NIS2 Industry 2026: The Complete Compliance Checklist (30 Points)

· 15 min read
15 min read
Eziwan Team
IoT Infrastructure

The NIS2 (Network and Information Security 2) Directive has been transposed into French law since October 2024. In 2026, industrial entities that have not yet begun the compliance process are operating in a high-risk environment: the first penalties from ANSSI are expected, and cyberattacks on industrial infrastructure continue to rise—according to CERT-FR, OT incidents increased by 38% between 2023 and 2025.

This article provides a clear overview of the requirements NIS2 imposes on the industry and a structured 30-point checklist to assess your level of compliance.

NIS2 at a Glance: What's Changing for French Industry

NIS2 succeeds NIS1 (2016) with a significantly expanded scope of application. European Directive 2022/2555 has been transposed into French law through a specific statute that grants ANSSI the powers to supervise, audit, and impose sanctions.

What has fundamentally changed compared to NIS1:

  • The scope is expanding significantly: NIS1 primarily covered operators of critical infrastructure (OCI) and a few critical service providers. NIS2 adds tens of thousands of additional companies, particularly in the manufacturing industry, medical device manufacturing, the chemical industry, and the production of critical materials.

  • Responsibility extends to senior management: Executives may be held personally liable in the event of serious noncompliance. They must approve security measures and complete basic cybersecurity training.

  • The notification deadlines are short: 24 hours for the initial notification in the event of a significant incident, 72 hours for the interim report, and one month for the final report.

  • These obligations extend to the subcontracting chain: You must assess the security of your critical suppliers and service providers who have access to your systems.

The directive distinguishes between two categories of entities based on their size and industry, with slightly different requirements.

Who Is Affected: Essential Entities vs. Significant Entities

Essential Entities (EE)

Essential entities are defined as large organizations (> 250 employees OR > 50 M€ in revenue OR > 43 M€ in total assets) in the following sectors:

  • Energy (electricity, gas, oil, hydrogen)
  • Transportation (air, rail, maritime, road)
  • Banking and financial market infrastructure
  • Healthcare
  • Drinking water and wastewater
  • Digital infrastructure
  • ICT services management
  • Public administration
  • Space

Critical entities are subject to proactive oversight by ANSSI: scheduled audits, on-site inspections, and a requirement to report uncertainties.

Significant Entities (SE)

The following medium-sized organizations (>50 employees OR >€10 million in revenue) in the following sectors are classified as significant entities:

  • Postal and shipping services
  • Waste management
  • Manufacturing, production, and distribution of chemicals
  • Production, processing, and distribution of food products
  • Manufacturing (including the manufacture of medical devices, computers, electronics, electrical equipment, machinery, vehicles, and transportation equipment)
  • Digital service providers
  • Research

Significant entities are subject to reactive oversight: ANSSI does not conduct audits on its own initiative, but may initiate an audit upon notification of an incident or a report.

The Case of French Industrial SMEs

An industrial SME with 75 employees and €12 million in revenue is considered a significant entity under NIS2. It is subject to all technical requirements, although compliance deadlines may be extended depending on the sector.

ANSSI has published a self-assessment tool for determining the scope of coverage, available on the anssi.fr website. If you haven't yet performed this check, this is the first step.

Technical Checklist — 30 Checkpoints

A. Inventory of Assets (5 points)

A1. Complete Inventory of IT Assets You have an up-to-date inventory of all IT equipment (servers, workstations, network equipment), including operating system versions, critical software versions, the person responsible, and business criticality. Updated at least every 6 months.

A2. Complete Inventory of OT Assets Your inventory includes controllers (PLCs, RTUs), HMIs, SCADA supervisors, IoT gateways, industrial routers, and any equipment connected to the OT network. The firmware version and the date of the last update are documented.

A3. Data Flow Mapping Communication flows between IT and OT systems are documented in the form of data flow diagrams. Undocumented flows are blocked by default (whitelist policy).

