Compliance
NIS2 for a Manufacturing SME: a Practical Checklist Without Getting Lost in Bureaucracy
NIS2 is not just for large companies. Manufacturing SMEs within scope have concrete obligations: OT asset inventory, vulnerability management, detection, incident notification. A practical checklist.
Who Needs to Worry About NIS2
The first question to ask is not "what do I have to do" but "does it apply to me". NIS2 distinguishes between essential entities and important entities based on sector and size.
For manufacturing, the relevant sectors listed in Annex II of the directive include the production of machinery, vehicles, medical devices, chemical products and other industrial goods. Not all manufacturing is included: the regulation focuses on production considered relevant to the economy and society.
In terms of size, NIS2 generally applies to medium-sized enterprises (more than 50 employees or turnover above 10 million euros) and to large enterprises. Microenterprises are excluded except in specific cases. However, Legislative Decree 138/2024, which transposes NIS2 in Italy, provides that ACN may extend the obligations beyond the standard size thresholds in sectors considered critical.
The practical step: registering on the ACN platform for NIS entity notification is the starting point. Verifying applicability happens through this process, not through a self-assessment based on reading the directive.
Once applicability has been verified, classification as an essential or important entity determines the intensity of the controls you are subject to, but it does not substantially change the technical security obligations.
What NIS2 Really Requires in Technical Terms
NIS2 does not prescribe a list of specific controls in the regulatory text. Instead, it establishes a set of security measures that organizations must implement, leaving the technical detail to national authorities and reference standards. This approach creates a certain ambiguity, which can be clarified by looking at what auditors ask for and at the technical standards cited as references.
The main areas that NIS2 touches for an organization with OT networks are:
Security policies for networks and information systems: you need a policy document that also covers OT systems, not just IT. Many SMEs have up-to-date IT policies but nothing that explicitly mentions PLCs, HMIs, or SCADA systems.
Incident handling: documented procedures to detect, respond to and notify incidents. NIS2 sets precise deadlines for notification: 24 hours for the early warning, 72 hours for the initial notification, 30 days for the final report. These timeframes are tight and require advance preparation.
Business continuity and crisis management: the directive refers to business continuity, backup and disaster recovery. In an OT context this means having copies of PLC configurations, documented recovery procedures, and periodic recovery tests.
Supply chain security: NIS2 includes explicit obligations on assessing the security of suppliers. For OT manufacturing, this includes automation vendors, remote maintenance providers, and system integrators.
Vulnerability management: it is not enough to know that patches exist. You need a process to identify relevant vulnerabilities, assess their risk in the specific context, and make documented decisions on how to handle them.
Detection measures: the ability to detect compromises within a reasonable timeframe is implicit in the incident handling requirements. Without monitoring, notifying an early warning within 24 hours is practically impossible.
The Checklist Point by Point
This checklist is not a substitute for a professional assessment, but it helps you understand where you stand and where the gaps are most evident.
Asset inventory
- A complete list of all OT devices (PLCs, HMIs, SCADA, historian, RTU, intelligent field devices)
- For each asset: software/firmware version, manufacturer, end-of-support date
- A map of the connections between IT and OT networks, including temporary and maintenance connections
- Documentation of dependencies between systems (which PLC depends on which server?)
- A defined process to update the inventory when a device is added or removed
Vulnerability management
- A source of intelligence on OT CVEs (CISA ICS-CERT, vendor advisories)
- A process to assess CVEs against the assets in the inventory
- A documented prioritization criterion (not all CVEs require the same urgency)
- A log of patching decisions with rationale (patch applied, not applicable, compensating control)
- A periodic vulnerability assessment cycle (at least annual for critical systems)
Detection and monitoring
- Visibility into OT network traffic (at least in the critical segments)
- An alert management process with documented triage
- Security logs retained for a sufficient period (NIS2 does not specify, but 90 days is a reasonable minimum)
- An internal escalation procedure for OT security alerts
Incident handling
- A documented incident response procedure that includes OT scenarios
- A definition of what constitutes a "significant incident" for the purposes of NIS2 notification
- ACN contacts and notification procedures known to the responsible staff
- An incident response exercise conducted at least once a year
- Emergency contacts with OT vendors and system integrators
Business continuity
- Backups of PLC and SCADA configurations (verified and tested)
- A defined recovery time objective for critical OT systems
- A documented and tested recovery procedure
- Critical dependencies identified (what stops if system X goes down?)
