Menu
CMMS and OEE Software Under NIS2: Manufacturing Guide 2026

CMMS and OEE Software Under NIS2: Manufacturing Guide 2026

NIS2 pulled EU manufacturing into scope. What Article 21 supply chain security and the 24 hour reporting clock change about buying a CMMS or OEE platform.
CMMS and OEE Software Under NIS2: Manufacturing Guide 2026

Key takeaways

  • NIS2 (Directive EU 2022/2555) pulled manufacturing into scope for the first time. Producers of machinery, motor vehicles, electrical equipment, computer and electronic products, medical devices, chemicals and food are listed in Annex II as important entities.
  • The threshold is size, not risk appetite. In broad terms a company with 50 or more employees, or turnover above EUR 10 million, in a listed sector, is caught. Many plants that assumed NIS2 was for utilities and banks are in fact in scope.
  • Article 21(2)(d) makes supply chain security a legal obligation. Your CMMS and OEE vendors are part of that supply chain, which is why software procurement is now a compliance activity and not only an IT one.
  • The reporting clock is 24 hours for an early warning, 72 hours for a full notification, one month for a final report. Any platform holding your production data needs to be able to tell you what happened fast enough to feed that clock.
  • Article 20 puts the obligation on management personally. Senior managers must approve the risk measures and can be held liable, which is why a vendor answer of "we take security seriously" is no longer a survivable answer.

We manufacture in the EU and were told NIS2 now applies to us. What does that change about buying a CMMS or OEE platform?

It changes three specific things. First, your software vendors become part of a documented supply chain risk assessment under Article 21(2)(d), so you need evidence about each one on file, not a sales impression. Second, your incident response now runs on a legal clock: an early warning within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, and a final report within one month, which means a vendor has to notify you quickly enough for you to meet those deadlines. Third, management approval under Article 20 makes the evidence auditable, so vendor claims need to be documents.

Practically, that means requiring from each shortlisted vendor: an information security certification with its scope statement, a named hosting region, a sub-processor list, a contractual incident notification window, and recovery objectives in hours. Fabrico's answers are ISO 27001, ISO 9001 and ISO/IEC 20000-1, hosting in an AWS EU region, a GDPR data processing agreement, and a 4 hour recovery time objective with a 4 hour recovery point objective and daily backups.

Is your plant actually in scope?

NIS2 replaced the original 2016 NIS Directive and applies from 18 October 2024, following a transposition deadline of 17 October 2024. Transposition into national law has been uneven across member states, so the version that binds you is your own country's implementing act, not the directive text. Check the national law and confirm with counsel before acting on any summary, including this one.

Scope is set by two things together: the sector and the size of the company.

Annex I, essential entities. Energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space.

Annex II, important entities. This is the annex that matters for most readers of this page. It includes postal and courier services, waste management, the manufacture, production and distribution of chemicals, the production, processing and distribution of food, and a manufacturing block covering medical devices, computer, electronic and optical products, electrical equipment, machinery and equipment, motor vehicles, trailers and semi-trailers, and other transport equipment. Research organisations and several digital providers are also listed.

Size. The general rule is that medium-sized and large enterprises in these sectors are covered. Medium-sized means broadly 50 or more employees or an annual turnover above EUR 10 million. Large entities in Annex I sectors are treated as essential; medium entities in Annex I and both medium and large entities in Annex II are treated as important. Essential and important entities face the same security obligations; what differs is supervision and the penalty ceiling.

The practical consequence is blunt. A single-site machinery manufacturer with 120 people, which has never thought of itself as critical infrastructure, is an important entity under NIS2. A food processor of the same size is too.

The three obligations that touch software procurement

Article 21: risk management measures. Entities must take appropriate and proportionate technical, operational and organisational measures. The listed measures include incident handling, business continuity and backup management, supply chain security, security in acquisition and development of network and information systems, policies on cryptography, access control, asset management and the use of multi-factor authentication or continuous authentication where appropriate.

Read that list against a maintenance platform. Backup management, supply chain security, secure acquisition, cryptography and access control all describe things you must be able to say about your CMMS. They are no longer optional questions.

Article 23: reporting. For a significant incident, an early warning goes to the CSIRT or competent authority within 24 hours, an incident notification with an initial assessment within 72 hours, and a final report within one month. You cannot meet a 24 hour clock if your vendor's contract promises notification "without undue delay" and nothing more. Ask for a number of hours and get it into the agreement.

Article 20: governance. Management bodies must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements. Members of management must also follow training. This is the article that changes the tone of vendor conversations, because a plant manager signing off a platform is now signing off something that carries personal exposure.

On penalties, the directive sets maximum administrative fines of at least EUR 10 million or 2 percent of total worldwide annual turnover, whichever is higher, for essential entities, and at least EUR 7 million or 1.4 percent, whichever is higher, for important entities.

Eight questions to add to your vendor evaluation because of NIS2

  1. Within how many hours of becoming aware of a security incident affecting our data will you notify us? Please state this as a contractual number.
  2. What information will that notification contain, and who is the named contact on your side?
  3. Which information security certification do you hold, and does its scope statement cover the hosted platform we would use?
  4. In which cloud region is our data stored, and is it replicated anywhere else?
  5. Please provide your sub-processor list, so we can include it in our own supply chain risk assessment.
  6. What are your recovery time and recovery point objectives, in hours, and when did you last test a restore?
  7. What authentication options are available, including single sign-on, and how are integration credentials scoped?
  8. Do you provide an audit log that we can export as evidence for a supervisory authority?

