[Home](/)/[Resources](/resources)/EU NIS2 Directive and Hardware Manufacturers

EUCybersecurityRegulation guide

# EU NIS2 Directive and Hardware Manufacturers

Directive (EU) 2022/2555 — NIS2 — extends cybersecurity obligations to a much broader set of entities than its predecessor, including manufacturers of connected products, critical infrastructure operators, and digital infrastructure providers. For hardware companies, NIS2 creates direct obligations if you operate in a covered sector or supply critical infrastructure operators who are themselves NIS2 obligated.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Feu-nis2-directive-hardware)

At a glance

Directive

(EU) 2022/2555

Transposition deadline

October 2024

Initial report

Within 24 hours

Full report

Within 72 hours

Max fine (essential)

€10M or 2% turnover

## Who NIS2 applies to

NIS2 applies to entities in 18 covered sectors above defined size thresholds, and to certain critical entities regardless of size. Hardware manufacturers whose NACE codes fall within scope — particularly electronics and machinery manufacturing — face direct obligations. Even out-of-scope manufacturers face indirect pressure through their customers' supply chain security requirements.

### Essential Entities

Organisations in energy (electricity, oil, gas, hydrogen), transport (air, rail, water, road), banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure (internet exchange points, DNS, TLD registries, cloud, data centres, CDN, trust services, electronic communications), and public administration. Subject to proactive supervision and the highest sanction levels.

**Threshold:** All sizes in most sectors; some sectors have 250+ employee / €50M+ turnover thresholds.

### Important Entities

Includes manufacturers of medical devices (Class IIa and above under MDR/IVDR), computers and electronic components (NACE C26), electrical equipment (NACE C27), machinery (NACE C28), motor vehicles (NACE C29), and other transport equipment. Also covers postal services, waste management, chemicals, food, and digital providers not in the essential category.

**Threshold:** Medium enterprises (50+ employees or €10M+ annual turnover) and above within covered sectors.

### Supply Chain Obligations

Even if your organisation is not itself a covered entity, NIS2 requires essential and important entities to assess and manage cybersecurity risks in their supply chains. This creates indirect obligations for hardware manufacturers who supply NIS2-covered operators — your customers will ask for evidence of your security posture, vulnerability management process, and incident reporting capability.

**Threshold:** Applies to suppliers of covered entities regardless of the supplier's own size or sector.

### Size Thresholds

NIS2 generally applies to medium and large enterprises — those with 50 or more employees, or annual turnover/balance sheet above €10 million. Micro and small enterprises are excluded from direct NIS2 obligations in most sectors, with narrow exceptions for critical infrastructure operators and specific digital service providers regardless of size.

**Threshold:** Medium: 50–249 employees, €10M–€50M turnover. Large: 250+ employees, >€50M turnover.

## Core NIS2 obligations for manufacturers

NIS2 mandates a risk-based approach — measures must be appropriate and proportionate to the risks faced. Article 21 sets out the minimum security measures required. Member state implementing legislation may add further requirements. Senior management bears personal responsibility for approving and overseeing implementation.

01

Risk management measures: covered entities must implement appropriate and proportionate technical, operational, and organisational measures to manage cybersecurity risks. Measures must address: policies on risk analysis and information system security, incident handling, business continuity, supply chain security, network and information systems security, access control, cryptography, and human resources security.

02

Incident reporting — initial notification within 24 hours: any significant incident (one that causes or could cause severe operational disruption or financial loss, or affects other natural or legal persons significantly) must be reported to the relevant CSIRT or competent authority within 24 hours of becoming aware.

03

Incident reporting — full report within 72 hours: a full incident notification must follow within 72 hours, including an initial assessment of severity and impact, indicators of compromise if available, and any mitigation measures applied.

04

Incident reporting — final report within 1 month: a final report must be submitted within one month of the initial notification, including a detailed description, type of threat or root cause, mitigation measures applied, and cross-border impact assessment where relevant.