A4. Classification of Assets by Criticality Each asset is classified according to its criticality for business continuity: critical (immediate production shutdown if compromised), important (significant degradation), standard. This classification guides security priorities.

A5. Lifecycle Management A documented process manages the end of life for equipment: removal of unsupported equipment, secure decommissioning (data erasure, account removal), and recycling.

B. Access Management and Authentication (5 points)

B1. MFA for Remote Access Multi-factor authentication (MFA) is mandatory for all remote access to information systems, including VPN access to OT networks. ANSSI advises against using SMS OTP solutions; instead, use TOTP (Google Authenticator, Aegis) or FIDO2 keys.

B2. Principle of Least Privilege User accounts have only the permissions necessary to perform their duties. Dedicated administrator accounts are separate from accounts used for day-to-day work. Permissions are reviewed at least once a year and whenever a user changes positions.

B3. Management of Shared and Service Accounts Shared accounts (generic "admin" and "operator" accounts) are deleted or replaced with named accounts. Application service accounts are managed in a vault (CyberArk, Hashicorp Vault, Bitwarden Business) with automatic password rotation.

B4. Physical Access Control Physical access to server rooms, control cabinets, and technical rooms is controlled by access cards or keys, with access logs maintained. Access by external personnel is tracked.

B5. Revocation of Access A formalized process ensures that access is immediately revoked upon an employee’s departure or a change in role. The revocation timeframe is documented and is less than 24 hours for critical access.

C. VPNs and Encryption of OT Communications (5 points)

C1. VPN for All Remote OT Access All remote access to an OT network (SCADA, monitoring, PLCs) must go through an encrypted VPN (IPsec, OpenVPN, or mutual TLS). Direct Internet access to OT equipment is prohibited and technically blocked.

C2. IT/OT Segmentation The OT network is physically or logically separated from the IT network (office, company). Communication between zones goes through a DMZ or a dedicated firewall with explicit rules. The default policy is "deny all."

C3. Cloud Communication Encryption All communications between field devices and cloud platforms (MQTT, HTTPS, REST API) use at least TLS 1.2 (TLS 1.3 recommended). The certificates are valid, not self-signed, and their expiration dates are monitored.

C4. No Inbound Ports Open to the Internet No OT equipment, HMI, or supervisor is directly accessible from the Internet via an incoming port. All remote access is initiated from the equipment to the platform (using the “call home” model or access via a client VPN).

C5. Key and Certificate Management An inventory of TLS certificates, VPN keys, and application secrets is maintained. Keys and certificates set to expire within 30 days trigger an alert. A rotation process is documented.

D. Incident Detection and Response (4 points)

D1. Security Event Logging Critical equipment (firewalls, VPNs, HMIs, SCADA servers) generates security logs that are collected in a centralized system (SIEM, syslog server). Logs are retained for at least 12 months for essential entities and 6 months for important entities.

D2. Anomaly Monitoring Anomaly detection rules are active on OT network flows: connections to unknown destinations, unusual traffic volumes, connections outside of production hours, and repeated failed authentication attempts.

D3. Documented Incident Response Procedure An incident response plan (IRP) is documented, approved by management, and tested at least once a year (through a simulation exercise or tabletop drill). It covers the detection, containment, eradication, recovery, and communication phases.

D4. CERT-FR and ANSSI Contact Information Up to Date The company has registered its contact information with ANSSI via the NIS2 portal. The contact information for the security officer and management is up to date. The relevant teams are aware of the CERT-FR contact information (cert-fr.cert.gouv.fr, +33 3 51 14 17 41).

E. Business Continuity (4 points)

E1. Documented Business Continuity Plan (BCP) A BCP covering cyberattack scenarios (ransomware, SCADA compromise) is documented and tested. It defines procedures for operating under degraded conditions (manual mode, restarting from clean backups).

E2. Regular and Tested Backups The configurations of PLCs, SCADA systems, HMIs, and servers are backed up in accordance with a documented policy. Backups are stored offline or in an isolated environment. Their restoration is tested at least once every six months.

