Regulations
NIS2 Is Here: Now What? An Operational Guide to Your Next Steps
The NIS2 directive has been transposed: what matters now is what to do in practice. From entity classification to OT asset visibility, an operational checklist.
The debate is over. After the 17 October 2024 transposition deadline, NIS2 is no longer a distant regulatory horizon but an obligation you have to reckon with. Italy was among the first countries to complete transposition, and that shifts the question from "what changes" to something far more concrete: now what, exactly, do I have to do?
In another article we already covered the general framework of the directive. The angle here is different: zero theory, a sequence of concrete steps for anyone who has to comply without halting production.
First of all: figure out whether you are in scope and on what basis
The first mistake is waiting for an official notice before acting. NIS2 works largely through self-identification: it is up to the organisation to determine whether it falls within scope and with what classification.
- Check your sector and size. The scope has widened sharply compared with NIS1: energy, manufacturing, healthcare, food, waste management, digital infrastructure and more. The size threshold (medium and large enterprises) is a starting point, not the only criterion.
- Distinguish essential from important. The two categories carry different obligations and supervisory regimes. Knowing where you sit determines internal priorities and deadlines.
- Do not forget the supply chain. Suppliers and non-EU service providers that deliver services within the Union can also fall within the perimeter.
The seven pillars translated into actions
The directive mandates minimum risk management measures. Read in operational terms, they become a work plan:
| Requirement | Concrete action |
|---|---|
| Risk analysis | An up-to-date asset inventory and periodic assessment, not a one-off |
| Incident management | Detection, response and notification procedures within the required timeframes |
| Business continuity | Tested backup, disaster recovery and crisis management |
| Supply chain security | Contractual clauses and assessment of critical suppliers |
| Governance | Accountability resting with management bodies, with training |
| Encryption and access control | Cryptography policies and strong authentication |
| OT security | Explicit extension of the measures to industrial environments |
The last point is where many organisations discover the biggest gap: security frameworks are designed with IT in mind, while NIS2 requires protecting OT networks and plants as well.
Where the OT angle makes the difference
You cannot protect what you cannot see. In industrial contexts the first gap is almost always the lack of a complete inventory of OT assets: PLCs, HMIs, RTUs and legacy devices that often appear in no management system at all.
This is where the MON5 approach plugs directly into NIS2 obligations:
- Passive asset visibility. Map every connected device without active scans that risk disrupting production processes.
- Contextualised vulnerabilities. Not a generic list of CVEs, but the correlation between vulnerabilities and the real context of the plant, so you can prioritise what truly matters.
- Anomaly monitoring. Detect suspicious behaviour on the OT network during normal operation, without stopping the line, feeding the incident management procedures the directive requires.
This turns abstract requirements such as "risk analysis extended to OT" into concrete data on which to build compliance.
The next-90-days checklist
- Complete the self-assessment and lock in your classification.
- Read the national transposition decree and its implementing measures.
- Inventory your assets, starting precisely with the OT that is today the blind spot.
- Map your existing measures against the seven requirements and identify the gaps.
- Formally involve governance: accountability lies with senior management.
- Align the programme with a recognised framework such as NIST CSF 2.0.
NIS2 does not reward those who wait for a letter from the competent authority, but those who arrive prepared. Starting now with asset visibility means building compliance on real foundations, not on a spreadsheet.
Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.
Related articles

Regulations
Cyber Resilience Act: What Changes for OT and IoT Device Manufacturers
The Cyber Resilience Act introduces security obligations for manufacturers of products with digital elements. For OT and IoT device makers, the compliance scope is broad and the deadlines are approaching.
Regulations
IEC 62443 in practice: from gap assessment to your first remediation plan
IEC 62443 is the reference standard for industrial control system cybersecurity. How to use it concretely: structure, gap assessment and a first five-step remediation plan.

Compliance
How to Prove NIS2 Compliance in an Audit: The Technical Evidence That Really Counts
NIS2 is not proven with policies: it is proven with technical evidence. What auditors look for in an OT audit, how to prepare evidence before they arrive, and the role of continuous monitoring as documentary proof.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.
Learn more about the regulation: NIS2