---
title: "NIS2 for manufacturers and plants: who is covered and what it asks | Edge SDN"
description: "Who NIS2 covers, including machinery manufacturing, the ten risk-management measures of Article 21, reporting in 24 hours, fines and the Italian law 138/2024. With links to each article."
url: https://www.edge-sdn.com/regulations/nis2/
last_updated: 2026-09-30
---

Directive (EU) 2022/2555

# Check whether NIS2 applies to your company

Last updated 30 September 2026. A summary, not legal advice. Always check the official text for your case.

What does NIS2 ask a company?

NIS2 asks medium and large organisations in critical sectors, including the manufacturing of machinery, to manage cybersecurity risk, secure their supply chain and report significant incidents within 24 hours. Management approves the measures and can be held liable. Each Member State has its own law: in Italy it is Legislative Decree 138/2024.

Early warning of a significant incident[Article 23(4)(a)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555#art%5F23)

Or 2% of worldwide turnover, whichever is higher, for essential entities. National law may set more[Article 34(4)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555#art%5F34)

Or 1.4% of worldwide turnover, whichever is higher, for important entities. National law may set more[Article 34(5)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555#art%5F34)

Who is covered

## Medium and large organisations in the listed sectors

Sectors in Annex I and II, from medium size up. Manufacturing is in Annex II:

- Machinery and equipment n.e.c. (NACE division 28)
- Computer, electronic and optical products (26) and electrical equipment (27)
- Motor vehicles (29), other transport equipment (30), medical devices

[Article 2](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555#art%5F2) · [Annex II](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555#anx%5FII)

Article 21

## Take ten risk-management measures, at least

Appropriate and proportionate to the risk, the size of the entity and the state of the art.

1. Risk analysis and information system security policies
2. Incident handling
3. Business continuity, backups, disaster recovery
4. Supply chain security
5. Security in acquisition, development and maintenance, including vulnerability handling
6. Assessing the effectiveness of the measures
7. Basic cyber hygiene and training
8. Cryptography and encryption
9. Human resources security, access control and asset management
10. Multi-factor authentication and secured communications

[Article 21(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555#art%5F21)

Article 23

## Report a significant incident in three steps

To the national CSIRT or the competent authority. Where appropriate, also tell the recipients of your services.

1. **Early warning within 24 hours**Say whether it may be malicious or cross-border.
2. **Notification within 72 hours**A first assessment, severity and impact.
3. **Final report within one month**Root cause and the measures taken.

[Article 23(4)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555#art%5F23)

In Italy

## Legislative Decree 138/2024

In force since 16 October 2024. The Agenzia per la Cybersicurezza Nazionale (ACN) is the competent authority. Entities in scope register on the ACN platform and keep the registration up to date.

[The NIS legislation on the ACN site](https://www.acn.gov.it/portale/en/nis/la-normativa)

[Article 20(1)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555#art%5F20)

**What NIS2 does not do**

It does not certify products and it does not name a technology. It asks your organisation for measures. A product can support some of them, never all.

### What to do first

- Check whether your company is in scope in your country
- Map the assets and flows of the OT network
- Segment by process, starting from the most critical line

Our products

## Which products help, and why

Built for it

### Edge SDN

Segmentation and access control; asset inventory and vulnerability scanning with the Advanced probe; IDS for incident handling; NIS2 reports as evidence.

Article 21(2)(a), (b), (e), (i)

[Explore Edge SDN](https://www.edge-sdn.com/products/edge-sdn/)

Helps with a part

### Edge Shield

Isolates machines that cannot be patched; its IDS helps incident handling.

Article 21(2)(b), (e)

[Explore Edge Shield](https://www.edge-sdn.com/products/edge-shield/)

Helps with a part

### Shield Lifecycle

Supply chain security: the plant receives SBOM, VEX and notices from its machine builders.

Article 21(2)(d)

[Explore Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/)

FAQ

## Questions about NIS2

### Is a machine builder in scope of NIS2?

A medium or large company that manufactures machinery and equipment (NACE Rev. 2, division 28) is in Annex II, so it is in scope, as an important entity unless it is designated essential ([Article 2](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555#art%5F2), [Annex II](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555#anx%5FII)). Check your national law for the details.

### What is the law in Italy?

Legislative Decree 138/2024, in force since 16 October 2024. The competent authority is the Agenzia per la Cybersicurezza Nazionale (ACN), and entities in scope register on its platform ([ACN](https://www.acn.gov.it/portale/en/nis/la-normativa)).

### Does NIS2 affect me if I am a small supplier?

Not directly. But your customers in scope must manage the security of their supply chain ([Article 21(2)(d)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555#art%5F21)), so they ask their suppliers for security documentation and a vulnerability process.

### Are the managers personally responsible?

The management bodies approve the risk-management measures, oversee them and can be held liable for infringements. They must also follow training ([Article 20](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555#art%5F20)).

## Where are you against 20 January 2027?

Seven questions about how you work today. Three minutes. You get a score out of 10 and what is missing for you.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026