E3. Network Access Redundancy Critical sites have redundant connectivity (dual SIM with multiple carriers, fiber + 4G LTE) to maintain remote monitoring access in the event of a carrier failure.

E4. Documented Recovery Time and Point Objectives (RTO/RPO) Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and documented for each critical system. These objectives are consistent with contractual commitments to customers.

F. Training and Awareness (3 points)

F1. Mandatory Cybersecurity Training for Management NIS2 requires that executives receive training on cybersecurity risks and the security measures applicable to the organization. This training (at least 4 hours) must be documented with the date and a certificate of completion.

F2. Regular Employee Awareness Training An awareness training session on cyber risks (phishing, social engineering, passwords) is held at least once a year for all staff. This includes contractors with access to the systems.

F3. Phishing Exercise A simulated phishing exercise is conducted at least once a year to assess employees’ level of vigilance and identify those at risk so they can receive additional training.

G. Management of Third Parties and Contractors (4 points)

G1. Inventory of Critical Subcontractors Service providers who have access to your information systems or OT systems (integrators, maintenance providers, software vendors) are listed along with the criticality level of their access. This inventory is kept up to date.

G2. Contractual Security Provisions Contracts with critical service providers include security provisions: obligation to report incidents, NIS2 compliance for subject entities, right to audit, and confidentiality.

G3. Limited and Logged Subcontractor Access Remote access granted to subcontractors (PLC maintenance access, remote support) is time-limited, logged, and can be revoked immediately. Dedicated VPNs for each service provider are preferable to shared accounts.

G4. Security Assessment of Critical Suppliers Suppliers of critical software or hardware undergo a minimum security assessment (questionnaire, ISO 27001 certifications, audit).

OT Remote Access Management: The NIS2 Blind Spot

Secure remote access to OT systems is often the most critical blind spot for industrial companies. It is also one of the most commonly exploited attack vectors—the ENISA 2025 report on OT incidents cites poorly secured remote access as the primary entry point in 42% of documented incidents.

The Most Common Security Mispractices:

  • Port 3389 (RDP) open directly to the Internet and connected to a SCADA supervisor
  • An "admin" account with the password "password" on a web-accessible HMI
  • Shared operator VPN without network segmentation (the user has access to the entire network)
  • TeamViewer or AnyDesk without MFA, with permanent access

The NIS2-compliant approach:

  1. No incoming ports open to the Internet from the OT network
  2. All remote access goes through a VPN with MFA (OpenVPN + client certificate + TOTP OTP)
  3. VPN access is limited to the subnets necessary for the service provider’s work (segmentation by VLAN)
  4. Each remote access session is logged with a timestamp, user identity, and actions performed
  5. Exceptional access (emergency troubleshooting) is granted temporarily via an approval workflow and automatically revoked after the session

This architecture is accessible to an industrial SME with modern equipment—an Eziwan industrial router with built-in OpenVPN/IPSec VPN and remote access via the Eziwan Cloud platform meets these requirements without requiring complex infrastructure.

Incident Reporting Deadlines (24 hours / 72 hours)

NIS2 imposes strict notification deadlines in the event of a significant security incident, defined as an incident that has or is likely to have a significant impact on service continuity.

Initial Notification (Early Warning) — 24 hours: Report to ANSSI via the dedicated portal if the incident is likely to have a cross-border impact, if it results from a criminal offense, or if it may affect other entities. This notification should be brief: nature of the incident, affected systems, and estimated initial impact.

Interim Notification — 72 hours: A more detailed report including a preliminary assessment of the severity, the probable cause, and the containment measures currently in place.

Final Report — 1 month: Complete description of the incident, identified cause, actual impact, corrective actions taken, and measures to prevent recurrence.

Practical Tip: The time limits begin to run from the moment the company becomes aware of the incident—not from the moment the incident actually began. A ransomware incident discovered 3 weeks after the initial intrusion triggers the timer on the date of discovery, not on the date of the intrusion. Document the timeline of the discovery in detail.