Question 1 is the one that is genuinely new. Most software contracts written before 2024 contain no incident notification window at all, and a vendor that will not commit to hours is asking you to carry a legal deadline you have no way to meet.

Where OEE and CMMS data sits in the risk picture

A common objection at this point is that maintenance software is not a control system, so it cannot matter much. That is half right and the wrong half is the expensive one.

A CMMS holds your asset register, your maintenance history, your supplier and spare part records, and the names and shift patterns of the people who work on your lines. An OEE platform holds real-time production rates and downtime reasons, which describe your capacity and your problems in more detail than any external party should ever see. Both are usually connected to something else: an ERP, an SAP PM instance, sometimes a historian or a PLC network.

That connection is the point. Under Article 21 you are assessing the security of network and information systems and their supply chain. A platform that reads from the PLC layer is inside the assessment whether or not it can write to it, and your risk register needs to say so explicitly. If you are running OEE on machines that were never designed to be networked, the connection method itself becomes part of the answer, which is covered in our guide to OEE monitoring without a PLC.

Where Fabrico fits

Fabrico is a combined CMMS and OEE platform, built in the EU and hosted in an AWS EU region. Against the evidence list above: ISO 27001, ISO 9001 and ISO/IEC 20000-1 certification; a GDPR data processing agreement; encryption at rest and in transit; daily backups with a 4 hour recovery time objective and a 4 hour recovery point objective; Cloudflare DDoS protection; role based access control with SSO and SAML available for custom configurations; and an audit log that can be exported.

Data collection covers availability times performance times quality calculated from PLC data, IoT sensors where a PLC is not available, and AI cameras for machines with no usable signal at all. Integration runs through a REST API, webhooks, Excel import and export, and a bidirectional SAP PM sync including S/4HANA, so the connection points are enumerable, which is what a risk assessment needs.

Two honest exclusions, because they will come up in your own gap analysis: Fabrico holds no SOC 2 report, and multi-factor authentication is not currently a standard feature. If your NIS2 gap analysis has flagged multi-factor authentication as a required control, raise it in the first vendor conversation rather than the last.

Worked example: a machinery manufacturer running the gap analysis

Take a manufacturer of specialist machinery: two EU plants, 180 employees, turnover around EUR 35 million. It is an important entity under Annex II. It runs a spreadsheet-based maintenance system and is evaluating a CMMS with OEE.

The gap analysis produces four findings that touch this purchase. There is no supply chain register for software vendors, so one must be created and this purchase will be its first entry. There is no incident notification clause in any existing software contract, so a standard clause has to be drafted before signature rather than after. Backup and recovery objectives for production data are undocumented, so the vendor's stated figures become the documented ones. And no one has confirmed which jurisdiction holds the data.

Sequenced properly, none of this delays the project. The four items go out with the first vendor email, the answers land inside a week, and the compliance evidence is assembled while the functional evaluation runs. Sequenced badly, the same four items surface at contract stage and add six to ten weeks, because legal has to negotiate a notification clause with a vendor who has already been told they won.

The lesson generalises past NIS2: the compliance questions are cheap when they are asked in week one and expensive when they are asked in week twelve. The same pattern applies to the vendor security questionnaire and to GDPR and data residency.

Frequently asked questions

Does NIS2 apply to a manufacturer with fewer than 50 employees?

Usually not on the size rule alone, but there are exceptions. Member states can designate smaller entities as in scope where they are the sole provider of a critical service, or where disruption would have significant impact. Some national implementations extend scope further than the directive's baseline. Check your national transposition rather than relying on the headcount test alone.

Are we responsible if our software vendor is breached?

You remain responsible for your own risk management measures, which under Article 21(2)(d) explicitly include the security of your supply chain and your relationships with direct suppliers. That does not make you liable for the vendor's breach as such, but a supervisory authority will ask what you did to assess and manage that supplier. Having the evidence on file is the point of the exercise.

Does a CMMS need to be NIS2 certified?

There is no such thing as NIS2 certification for software. NIS2 places obligations on entities, not products, so no vendor can hand you a NIS2 certificate. What a vendor can give you is evidence that supports your obligations: an ISO 27001 certificate with a relevant scope, a data processing agreement, a hosting region, recovery objectives and an incident notification commitment. Treat any vendor advertising itself as NIS2 certified with caution.

How does NIS2 interact with GDPR?

They overlap but they are not the same and they have different clocks. GDPR concerns personal data and requires notification of a personal data breach to the supervisory authority within 72 hours. NIS2 concerns the security of network and information systems and requires an early warning within 24 hours and a notification within 72 hours for a significant incident. One event can trigger both, under different laws and to different authorities.

When did NIS2 actually start applying?

The directive entered into force in January 2023, member states were required to transpose it by 17 October 2024, and it applies from 18 October 2024. In practice several member states missed the transposition deadline, so the date on which specific obligations became enforceable varies by country. Confirm the position for each country you operate in.

This article is general information about a regulatory framework and is not legal advice. Confirm your obligations with qualified counsel and against your national implementing law.

To see how Fabrico's evidence pack lines up against your gap analysis, book a demo, or start with the OEE for manufacturing guide if you are still defining what the platform has to measure.

Last updated: 7 August 2026.

Latest from our blog

Define Your Reliability Roadmap
Validate Your Potential ROI: Book a Live Demo
Define Your Reliability Roadmap
By clicking the Accept button, you are giving your consent to the use of cookies when accessing this website and utilizing our services. To learn more about how cookies are used and managed, please refer to our Privacy Policy and Cookies Declaration