery capabilities, including backup management.
  • Governance and accountability, with management bodies responsible for overseeing the measures.

The exact wording and thresholds are defined in the directive and in each country's implementing law, but the direction is consistent: demonstrable risk management and timely reporting.

04How NIS2 intersects with OT and ICS

OT systems are often where the consequences of an incident are most severe, affecting safety, availability and the delivery of essential services. That places them squarely within the risk that NIS2 expects entities to manage.

Yet OT environments are harder to secure with conventional IT measures: patch windows are scarce, systems run for years, and downtime carries operational cost. This is why OT security tends to emphasize reducing unnecessary reachability as much as detecting threats, a theme that maps well onto risk-management expectations.

05Technical controls that help

No single control delivers compliance, but several technical measures support the risk-management and continuity expectations that NIS2 sets out.

Segmentation
Dividing systems into zones with controlled conduits limits how far an incident can spread and supports proportionate risk management.
Exposure reduction
Keeping assets reachable only when needed reduces the attack window and the chance an incident reaches critical systems.
One-way transfer
Publishing data outward without an inbound path protects high-consequence zones while still meeting reporting and analytics needs.
Protected backups
Isolated, recoverable backups support the business continuity and recovery expectations within the directive.

For OT assets that do not need continuous connectivity, an AIRGAPNET controlled connectivity approach can reduce exposure and produce the connection records that support a demonstrable, auditable risk-management story.

06Evidence and auditability

NIS2 rewards organizations that can demonstrate their measures, not just assert them. Evidence is part of the obligation, especially around incident handling and the effectiveness of controls.

  • Keep records that show which controls protect which systems and why.
  • Log connectivity, access windows and transfers so the operating model can be proven.
  • Maintain incident handling procedures and the ability to report within required timeframes.
  • Test recovery so business continuity claims are backed by evidence.

07How NIS2 relates to IEC 62443 and NIST

NIS2 sets obligations; frameworks such as IEC 62443 and NIST guidance offer the structured methods to meet them. They are complementary rather than competing.

An organization can use the IEC 62443 zone-and-conduit model and NIST OT guidance to design and justify the technical measures, then use NIS2 as the regulatory frame that requires those measures to exist, be governed and be reported. Building on established frameworks is usually the fastest route to a defensible position.

08Closing thought

NIS2 raises the baseline and makes management accountable for it, and for OT-dependent organizations that means industrial security can no longer sit on the margins. The good news is that the measures it expects are the same ones that genuinely reduce operational risk.

Treat NIS2 less as a checklist and more as a prompt to make risk management real and provable. Reduce exposure, segment deliberately, protect recovery, and keep the evidence. The compliance follows the security, not the other way around.

FAQFrequently asked questions

What is NIS2?

NIS2 is the European Union's updated Network and Information Security Directive. It broadens the sectors and organizations covered, raises the baseline for cybersecurity risk management, and tightens incident reporting compared with the original NIS Directive.

Does NIS2 apply to OT and industrial systems?

Yes, in effect. Many in-scope sectors such as energy, water, manufacturing and transport depend on operational technology, so meeting NIS2 expectations requires addressing OT security directly rather than treating it as IT-only.

What does NIS2 require organizations to do?

Broadly, NIS2 requires proportionate risk-management measures, handling and timely reporting of significant incidents, supply chain security, business continuity, and management-level accountability. Exact thresholds follow each member state's implementing law.

Which technical controls help with NIS2 for OT?

Segmentation, exposure reduction, one-way data transfer and protected backups all support the risk-management and continuity expectations. None delivers compliance alone, but together they build a demonstrable security posture.

How does NIS2 relate to IEC 62443 and NIST?

NIS2 sets the obligations, while IEC 62443 and NIST guidance provide structured methods to meet them. They are complementary: use the frameworks to design and justify controls, and NIS2 as the regulatory frame requiring them.

SRCSources of record

Security first, compliance follows

Make OT risk management real and provable.

Reduce exposure on assets that do not need to be always reachable, keep the connection records, and turn a NIS2 obligation into a defensible, auditable posture.

Related article

Continue the thread IEC 62443 Zones and Conduits Explained: A Practical OT Segmentation Guide