Penalties: up to 10 M€ or 2% of global revenue

NIS2 introduces a system of administrative penalties that is significantly stricter than that of NIS1.

Key Provisions:

  • Fines of up to 10 M€ or 2% of total global annual revenue (whichever is higher)
  • Possible temporary suspension of business operations or executive functions

Significant entities:

  • Fines of up to 7 M€ or 1.4% of total global annual revenue

Criteria for Determining Penalties:

  • Severity and duration of the violation
  • Whether the violation was intentional or negligent
  • Measures taken to mitigate the damage
  • The entity’s compliance history
  • Cooperation with ANSSI

In practice, the first French penalties will likely target large, critical entities before being extended to other significant entities. But the experience with the GDPR shows that enforcement efforts ramp up quickly once the framework is in place.

Liability of Executives: In the event of a serious violation resulting from gross negligence, NIS2 provides that executives may be personally liable. This provision is a significant new development that elevates cybersecurity to the executive committee level.

Official Resources (ANSSI, CERT-FR)

  • ANSSI — NIS2 portal: https://www.cert.ssi.gouv.fr/nis2 — scope self-assessment tool, sector-specific guides, compliance timeline
  • ANSSI — IT Security Best Practices Guide: a set of 42 basic measures, available for free, a good starting point for SMEs
  • CERT-FR: cert-fr.cert.gouv.fr — security bulletins, alerts on critical vulnerabilities, incident reporting (signalement@cert.gouv.fr)
  • ANSSI — Industrial Systems Security Guide: a specific OT/SCADA framework, highly relevant for the manufacturing industry
  • CNIL and NIS2: NIS2 compliance complements the GDPR—technical security measures often satisfy both regulations simultaneously

For small organizations, ANSSI recommends starting with the CyberDC assessment available at cybermalveillance.gouv.fr, and then prioritizing measures based on the results.


FAQ

Is my industrial SME subject to NIS2? If you have between 50 and 249 employees (or annual revenue between €10 million and €50 million) and operate in a sector listed in NIS2 (critical manufacturing, water, energy, healthcare, etc.), you are likely a significant entity (SE). Below these thresholds, you are generally not directly subject to the regulation, but your clients (EEs or SEs) may impose contractual security obligations on you. Use the ANSSI self-assessment tool available at cert.ssi.gouv.fr/nis2 to check.

When are the first NIS2 penalties expected in France? The French implementation has been in effect since October 2024. ANSSI is initially prioritizing the notification of affected entities and providing support for compliance. The first administrative penalties are expected to be imposed starting in 2026, beginning with large critical entities. SMEs will generally be given a grace period before penalties are imposed.

Does NIS2 cover OT/SCADA systems or only management IT systems? NIS2 explicitly applies to OT (Operational Technology), SCADA, ICS, and industrial control systems. ANSSI has published a specific guide titled “Security of Industrial Systems” that describes concrete measures for PLCs, HMIs, SCADA, and OT networks. IT/OT segmentation and securing remote access to PLCs are direct requirements.

Can a single NIS2 incident automatically trigger penalties? No. A reporting requirement is not a penalty. The requirement to report an incident to ANSSI within 24 hours does not automatically result in a penalty—it is a procedural requirement. Penalties are imposed in cases of non-compliance with technical and organizational measures (unsecured access, lack of backups, failure to manage vulnerabilities), or in cases of non-cooperation with ANSSI.

How to Demonstrate NIS2 Compliance to ANSSI? ANSSI may request documentary evidence: security policies approved by management, security logs, audit results, training plans, and a tested business continuity plan. For critical entities, on-site audits are possible. The best way to prepare is to systematically document your measures starting now: implementation date, person in charge, and results.


Further Reading


Want to learn more? Eziwan helps manufacturers secure their OT remote access in accordance with NIS2 requirements: OpenVPN/IPSec VPNs, network segmentation, and no open inbound ports. Check out our guide to OT cybersecurity or contact us for an audit of your remote access.


Additional Resources