05

Supply chain security: entities must address security risks in their supply chains, including security-related aspects of relationships with direct suppliers and service providers. This requires contractual security requirements for suppliers, periodic security assessments of critical suppliers, and incident communication clauses.

06

Access controls and authentication: multi-factor authentication (MFA) or continuous authentication solutions must be used where technically feasible. Privileged access must be segregated and monitored. Remote access must use encrypted channels.

07

Vulnerability disclosure and handling: covered entities must have processes for identifying, assessing, and remediating vulnerabilities in their products and services. Coordinated vulnerability disclosure policies are expected. This overlaps with CRA requirements for product manufacturers.

08

Business continuity planning: entities must maintain plans covering backup management, disaster recovery, crisis management, and the ability to restore systems and services within defined recovery time objectives.

## NIS2 and CRA overlap — building one compliance program

Hardware manufacturers who face both NIS2 (as an entity) and CRA (as a product manufacturer) are navigating complementary but distinct frameworks. Understanding the overlap is essential for building an efficient, non-duplicative compliance program.

### Level of Obligation

NIS2 is an entity-level obligation — it applies to the organisation as an operator of networks and information systems. The Cyber Resilience Act (CRA) is a product-level obligation — it applies to manufacturers placing products with digital elements on the EU market. A hardware manufacturer may face both: NIS2 if they operate in a covered sector or above the size threshold, and CRA for every connected product they place on the market.

### Supply Chain Security Overlap

NIS2 requires covered entities to assess supply chain cybersecurity and impose contractual requirements on suppliers. CRA requires product manufacturers to have vulnerability handling processes and SBOMs. These requirements reinforce each other: CRA compliance evidence (SBOM, vulnerability disclosure policy, security documentation) directly satisfies NIS2 supply chain security evidence requests from customers.

### Incident Reporting Differences

NIS2 incident reporting applies to significant incidents affecting the entity's own systems or services. CRA incident reporting applies to actively exploited vulnerabilities in products on the market — reported to ENISA and competent authorities. The reporting timelines differ (NIS2: 24h/72h/1 month; CRA: 24h early warning for actively exploited vulnerabilities, 72h for significant incidents). Both may trigger simultaneously for a product vulnerability exploited against a NIS2-covered operator.

### Avoiding Compliance Duplication

Manufacturers who face both NIS2 (as an entity) and CRA (as a product manufacturer) should build a unified security governance framework. A single vulnerability management process, a single coordinated disclosure policy, and a unified incident response procedure can satisfy both frameworks without duplication. Map the specific requirements of each against your organisational structure to identify gaps and overlaps.

## Implementation across EU member states

NIS2 is a directive — it sets minimum requirements that member states must transpose into national law. Implementation varies in timing and in certain national additions. Manufacturers operating across multiple EU markets must track the applicable national legislation in each jurisdiction where they have significant operations.

### Transposition Deadline — October 2024

EU Member States were required to transpose NIS2 into national law by 17 October 2024. Implementation quality and timing varies — some states transposed fully on time, others had delays. Manufacturers operating across multiple EU markets must track national implementing legislation in each relevant jurisdiction, as competent authorities and sanction structures differ.

### Competent Authorities by Sector

NIS2 is supervised by sector-specific competent authorities rather than a single pan-EU body. For manufacturing sectors, the competent authority is typically the national cybersecurity authority (e.g. BSI in Germany, ANSSI in France, NCSC in the Netherlands) or a sectoral regulator. ENISA coordinates at EU level and publishes guidance, but enforcement is national.

### Supervisory Powers

Competent authorities have broad powers under NIS2: on-site inspections, off-site supervision, targeted security audits, security scans, requests for information, and the ability to issue binding instructions. For essential entities, proactive supervision applies regardless of whether an incident has occurred. For important entities, supervision is primarily reactive.

### Sanctions

For essential entities: administrative fines of up to €10,000,000 or 2% of total worldwide annual turnover (whichever is higher). For important entities: up to €7,000,000 or 1.4% of worldwide annual turnover. Member states may impose additional criminal penalties for natural persons (management liability). Personal liability for senior management is an explicit NIS2 feature — management bodies can be held responsible for compliance failures.

