Skip to main content
Qasttor logo
QASTTORTECHNOLOGY CONSULTING & IMPLEMENTATION
NIS2 for manufacturing

Check your NIS2 obligations

Answer a few quick questions about your company to see whether the NIS2 Directive applies to you, which obligations you'll carry, and how ready you are today — built for production and manufacturing companies.

Indicative result based on Directive (EU) 2022/2555 (NIS2). Not legal advice — final scope depends on national transposition (in Poland, the amended Act on the National Cybersecurity System) and your specific circumstances.

1 · Are you in scope?

Tell us about your company. Everything runs in your browser — nothing is submitted.

OT (operational technology) means your factory-floor systems — PLCs, SCADA, machines — as distinct from IT (business systems).

Employees (headcount)
Annual turnover
Do you supply products or services (IT/OT, components or critical services) to companies in these sectors?

NIS2 obligations at a glance

The core duties for in-scope manufacturers, mapped to the NIS2 articles your auditor will cite.

ArticleObligationControl areaWhat an audit checks
Art. 20Management oversightGovernanceBoard-approved strategy; training records for leaders and staff.
Art. 21(2)(a)Risk-management policiesRisk managementDocumented policy and risk register covering IT and OT.
Art. 21(2)(b)Incident handlingIncident responseIR plan, roles and escalation; evidence of exercises.
Art. 21(2)(c)Business continuityContinuity & DRBC / DR plan, backups and a recent restore test.
Art. 21(2)(d)Supply-chain securityVendor managementSupplier register, risk criteria and security clauses.
Art. 21(2)(e)Secure acquisition & developmentSecure SDLC / patchingChange control, patch schedule and vulnerability handling.
Art. 21(2)(f)Effectiveness testingAudit & assuranceAudit reports, scans and penetration-test results.
Art. 21(2)(g)Basic cyber hygiene & trainingTechnical controlsSegmentation, endpoint protection and awareness training.
Art. 21(2)(h)Cryptography & encryptionEncryptionEncryption policy, data at rest / in transit, key management.
Art. 21(2)(i)HR security & access controlAccess & assetsLeast privilege, access reviews and asset inventory.
Art. 21(2)(j)Multi-factor authenticationAuthenticationMFA on remote / admin access; secure communications.
Art. 23Incident reportingNotification24h early warning, 72h notification, 1-month final report.

Indicative guidance based on the NIS2 Directive — not legal advice. Confirm details against your national transposition.

NIS2 for manufacturers — FAQ

Turn your NIS2 result into a plan

Book a free consultation. We'll walk through your scope, prioritise the gaps this tool surfaced, and map a realistic path to compliance across your IT and OT.