Check whether NIS2 applies to your company
Last updated 30 September 2026. A summary, not legal advice. Always check the official text for your case.
NIS2 asks medium and large organisations in critical sectors, including the manufacturing of machinery, to manage cybersecurity risk, secure their supply chain and report significant incidents within 24 hours. Management approves the measures and can be held liable. Each Member State has its own law: in Italy it is Legislative Decree 138/2024.
Medium and large organisations in the listed sectors
Sectors in Annex I and II, from medium size up. Manufacturing is in Annex II:
- Machinery and equipment n.e.c. (NACE division 28)
- Computer, electronic and optical products (26) and electrical equipment (27)
- Motor vehicles (29), other transport equipment (30), medical devices
Take ten risk-management measures, at least
Appropriate and proportionate to the risk, the size of the entity and the state of the art.
- Risk analysis and information system security policies
- Incident handling
- Business continuity, backups, disaster recovery
- Supply chain security
- Security in acquisition, development and maintenance, including vulnerability handling
- Assessing the effectiveness of the measures
- Basic cyber hygiene and training
- Cryptography and encryption
- Human resources security, access control and asset management
- Multi-factor authentication and secured communications
Report a significant incident in three steps
To the national CSIRT or the competent authority. Where appropriate, also tell the recipients of your services.
- Early warning within 24 hoursSay whether it may be malicious or cross-border.
- Notification within 72 hoursA first assessment, severity and impact.
- Final report within one monthRoot cause and the measures taken.
Legislative Decree 138/2024
In force since 16 October 2024. The Agenzia per la Cybersicurezza Nazionale (ACN) is the competent authority. Entities in scope register on the ACN platform and keep the registration up to date.
The NIS legislation on the ACN site
the management bodies of essential and important entities approve the cybersecurity risk-management measures […] oversee its implementation and can be held liable for infringements
What to do first
- Check whether your company is in scope in your country
- Map the assets and flows of the OT network
- Segment by process, starting from the most critical line
Which products help, and why
Edge SDN
Segmentation and access control; asset inventory and vulnerability scanning with the Advanced probe; IDS for incident handling; NIS2 reports as evidence.
Article 21(2)(a), (b), (e), (i)
Explore Edge SDN Helps with a partEdge Shield
Isolates machines that cannot be patched; its IDS helps incident handling.
Article 21(2)(b), (e)
Explore Edge Shield Helps with a partShield Lifecycle
Supply chain security: the plant receives SBOM, VEX and notices from its machine builders.
Article 21(2)(d)
Explore Shield LifecycleQuestions about NIS2
Is a machine builder in scope of NIS2?
What is the law in Italy?
Legislative Decree 138/2024, in force since 16 October 2024. The competent authority is the Agenzia per la Cybersicurezza Nazionale (ACN), and entities in scope register on its platform (ACN).
Does NIS2 affect me if I am a small supplier?
Not directly. But your customers in scope must manage the security of their supply chain (Article 21(2)(d)), so they ask their suppliers for security documentation and a vulnerability process.
Are the managers personally responsible?
The management bodies approve the risk-management measures, oversee them and can be held liable for infringements. They must also follow training (Article 20).
Where are you against 20 January 2027?
Seven questions about how you work today. Three minutes. You get a score out of 10 and what is missing for you.
Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026