NIS2 in manufacturing: when it applies and what the deadlines are
Machinery makers above 50 staff usually fall under NIS2. Registration within 60 days, incident report within 24 hours, fines reaching millions of euros.
If you manufacture machinery and equipment and you are at least a medium sized company, meaning 50 or more staff or turnover above 10 million euros, you are very likely a regulated entity under Directive (EU) 2022/2555, known as NIS2. Manufacturing sits in the annex of important sectors. In practice that means registering with the national authority within 60 days, sending an early warning about a significant incident within 24 hours of becoming aware of it, and holding your IT and OT suppliers to contractual security duties.
One thing decides everything else: NIS2 is a directive, so the binding text is your national transposition, not the directive itself. Thresholds, the authority you report to and the size of fines differ by country.
| Obligation | Typical deadline |
|---|---|
| Notify the national authority | within 60 days of meeting the conditions |
| Early warning about a significant incident | within 24 hours of becoming aware |
| Incident notification with a first assessment | within 72 hours |
| Final report | within one month |
How do I know whether we are in scope?
Two conditions apply together: the size of the company, and the sector of the activity actually carried out, classified under NACE rather than described in marketing terms. Manufacture of machinery and equipment, NACE division 28, falls into the annex of important entities in both countries we checked.
A medium sized company is one that is no longer small. A small company has fewer than 50 staff and turnover or a balance sheet total of at most 10 million euros. Cross either of those and the size condition is met. For partner and linked undertakings the figures of the group are added together, so a subsidiary of a large group does not stay small.
Important entity status is not the same as essential or critical. The difference shows mainly in the intensity of supervision and in how far obligations reach individual managers.
How different are national rules in practice?
Very. Two examples we verified against the primary sources.
Slovakia transposed NIS2 in Act No. 69/2018 Coll. on cybersecurity. Registration goes to the National Security Authority within 60 days, incidents follow the 24 hours, 72 hours and one month sequence, and fines for serious breaches reach 7 million euros or 1.4 percent of worldwide annual turnover, whichever is higher.
Czechia replaced its old regime with Act No. 264/2025 Coll., effective 1 November 2025. Machinery manufacturers land in the lower obligations regime, incidents are reported to the national CERT rather than directly to the authority, and failing to register can cost up to 250 million Czech koruna or 2 percent of worldwide turnover.
Same directive, different authority, different reporting channel, different ceiling on fines. If you operate plants in several member states, you need the local answer for each of them.
What do we need from suppliers?
Supply chain security is the part that surprises manufacturers most. Any third party whose work touches the availability, confidentiality or integrity of your networks and systems has to be covered contractually, and the choice of supplier itself has to follow from your risk analysis.
In a plant this typically means the IT and OT administrator, the vendor of industrial control systems, remote service access to machines, cloud, backups, ERP and MES. The contract should cover the scope of access, incident and vulnerability reporting, cooperation during an incident, rules for subcontractors, audit rights, protection and return of data, continuity and service levels, and the removal of access when the relationship ends.
When is an incident significant?
National rules define it, usually through a combination of duration and impact: an outage of the service beyond a set number of minutes, a serious operational disruption, financial loss, or harm to other parties. What matters procedurally is that the clock runs from the moment you become aware, not from the moment the incident began. A company that cannot detect and classify an incident will miss the deadline before management even hears about the problem.
What this means for AI in the plant
Two consequences land directly on how you deploy AI in manufacturing. First, any tool connected to your systems is a third party with contractual security obligations. Second, data leaving the plant expands both your risk and your paperwork. That is why our deployments run on premise, inside the customer network: sensor data and service documentation never leave the factory, which keeps the number of places where data can leak, and the scope of what has to be covered contractually, as small as possible.
Frequently asked questions
We have 60 employees and 8 million euros in turnover. Are we still a small company? No. A small company must have fewer than 50 staff. On headcount alone you are above the line, so the size condition is met and only the sector classification remains to be checked.
We are a subcontractor and not listed in any annex. Why does our customer want security clauses? Because they are regulated and must pass requirements down to suppliers who touch their systems. The obligation reaches you through the contract, not directly through the law.
We found the incident on Monday but it happened on Saturday. When do the 24 hours start? From becoming aware of it. That is why detection and a named person who classifies incidents matter more than the policy document.
Our cybersecurity is outsourced. Is that enough? An external provider can run the measures, but responsibility towards the authority stays with you and management has to be demonstrably informed.
Sources
- Directive (EU) 2022/2555 (NIS2), the EU framework
- Act No. 69/2018 Coll., Slovak transposition
- Act No. 264/2025 Coll., Czech transposition effective 1 November 2025
- Commission Recommendation 2003/361/EC, the SME size definition
We verified the legal facts in this article with Nexana, a research tool for EU and national legislation.