What is changing
NIS2 in manufacturing: three issues to put in order
NIS2 covers a wider group of manufacturing companies and changes how cybersecurity is managed: self-assessment, management accountability and IT, OT and supplier risk become part of a single process.
Change 1
You classify yourself – and you register yourself
The manufacturing scope of KSC is specific. It covers electronics, electrical equipment, machinery, vehicles and certain medical devices, among others. Company size also matters. Details in the FAQ.
⚠ Registration within 6 months
Change 2
Management is accountable, not the IT department
Management approves risk management measures and is personally accountable for them. In a plant, ERP, MES, SCADA, PLCs, engineering workstations and vendor maintenance access form a single chain of dependencies – risk must be assessed from the perspective of the production process, not separate technology silos.
✓ Personal liability
Change 3
The scope is the whole organisation: IT, OT and suppliers
An MES outage, ransomware in IT, a PLC fault or unavailable maintenance support can stop a line. BIA and continuity plans should show which processes must be restored first and what they depend on.
✓ IT + OT + supply chain
Map of obligations
Five areas you need to maintain and be able to demonstrate
Audits and inspections quickly come down to specifics: who approved the risk, when the plan was tested, which actions are open, how the supplier was assessed and where the change history is.
1
Classification and registration
Self-identification, entry in the KSC register and keeping data and contact persons up to date.
2
Risk management and security measures
Risk assessment of IT and OT systems, security measures, business continuity and regular reviews.
3
Supply chain
Assessment of ICT and OT suppliers and control of security requirements and third-party access.
4
Incident handling
Incident classification, meeting the required reporting deadlines and documenting decisions, communication and post-incident actions.
5
Management oversight, training and audit
Management oversight, training, security audit, and planning and monitoring of corrective actions.
Timeline
Deadlines counted from the Act’s entry into force
3 Apr 2026
The KSC Act implementing NIS2 enters into force. All further deadlines are counted from this date.
3 Oct 2026
+6 months
+6 months
Registration in the KSC register (S46 system) and appointment of a cybersecurity contact person. The nearest deadline for most manufacturing companies.
3 Apr 2027
+12 months
+12 months
Full implementation of the information security management system and statutory measures – including documentation and approval by the management board.
3 Apr 2028
+24 months
+24 months
First security audit for essential entities – then at regular intervals. From this point on, fines become a real prospect.
ongoing
Incident reporting within 24 h / 72 h, risk reviews, plan testing, supplier assessments, board and staff training.
Legal basis: Directive (EU) 2022/2555 (NIS2) and the Polish Act of 5 July 2018 on the National Cybersecurity System (KSC), as amended. Annex II to the KSC Act covers specific types of manufacturing, including electronics, electrical equipment, machinery, motor vehicles, other transport equipment and medical devices. Classification depends on the type of activity and the rules in Article 5 of the KSC Act.
Sector specifics
In manufacturing, a cyber incident can stop a physical process
Ransomware, an MES outage, an industrial network problem or an unavailable control system can stop a line, a warehouse or shipping. That is why cyber risk must be linked to the production process and its business impact.
Electronics and optics
Computers, electronics and optical products
Manufacturing of computers, electronic and optical products – heavily dependent on test systems, software and global component suppliers.
Electrical equipment
Manufacturing of electrical equipment
Motors, transformers, switchgear, cables and other electrical equipment. Lines depend on automation, quality systems and on-time component deliveries.
Machinery and equipment
Manufacturing of machinery and equipment
Machinery manufacturing depends heavily on automation, design systems, software and remote maintenance.
Automotive
Motor vehicles, trailers and semi-trailers
In automotive, downtime of a single line or supplier can affect the entire supply chain, so dependencies and recovery priorities are crucial.
Transport equipment
Other transport equipment
Ships, rolling stock, aircraft and other means of transport. Long production cycles and complex subcontractor chains require supplier oversight.
Medical devices
Medical devices and in vitro diagnostics
Production under strict quality and regulatory regimes – downtime or a breach of production data integrity can affect the availability of devices for healthcare.
What this means in practice: risk assessments and continuity plans must cover both IT and OT (PLCs, SCADA, MES, industrial networks), as well as dependencies on suppliers and maintenance providers. More details in the FAQ.
BCMLogic Next for industry
A GRC system for industrial manufacturing
BCMLogic Next connects IT/OT risks, BIA, continuity plans, incidents, suppliers and actions. As a result, security, IT, maintenance and process owners all work on one dependency model.
