Check your NIS2 obligations
Answer a few quick questions about your company to see whether the NIS2 Directive applies to you, which obligations you'll carry, and how ready you are today — built for production and manufacturing companies.
Indicative result based on Directive (EU) 2022/2555 (NIS2). Not legal advice — final scope depends on national transposition (in Poland, the amended Act on the National Cybersecurity System) and your specific circumstances.
1 · Are you in scope?
Tell us about your company. Everything runs in your browser — nothing is submitted.
OT (operational technology) means your factory-floor systems — PLCs, SCADA, machines — as distinct from IT (business systems).
NIS2 obligations at a glance
The core duties for in-scope manufacturers, mapped to the NIS2 articles your auditor will cite.
| Article | Obligation | Control area | What an audit checks |
|---|---|---|---|
| Art. 20 | Management oversight | Governance | Board-approved strategy; training records for leaders and staff. |
| Art. 21(2)(a) | Risk-management policies | Risk management | Documented policy and risk register covering IT and OT. |
| Art. 21(2)(b) | Incident handling | Incident response | IR plan, roles and escalation; evidence of exercises. |
| Art. 21(2)(c) | Business continuity | Continuity & DR | BC / DR plan, backups and a recent restore test. |
| Art. 21(2)(d) | Supply-chain security | Vendor management | Supplier register, risk criteria and security clauses. |
| Art. 21(2)(e) | Secure acquisition & development | Secure SDLC / patching | Change control, patch schedule and vulnerability handling. |
| Art. 21(2)(f) | Effectiveness testing | Audit & assurance | Audit reports, scans and penetration-test results. |
| Art. 21(2)(g) | Basic cyber hygiene & training | Technical controls | Segmentation, endpoint protection and awareness training. |
| Art. 21(2)(h) | Cryptography & encryption | Encryption | Encryption policy, data at rest / in transit, key management. |
| Art. 21(2)(i) | HR security & access control | Access & assets | Least privilege, access reviews and asset inventory. |
| Art. 21(2)(j) | Multi-factor authentication | Authentication | MFA on remote / admin access; secure communications. |
| Art. 23 | Incident reporting | Notification | 24h early warning, 72h notification, 1-month final report. |
Indicative guidance based on the NIS2 Directive — not legal advice. Confirm details against your national transposition.
NIS2 for manufacturers — FAQ
Turn your NIS2 result into a plan
Book a free consultation. We'll walk through your scope, prioritise the gaps this tool surfaced, and map a realistic path to compliance across your IT and OT.