Supply chain
- An inventory of suppliers that have remote or physical access to OT systems
- Minimum security requirements for vendors documented and included in contracts
- A secure onboarding process for remote maintenance access
Governance
- An OT security owner identified (this does not necessarily have to be a CISO)
- Management aware of NIS2 obligations and of the penalties for non-compliance
- Security policies approved by management that explicitly cover OT
The Most Common Mistakes in Manufacturing SMEs
Confusing IT compliance with OT compliance: holding an ISO 27001 certification for IT does not mean being NIS2 compliant for the OT environment. NIS2 applies to the entire organization, including industrial control networks. An audit that does not enter the OT network is not a complete NIS2 audit.
Relying only on policies and documents without technical evidence: NIS2 is not just a documentation exercise. An auditor who asks to see the monitoring logs from the last three months, or the up-to-date list of OT assets, or the evidence of a recent vulnerability assessment, will not be satisfied with a Word document that describes how these processes work in theory. Technical evidence counts.
Underestimating the notification requirements: the 24-hour deadline for the early warning of a significant incident is much tighter than many organizations realize. Without a well-rehearsed detection and escalation process, meeting it is impossible. Discovering an incident on Monday morning, realizing it is significant on Wednesday, and notifying on Friday falls outside the required timeframes.
Ignoring the supply chain: automation vendors that access plants remotely are an often underestimated risk vector. NIS2 explicitly requires this risk to be managed. Keeping permanent VPN access open to multiple vendors without logging or session control is a gap that an auditor will notice.
Starting from the policy instead of from visibility: the logical order is inverted compared with the bureaucratic approach. First visibility (knowing what is on the OT network), then risk assessment (understanding what is critical and vulnerable), then technical measures, and finally the documentation that describes what you do. Starting by writing policies without technical visibility produces documents that do not match reality.
The NIS2 journey for a manufacturing SME is not short, but it is not unreachable either. Starting from the OT asset inventory and progressively building detection and incident handling capabilities is a workable path, and it delivers benefits in terms of operational security regardless of the regulatory obligation.
The MON5 Angle
Most of the items in this checklist, asset inventory, vulnerability management, detection, evidence for auditors, depend on a single foundational capability: visibility into the OT network. MON5 builds it starting from the assessment (the DISCOVER phase) and turns it into usable evidence with the ANALYZE phase: continuous inventory, correlation of CVEs with EPSS scores and real exposure, and direct support for NIS2 compliance.
For an SME, the advantage is the modular path: you start with what you need to close the most evident gaps and grow in phases. To find out how many boxes on the checklist you can already tick, begin with an OT assessment.
Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.
Related articles

Compliance
How to Prove NIS2 Compliance in an Audit: The Technical Evidence That Really Counts
NIS2 is not proven with policies: it is proven with technical evidence. What auditors look for in an OT audit, how to prepare evidence before they arrive, and the role of continuous monitoring as documentary proof.
Compliance
IEC 62443 zones and conduits: how to apply it to a real plant without a year of consulting
IEC 62443 is often seen as out of reach for SMEs. Yet zones and conduits are practical tools you can apply to real plants, starting from visibility and reaching formal segmentation step by step.
Cybersecurity
OT incident notification under NIS2: obligations, timelines and what to have ready before it happens
NIS2 sets tight deadlines for notifying significant incidents: 24 hours for the early warning, 72 hours for the detailed notification. In OT, being ready to meet them takes preparation that starts long before the incident.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.
Learn more about the regulation: NIS2