Already have documentation? We move it into the system. Starting from scratch? Wizards guide you through.
We can migrate your existing documentation into the system or start with wizards that guide users step by step.
IT and OT risk assessment
Risks for IT, OT and production processes, with owners, actions and change history.
Step-by-step wizard
Policies and procedures
Templates, approval workflows, version history and audit trail.
Ready-made templates
Business continuity plans
BIA, BCP and DRP for critical production processes – with dependencies on machines, systems, utilities, staff and suppliers.
MES and OT failure scenarios
Incident management
Incident handling with 24 h / 72 h deadlines, classification and a clear course of action.
24 h / 72 h timer
Suppliers and supply chain
Register and risk assessment of machine builders, integrators, maintenance, automation, software and other suppliers that affect production.
OT and maintenance supplier register
Audit readiness
Compliance status, approval and review history, and reports that support audit preparation.
Report for the auditor
Note for the largest entities – the CER Directive:
Some manufacturing companies may also be subject to critical entity resilience requirements. The scope should be verified separately; details are in the FAQ.
Some manufacturing companies may also be subject to critical entity resilience requirements. The scope should be verified separately; details are in the FAQ.
Online demo
Want to see how it works in practice?
Explore BCMLogic Next with demo data or book a 30-minute meeting and walk through a manufacturing plant scenario with us.
🖥
Online demo environment
Ready-made demo data: risks, incidents, business continuity and NIS2 compliance.
📞
A short meeting with our team
30 minutes for a system walkthrough and questions about your organisation and where you are in your NIS2 preparations.
FAQ · NIS2 and GRC in industrial manufacturing
Frequently asked questions about NIS2/KSC in industrial manufacturing
A brief guide to classification, ISMS, service continuity, suppliers and audit preparation.
Which manufacturing companies are covered by NIS2/KSC?
The manufacturing scope of KSC covers specific activities listed in Annex II: computers, electronic and optical products, electrical equipment, machinery, motor vehicles, other transport equipment and medical devices, among others. Status must be determined based on the actual activity, company size and the rules in Article 5 of the KSC Act.
Does a NIS2 risk assessment in a factory have to cover OT?
Yes. In manufacturing, the risk assessment should also cover the OT environment – PLCs, SCADA, MES and industrial networks – as well as process dependencies, technology and maintenance suppliers, and production line continuity.
Does a NIS2 fine require an incident to occur?
No. Penalties may also result from failing to meet other obligations, such as registration, risk management, incident reporting or the required audit.
We have ISO 27001, an ISMS or a risk assessment. Do we need to start over?
No. Existing materials can be migrated to the platform by your team, BCMLogic or a partner. The goal is not to recreate documentation, but to keep risks, plans, actions and evidence in a single GRC system.
Does BCMLogic Next replace a NIS2 consultant or integrator?
It does not have to. BCMLogic Next can act as the platform that maintains the results of a project delivered by an external consultant or integrator. It lets you keep working with risks, documentation, suppliers, incidents and tasks after the implementation ends.
How does BCMLogic Next support audit preparation?
The platform keeps a history of changes, approvals, reviews, tests and actions. As a result, the information needed for an audit does not have to be gathered from multiple spreadsheets, documents and systems every time.
How do you prepare a manufacturing plant for a NIS2/KSC audit?
Start by compiling the evidence: an up-to-date IT and OT risk assessment, management-approved policies, BIA and continuity plans with test history, a supplier register and an incident register. In BCMLogic Next this information is kept up to date, so you do not have to gather it from multiple spreadsheets before every audit.
Can a manufacturing company also be subject to the CER Directive?
Some manufacturing companies may also be subject to critical entity resilience rules. Their status needs to be verified separately. BCMLogic Next can be used to manage requirements and evidence for multiple regulations in one environment.
How do you connect NIS2 with production continuity?
First, identify critical processes and lines, then link them to machines, IT/OT systems, utilities, staff and suppliers. A BIA lets you determine the impact of downtime and recovery priorities.
How should suppliers and remote machine maintenance be handled?
Start with suppliers that have access to OT or affect production continuity: machine builders, integrators, maintenance, automation and software providers. In a GRC system you can link them to processes, risks, requirements and review dates.
Next step
See how a GRC system for a manufacturing company works
Explore the platform online or book a short demo tailored to the processes, risks and requirements of your plant.