This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
    • Learn more about this provideropens in a new window
      CookieConsentStores the user's cookie consent state for the current domain
      Maximum Storage Duration: 1 yearType: HTTP Cookie
    • Learn more about this provideropens in a new window

      Some of the data collected by this provider is for the purposes of personalization and measuring advertising effectiveness. The provider may use the IP Addresses for ads measurement and ads personalization.

      rc::aThis cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
      Maximum Storage Duration: PersistentType: HTML Local Storage
      rc::cThis cookie is used to distinguish between humans and bots.
      Maximum Storage Duration: SessionType: HTML Local Storage
    • Learn more about this provideropens in a new window
      __cf_bmThis cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      bcookieUsed in order to detect spam and improve the website's security.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      li_gcStores the user's cookie consent state for the current domain
      Maximum Storage Duration: 180 daysType: HTTP Cookie
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • Learn more about this provideropens in a new window
      lidcRegisters which server-cluster is serving the visitor. This is used in context with load balancing, in order to optimize user experience.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • Learn more about this provideropens in a new window

      Some of the data collected by this provider is for the purposes of personalization and measuring advertising effectiveness. The provider may use the IP Addresses for ads measurement and ads personalization.

      _gaUsed to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.
      Maximum Storage Duration: 2 yearsType: HTTP Cookie
      _ga_#Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.
      Maximum Storage Duration: 2 yearsType: HTTP Cookie
    • _gat [x2]Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • Learn more about this provideropens in a new window

      Some of the data collected by this provider is for the purposes of personalization and measuring advertising effectiveness. The provider may use the IP Addresses for ads measurement and ads personalization.

      _gidUsed to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
    • Learn more about this provideropens in a new window
      __Secure-ROLLOUT_TOKENUsed to track user’s interaction with embedded content.
      Maximum Storage Duration: 180 daysType: HTTP Cookie
      __Secure-YECStores the user's video player preferences using embedded YouTube video
      Maximum Storage Duration: SessionType: HTTP Cookie
      __Secure-YNIDUsed to track user’s interaction with embedded content.
      Maximum Storage Duration: 180 daysType: HTTP Cookie
      LAST_RESULT_ENTRY_KEYUsed to track user’s interaction with embedded content.
      Maximum Storage Duration: SessionType: HTTP Cookie
      LogsDatabaseV2:V#||LogsRequestsStoreUsed to track user’s interaction with embedded content.
      Maximum Storage Duration: PersistentType: IndexedDB
      TESTCOOKIESENABLEDUsed to track user’s interaction with embedded content.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      VISITOR_INFO1_LIVETries to estimate the users' bandwidth on pages with integrated YouTube videos.
      Maximum Storage Duration: 180 daysType: HTTP Cookie
      YSCRegisters a unique ID to keep statistics of what videos from YouTube the user has seen.
      Maximum Storage Duration: SessionType: HTTP Cookie
      yt-icons-last-purgedNecessary for the implementation and functionality of YouTube video-content on the website.
      Maximum Storage Duration: PersistentType: HTML Local Storage
      YtIdbMeta#databasesUsed to track user’s interaction with embedded content.
      Maximum Storage Duration: PersistentType: IndexedDB
  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • We do not use cookies of this type.

Cookie declaration last updated on 8/14/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NIS2 Compliance for OT: Requirements, Controls & Roadmap

For operational technology teams, NIS2 Compliance is not simply another policy exercise. It requires organizations to show that cybersecurity risks affecting critical services are understood, controlled, monitored, and managed at leadership level.

That can be difficult in OT environments. Industrial networks often contain legacy assets, proprietary protocols, long equipment lifecycles, vendor dependencies, and systems that cannot be patched or restarted without operational consequences.

The NIS2 Directive expands the EU cybersecurity framework across 18 critical sectors and strengthens requirements for cybersecurity risk management, incident reporting, supply chain security, supervision, and governance.

For OT cybersecurity professionals, the practical question is therefore not just, "What are the NIS2 Requirements?" It is how to translate those requirements into controls that work inside real industrial environments.

What Is NIS2 Compliance?

NIS2, formally Directive (EU) 2022/2555, establishes a common cybersecurity framework across the European Union. It replaced the original NIS Directive and significantly expanded the organizations and sectors covered.

Being NIS2 compliant means implementing appropriate and proportionate cybersecurity risk-management measures, maintaining incident-reporting capabilities, establishing management oversight, and being able to demonstrate that those measures are operating effectively.

NIS2 is an EU directive, so organizations must also consider the national legislation that transposes it in each relevant Member State. The EU deadline for Member States to transpose NIS2 was October 17, 2024.

This distinction matters for multinational industrial operators. The core obligations come from NIS2, but regulatory procedures, supervisory authorities, and certain implementation details may vary by jurisdiction.

Which OT Organizations Are Subject to NIS2?

NIS2 covers organizations across sectors where disruption could have significant economic or societal consequences.

OT-heavy sectors include energy, transport, drinking water, wastewater, healthcare, chemicals, waste management, food, and several manufacturing categories. The Directive also covers digital infrastructure, ICT service management, public administration, space, research, and other sectors.

Organizations are generally classified as either essential entities or important entities. The classification influences how supervision and enforcement are applied. NIS2 also uses factors including sector, organizational size, and criticality when determining scope.

For OT security leaders, determining scope should be the first step. Identify which legal entities, plants, services, systems, and jurisdictions are affected before designing a compliance program.

Core NIS2 Compliance Requirements for OT

The NIS2 Compliance requirements follow a risk-based approach rather than prescribing one fixed technical architecture.

The Directive identifies ten core areas organizations must address within cybersecurity risk management. These include incident handling, supply chain security, vulnerability management, cryptography, and other fundamental security measures.

For OT teams, these requirements translate into several practical priorities:

  • Risk analysis and security policies: Assess risks to critical industrial processes, assets, networks, safety dependencies, and supporting IT infrastructure.

  • Incident handling: Establish OT-specific detection, containment, escalation, investigation, and recovery procedures.

  • Business continuity: Maintain tested backups, disaster recovery processes, crisis procedures, and recoverable system configurations.

  • Supply chain security: Evaluate OEMs, integrators, maintenance providers, software suppliers, and vendors with remote access.

  • Vulnerability management: Identify vulnerabilities and determine remediation based on exploitability, operational impact, vendor guidance, and compensating controls.

  • Security effectiveness: Test whether controls work through monitoring, exercises, audits, assessments, and remediation tracking.

Cyber hygiene and training: Provide role-specific training for operators, engineers, administrators, security teams, and management.

Cryptography: Protect communications and sensitive information where appropriate.

Access and asset management: Maintain accurate asset inventories and control user, administrator, and third-party access.

Strong authentication: Apply technologies such as MFA where appropriate, particularly for privileged and remote access.

The important point is that a written policy alone is insufficient. Organizations should be able to show how these controls operate within the industrial environment.