Skip to content

Regulations

NIS2 Is Here: Now What? An Operational Guide to Your Next Steps

The NIS2 directive has been transposed: what matters now is what to do in practice. From entity classification to OT asset visibility, an operational checklist.

2 min read

The debate is over. After the 17 October 2024 transposition deadline, NIS2 is no longer a distant regulatory horizon but an obligation you have to reckon with. Italy was among the first countries to complete transposition, and that shifts the question from "what changes" to something far more concrete: now what, exactly, do I have to do?

In another article we already covered the general framework of the directive. The angle here is different: zero theory, a sequence of concrete steps for anyone who has to comply without halting production.

First of all: figure out whether you are in scope and on what basis

The first mistake is waiting for an official notice before acting. NIS2 works largely through self-identification: it is up to the organisation to determine whether it falls within scope and with what classification.

  • Check your sector and size. The scope has widened sharply compared with NIS1: energy, manufacturing, healthcare, food, waste management, digital infrastructure and more. The size threshold (medium and large enterprises) is a starting point, not the only criterion.
  • Distinguish essential from important. The two categories carry different obligations and supervisory regimes. Knowing where you sit determines internal priorities and deadlines.
  • Do not forget the supply chain. Suppliers and non-EU service providers that deliver services within the Union can also fall within the perimeter.

The seven pillars translated into actions

The directive mandates minimum risk management measures. Read in operational terms, they become a work plan:

Requirement Concrete action
Risk analysis An up-to-date asset inventory and periodic assessment, not a one-off
Incident management Detection, response and notification procedures within the required timeframes
Business continuity Tested backup, disaster recovery and crisis management
Supply chain security Contractual clauses and assessment of critical suppliers
Governance Accountability resting with management bodies, with training
Encryption and access control Cryptography policies and strong authentication
OT security Explicit extension of the measures to industrial environments

The last point is where many organisations discover the biggest gap: security frameworks are designed with IT in mind, while NIS2 requires protecting OT networks and plants as well.

Where the OT angle makes the difference

You cannot protect what you cannot see. In industrial contexts the first gap is almost always the lack of a complete inventory of OT assets: PLCs, HMIs, RTUs and legacy devices that often appear in no management system at all.

This is where the MON5 approach plugs directly into NIS2 obligations:

  • Passive asset visibility. Map every connected device without active scans that risk disrupting production processes.
  • Contextualised vulnerabilities. Not a generic list of CVEs, but the correlation between vulnerabilities and the real context of the plant, so you can prioritise what truly matters.
  • Anomaly monitoring. Detect suspicious behaviour on the OT network during normal operation, without stopping the line, feeding the incident management procedures the directive requires.

This turns abstract requirements such as "risk analysis extended to OT" into concrete data on which to build compliance.

The next-90-days checklist

  1. Complete the self-assessment and lock in your classification.
  2. Read the national transposition decree and its implementing measures.
  3. Inventory your assets, starting precisely with the OT that is today the blind spot.
  4. Map your existing measures against the seven requirements and identify the gaps.
  5. Formally involve governance: accountability lies with senior management.
  6. Align the programme with a recognised framework such as NIST CSF 2.0.

NIS2 does not reward those who wait for a letter from the competent authority, but those who arrive prepared. Starting now with asset visibility means building compliance on real foundations, not on a spreadsheet.

Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.

Related articles

Industrial OT and IoT devices subject to the obligations of the Cyber Resilience Act

Regulations

Cyber Resilience Act: What Changes for OT and IoT Device Manufacturers

The Cyber Resilience Act introduces security obligations for manufacturers of products with digital elements. For OT and IoT device makers, the compliance scope is broad and the deadlines are approaching.

3 min read
Audit document with technical evidence and OT system logs on screen

Compliance

How to Prove NIS2 Compliance in an Audit: The Technical Evidence That Really Counts

NIS2 is not proven with policies: it is proven with technical evidence. What auditors look for in an OT audit, how to prepare evidence before they arrive, and the role of continuous monitoring as documentary proof.

6 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

Learn more about the regulation: NIS2

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna