Technical Guide

NIS2 Compliance for Industry — Specific Requirements and Technical Solutions

Understand NIS2 requirements for the industry: IT/OT segmentation, secure remote access, logs, business continuity and disaster recovery plans.

The NIS2 Directive strengthens cybersecurity requirements for many industrial organizations: manufacturing, energy, transportation, water, healthcare, chemicals, agri-food, critical manufacturing, digital suppliers, and essential service providers. For OT environments, compliance is not limited to a written policy; it requires verifiable technical measures, such as network segmentation, remote access control, logging, vulnerability management, and business continuity.

The Problem

NIS2 broadens the scope of affected organizations and requires a more structured approach to cyber risk. In the industrial sector, the challenge often stems from the gap between compliance requirements and the reality of OT systems: legacy controllers, flat networks, access for long-standing service providers, limited logging of monitoring data, vendor dependencies, and production outages that are difficult to tolerate.

The most common non-compliance issues are specific.

  • The supply chain falls within the scope of NIS2: software vendors, cloud service providers, system integrators, maintenance providers, and equipment manufacturers must be assessed.

  • Business continuity and disaster recovery plans, often referred to as BCP/DRP, must be formalized, maintained, and tested regularly.

  • Security audits and technical tests must be scheduled based on the level of risk. For certain regulatory audits in France, the use of qualified service providers may be required under the applicable framework.

  • The lack of an inventory of connected OT assets is a major weakness: you can’t protect, segment, or monitor what you don’t know about.

  • Remote access to PLCs, HMIs, monitoring servers, or specialized machines is often too broad, shared, or inadequately tracked.

  • Access logs are incomplete, scattered, or retained for too short a period to facilitate an investigation.

NIS2 does not simply require organizations to “practice cybersecurity.” It requires them to demonstrate that risks have been identified, that appropriate measures are in place, and that incidents can be detected, addressed, and reported within the specified timeframes.

How NIS2 Affects Industrial Sites

The NIS2 Directive replaces and expands upon the original NIS framework. It covers more sectors, distinguishes between essential and important entities, and strengthens management’s accountability. The exact details depend on national implementation and the sector of activity; in France, ANSSI remains the authority to consult for applicable texts, guidelines, and requirements.

For an industrial site, the impact generally translates into four operational requirements.

RequirementSpecific implementation in OTExpected evidence
Risk GovernanceIdentify assets, risks, responsibilities, and measuresMapping, risk analysis, procedures
Technical ProtectionSegment, filter, encrypt, authenticateNetwork rules, MFA, VPN, hardening
Detection and TraceabilityLog access and critical eventsTimestamped logs, alerts, reports
ResilienceMaintain operations and restore systemsBCP/DRP, backups, recovery tests

The key point is verifiability. A metric that is undocumented, untested, or unmonitored will be difficult to defend during an audit, even if it technically exists.

Obligations and Technical Measures to Prioritize

NIS2 outlines cybersecurity and risk management objectives. For industrial environments, these objectives must be translated into technical measures tailored to production constraints.

OT Asset Inventory

The inventory is the foundation of any industrial NIS2 program. It must cover both visible equipment and equipment that is often overlooked.

  • PLCs from Siemens, Schneider, Rockwell, Wago, Omron, or other manufacturers.

  • HMI, operator consoles, and industrial panels.

  • SCADA servers, engineering workstations, and data archives.

  • Drives, robots, smart sensors, gateways, and IIoT devices.

  • Industrial switches, routers, firewalls, modems, and gateways.

  • Remote access, vendor accounts, and existing VPN tunnels.

A useful inventory is not limited to the name of the equipment. It must include the IP address, network zone, owner, criticality, protocols used, vendor, software version (when known), and production dependencies.

IT/OT Network Segmentation

IT/OT segmentation limits attack vectors between the information system and the industrial network. It prevents an IT incident from spreading directly to PLCs or supervisory servers.

Segmentation must be clear and usable. A single VLAN for the entire plant is generally not sufficient when multiple production lines, critical areas, or service providers need to be isolated.

Secure Remote Access

Remote access is one of the most sensitive issues in an OT environment. It is necessary for maintenance, but it can become a major vulnerability if it is permanent, shared, or exposed.

An approach that complies with NIS2 best practices must include:

  • Personal accounts for each user.

  • Multi-factor authentication.

  • An encrypted VPN tunnel, with no direct exposure of RDP, VNC, SSH, or PLC interfaces to the Internet.

  • Fees based on resources, sites, lines, or equipment.

  • A time-limited opening.

  • A site-side validation or notification.

  • Comprehensive session logging.

An Eziwan gateway can serve as a control point between remote technicians and OT resources. It replaces scattered access points with a centralized, filtered, and traceable access point.

Logging and Access Logs

NIS2 requires organizations to detect incidents and provide factual evidence for analysis. Logs are therefore essential, but they must be actionable.

An OT access log must specify:

  • Who has logged in.

  • When the session began and when it ended.

  • When the connection was first established.

  • Which OT resource was accessed.

  • Which profile or access rule was used.

  • Which attempts were rejected?

  • Who approved or received the notification, if the process requires it.

The logs can then be sent to a monitoring system, a SIEM, or a centralized service in the Eziwan cloud, depending on the chosen architecture.

Vulnerability Management

Vulnerability management in industrial automation cannot be blindly modeled after IT. A PLC, HMI, or SCADA server does not always update in the same way as a desktop computer. Some equipment is certified for a specific version, and applying a patch may require a production shutdown.

Best practice is to establish a realistic process.

StepObjectiveOT Specifics
IdentifyDetermine which versions and equipment are at riskA reliable inventory is essential
AssessEvaluate the actual impact on the siteProduction and security criticality
PrioritizeAddress exploitable risks firstNetwork exposure, remote access, privileges
MitigateReduce risk if patching is not possibleSegmentation, filtering, deactivation
VerifyConfirm that the mitigation measure is workingTesting during maintenance windows

In some cases, the best immediate response is not a patch, but a workaround: removing direct access, filtering traffic, isolating an area, or restricting a vendor account.

Supplier and Supply Chain Management

The supply chain is a key focus of NIS2. Industrial companies depend on machine manufacturers, system integrators, SCADA software vendors, hosting providers, telecom operators, maintenance providers, and cloud providers. Each of these dependencies can create a risk.

The supplier evaluation must cover at least the following:

  • Remote access requested by the provider.

  • The accounts used and their registered status.

  • Procedures for termination at the end of a contract.

  • Notification requirements in the event of an incident.

  • Practices for updating and managing vulnerabilities.

  • The available safety evidence, without inventing a certification when one does not exist.

  • The location and protection of hosted data or logs.

It is better to centralize provider access through a controlled platform rather than letting each provider install its own modem, router, or remote service.

PCA/PRA and Industrial Resilience

NIS2 emphasizes business continuity and recovery capabilities. For the industry, this means more than just restoring files: it involves restarting production, restoring PLC settings, reestablishing monitoring systems, and ensuring the safety of personnel and facilities.

An industrial PCA/PRA must take the following into account:

  • Scenarios involving the loss of the IT network, the OT network, or the Internet connection.

  • Backups of PLC programs, HMI configurations, recipes, SCADA servers, and network configurations.

  • Dependencies between applications, directories, licenses, engineering workstations, and production equipment.

  • Procedures for returning to manual or degraded mode.

  • Acceptable rework lead times by line or process.

  • Regular restore tests—not just having backups.

Testing is essential. A backup that hasn’t been restored in years is not solid proof of resilience.

Incident Detection, Notification, and Management

NIS2 compliance also requires detecting and responding to incidents. Reporting deadlines depend on the transposition rules and the severity of the incident; therefore, organizations must follow the guidelines published by the relevant national authority.

From a technical standpoint, the organization must be able to quickly answer a few simple questions.

  • Which remote access connections were active at the time of the incident?

  • Which account accessed which OT resource?

  • Was a service provider logged in?

  • Were there any failed attempts prior to the incident?

  • What equipment is in the affected area?

  • Is it possible to cut off access without halting all production?

  • Are the backups needed for recovery available?

The value of a solution like Eziwan lies in providing monitoring and control capabilities for industrial access: notifications, logs, revocation, segmentation, and centralized rule management.

Example of a NIS2 Compliance Path

Effective compliance is achieved in stages. The goal is not to overhaul everything at once, but to gradually reduce the most significant risks.

This process quickly yields visible results: elimination of uncontrolled access, personalized accounts, improved traceability, and a reduction in attack vectors.

How Eziwan Meets NIS2 Requirements

Eziwan is not a substitute for a legal analysis, a regulatory audit, or comprehensive cybersecurity governance. However, the solution addresses several specific technical needs encountered in industrial NIS2 projects.

NIS2 RequirementEziwan Technical SolutionOperational Benefit
Remote Access ControlEncrypted VPN, MFA, named accountsReduction in shared and exposed access
IT/OT SegmentationGateway positioned between zonesAccess limited to necessary resources
TraceabilityTime-stamped session logsEvidence for audits and incident analysis
Vendor ManagementPermissions by service provider and scopeBetter control of the supply chain
RevocationRapid deactivation of accounts or rulesReduced risk at the end of the contract
MonitoringNotifications and centralizationVisibility into active connections
ResilienceControlled and documentable architectureLess dependence on scattered access points

This approach complements the pages dedicated to industrial connectivity, the secure cloud, and the Eziwan gateway.

Technical Checklist for an Industrial Site

This checklist provides a framework for assessing a website’s maturity in relation to NIS2 requirements. It is not a substitute for an audit, but it helps with prioritization.

AreaQuestionPriority
InventoryAre connected OT assets inventoried?High
Remote AccessAre all service provider access points known?High
IdentityAre accounts assigned to specific users?High
MFAIs strong authentication enabled?High
SegmentationAre IT/OT traffic flows filtered?High
LogsAre remote connections logged?High
VendorsIs vendor access reviewed regularly?Medium
VulnerabilitiesAre patches and mitigations tracked?High
Disaster RecoveryAre recovery procedures tested?High
IncidentAre alert roles and procedures well-known?High

Remote access is often the best place to start, as it brings together identity, segmentation, encryption, vendors, and logs within a scope that can be quickly monitored.

Common Pitfalls in Industrial NIS2 Projects

Several mistakes slow down or undermine compliance efforts.

Reducing NIS2 to a Documentary File

Documentation is essential, but it must reflect actual measures. A remote access policy is not enough if sites continue to use unaccounted-for modems or shared accounts.

Copying IT Methods Without Adapting Them to OT

The OT imposes requirements regarding availability, safety, equipment qualifications, and maintenance cycles. The measures must be tailored, tested, and validated in collaboration with the production teams.

Forget About Service Providers

System integrators, machine manufacturers, and maintenance personnel often have the most sensitive access privileges. Their access must be managed as part of the NIS2 program, using named accounts, time-limited access, and regular reviews.

Confusing VPNs with Security

A VPN encrypts a tunnel, but on its own, it does not guarantee any level of access control, traceability, segmentation, or revocation. Security comes from the combination of all these elements: identity, rules, logs, monitoring, and procedures.

Sources and Useful References

To stay up to date on changes to the regulatory framework and best practices, it is recommended that you consult official sources and recognized standards.

These references must be supplemented by the applicable national laws and regulations and by the sector-specific requirements of each organization.

Conclusion

NIS2 compliance for the industry hinges on operational details: an accurate inventory of OT assets, controlled remote access, IT/OT segmentation, role-based accounts, actionable logs, vendor management, tracked vulnerabilities, and tested business continuity. It is this concrete evidence that enables organizations to move from merely intending to be secure to having a defensible security posture.

Eziwan provides a targeted technical solution for one of the most critical issues: secure industrial connectivity. By centralizing remote access through a gateway, filtering traffic, logging sessions, and providing visibility to on-site teams, the solution helps manufacturers reduce their exposure and establish a critical component of their NIS2 compliance strategy.

Further Reading

Frequently Asked Questions

You might also like