## Frequently asked questions

### Does NIS2 apply directly to hardware manufacturers or only to their customers?

NIS2 can apply directly to hardware manufacturers if they fall within a covered sector and meet the size thresholds. The manufacturing of computers and electronic components (NACE C26), electrical equipment (NACE C27), and machinery (NACE C28) is explicitly listed in Annex II as covered sectors for important entities. A medium or large enterprise in these categories must register with their national competent authority and implement the full NIS2 risk management and incident reporting obligations. Even if a manufacturer does not meet the thresholds for direct application, their NIS2-covered customers will impose supply chain security requirements derived from NIS2.

### What's the difference between NIS2 and the CRA for a connected product maker?

NIS2 governs how your organisation manages cybersecurity risks in its own operations and supply chain — it is an entity-level framework. The CRA governs the security properties of the products you place on the market — it is a product-level framework. A connected product manufacturer may face both: NIS2 obligations for the company (if in scope), and CRA obligations for every connected product (applicable from December 2027 regardless of company size). The two frameworks have significant overlap in vulnerability management and supply chain security — a unified compliance program covering both is more efficient than treating them separately.

### What incident reporting timeline does NIS2 require?

NIS2 sets a three-stage reporting timeline for significant incidents. Within 24 hours of becoming aware: an early warning to the relevant CSIRT or competent authority indicating whether the incident is suspected to be malicious and whether it has cross-border impact. Within 72 hours: a full incident notification with initial severity assessment, likely cause, and mitigation measures applied. Within 1 month: a final report with detailed incident description, type of threat or root cause, applied and ongoing mitigation measures, and cross-border impact where relevant. Intermediate reports may be requested by the CSIRT or authority during the response period.

### How do we identify if our products supply NIS2-covered sectors?

Review Annexes I and II of Directive (EU) 2022/2555, which list covered sectors and subsectors. If your products are specifically designed or marketed for use in energy infrastructure, healthcare systems, water treatment, transport control systems, financial market infrastructure, or digital infrastructure (cloud, data centres, DNS), your customers are likely NIS2-covered entities. Conduct a customer segmentation analysis against the Annex lists. For industrial IoT and control system products, most industrial operators above the size threshold in covered sectors are NIS2 entities. Their procurement teams will increasingly request security documentation and vulnerability management evidence as contractual requirements.

**Disclaimer:** This page is an educational resource only and does not constitute legal or regulatory advice. NIS2 obligations depend on your specific sector, size, and the national implementing legislation in each relevant member state. Always consult qualified legal counsel with cybersecurity regulatory expertise for entity-specific compliance assessments.

🇪🇺 CE Marking roadmap for your product

Every standard, document, and test that applies — free, no account required.

See your free roadmap[

Want an expert to take your product through 🇪🇺 CE Marking compliance for you?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

See compliance services](/services)

Learn this properly

In-depth course that teaches the full process, not just this one answer.

[Start the course — $149](/courses/08-cybersecurity-compliance-connected-electronics)[Prefer to read? Get the book — $24.99](/books/08-cybersecurity-compliance-connected-electronics)

Related guides

*   [EU Cyber Resilience ActEU Cyber Resilience Act for hardware: default-secure requirements, vulnerability disclosure, 24-hour incident notification, and the four Annex I product classes.](/guides/eu-cyber-resilience-act)
*   [RED Cybersecurity Delegated ActCommission Delegated Regulation (EU) 2022/30 activates RED Article 3.3(d)(e)(f) for Wi-Fi, Bluetooth, and cellular products.](/guides/red-cybersecurity-delegated-act)
*   [UK NIS RegulationsThe UK NIS Regulations 2018 create supply chain obligations that affect hardware and IoT product suppliers to regulated sectors.](/guides/uk-nis-regulations)
*   [US NIST IoT CybersecurityGuide to NIST SP 800-213 and SP 800-213A — the six IoT device cybersecurity capability baseline areas, non-technical documentat…](/guides/us-nist-iot-cybersecurity)