Key takeaways
It changes three specific things. First, your software vendors become part of a documented supply chain risk assessment under Article 21(2)(d), so you need evidence about each one on file, not a sales impression. Second, your incident response now runs on a legal clock: an early warning within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, and a final report within one month, which means a vendor has to notify you quickly enough for you to meet those deadlines. Third, management approval under Article 20 makes the evidence auditable, so vendor claims need to be documents.
Practically, that means requiring from each shortlisted vendor: an information security certification with its scope statement, a named hosting region, a sub-processor list, a contractual incident notification window, and recovery objectives in hours. Fabrico's answers are ISO 27001, ISO 9001 and ISO/IEC 20000-1, hosting in an AWS EU region, a GDPR data processing agreement, and a 4 hour recovery time objective with a 4 hour recovery point objective and daily backups.
NIS2 replaced the original 2016 NIS Directive and applies from 18 October 2024, following a transposition deadline of 17 October 2024. Transposition into national law has been uneven across member states, so the version that binds you is your own country's implementing act, not the directive text. Check the national law and confirm with counsel before acting on any summary, including this one.
Scope is set by two things together: the sector and the size of the company.
Annex I, essential entities. Energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space.
Annex II, important entities. This is the annex that matters for most readers of this page. It includes postal and courier services, waste management, the manufacture, production and distribution of chemicals, the production, processing and distribution of food, and a manufacturing block covering medical devices, computer, electronic and optical products, electrical equipment, machinery and equipment, motor vehicles, trailers and semi-trailers, and other transport equipment. Research organisations and several digital providers are also listed.
Size. The general rule is that medium-sized and large enterprises in these sectors are covered. Medium-sized means broadly 50 or more employees or an annual turnover above EUR 10 million. Large entities in Annex I sectors are treated as essential; medium entities in Annex I and both medium and large entities in Annex II are treated as important. Essential and important entities face the same security obligations; what differs is supervision and the penalty ceiling.
The practical consequence is blunt. A single-site machinery manufacturer with 120 people, which has never thought of itself as critical infrastructure, is an important entity under NIS2. A food processor of the same size is too.
Article 21: risk management measures. Entities must take appropriate and proportionate technical, operational and organisational measures. The listed measures include incident handling, business continuity and backup management, supply chain security, security in acquisition and development of network and information systems, policies on cryptography, access control, asset management and the use of multi-factor authentication or continuous authentication where appropriate.
Read that list against a maintenance platform. Backup management, supply chain security, secure acquisition, cryptography and access control all describe things you must be able to say about your CMMS. They are no longer optional questions.
Article 23: reporting. For a significant incident, an early warning goes to the CSIRT or competent authority within 24 hours, an incident notification with an initial assessment within 72 hours, and a final report within one month. You cannot meet a 24 hour clock if your vendor's contract promises notification "without undue delay" and nothing more. Ask for a number of hours and get it into the agreement.
Article 20: governance. Management bodies must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements. Members of management must also follow training. This is the article that changes the tone of vendor conversations, because a plant manager signing off a platform is now signing off something that carries personal exposure.
On penalties, the directive sets maximum administrative fines of at least EUR 10 million or 2 percent of total worldwide annual turnover, whichever is higher, for essential entities, and at least EUR 7 million or 1.4 percent, whichever is higher, for important entities.
Question 1 is the one that is genuinely new. Most software contracts written before 2024 contain no incident notification window at all, and a vendor that will not commit to hours is asking you to carry a legal deadline you have no way to meet.
A common objection at this point is that maintenance software is not a control system, so it cannot matter much. That is half right and the wrong half is the expensive one.
A CMMS holds your asset register, your maintenance history, your supplier and spare part records, and the names and shift patterns of the people who work on your lines. An OEE platform holds real-time production rates and downtime reasons, which describe your capacity and your problems in more detail than any external party should ever see. Both are usually connected to something else: an ERP, an SAP PM instance, sometimes a historian or a PLC network.
That connection is the point. Under Article 21 you are assessing the security of network and information systems and their supply chain. A platform that reads from the PLC layer is inside the assessment whether or not it can write to it, and your risk register needs to say so explicitly. If you are running OEE on machines that were never designed to be networked, the connection method itself becomes part of the answer, which is covered in our guide to OEE monitoring without a PLC.
Fabrico is a combined CMMS and OEE platform, built in the EU and hosted in an AWS EU region. Against the evidence list above: ISO 27001, ISO 9001 and ISO/IEC 20000-1 certification; a GDPR data processing agreement; encryption at rest and in transit; daily backups with a 4 hour recovery time objective and a 4 hour recovery point objective; Cloudflare DDoS protection; role based access control with SSO and SAML available for custom configurations; and an audit log that can be exported.
Data collection covers availability times performance times quality calculated from PLC data, IoT sensors where a PLC is not available, and AI cameras for machines with no usable signal at all. Integration runs through a REST API, webhooks, Excel import and export, and a bidirectional SAP PM sync including S/4HANA, so the connection points are enumerable, which is what a risk assessment needs.
Two honest exclusions, because they will come up in your own gap analysis: Fabrico holds no SOC 2 report, and multi-factor authentication is not currently a standard feature. If your NIS2 gap analysis has flagged multi-factor authentication as a required control, raise it in the first vendor conversation rather than the last.
Take a manufacturer of specialist machinery: two EU plants, 180 employees, turnover around EUR 35 million. It is an important entity under Annex II. It runs a spreadsheet-based maintenance system and is evaluating a CMMS with OEE.
The gap analysis produces four findings that touch this purchase. There is no supply chain register for software vendors, so one must be created and this purchase will be its first entry. There is no incident notification clause in any existing software contract, so a standard clause has to be drafted before signature rather than after. Backup and recovery objectives for production data are undocumented, so the vendor's stated figures become the documented ones. And no one has confirmed which jurisdiction holds the data.
Sequenced properly, none of this delays the project. The four items go out with the first vendor email, the answers land inside a week, and the compliance evidence is assembled while the functional evaluation runs. Sequenced badly, the same four items surface at contract stage and add six to ten weeks, because legal has to negotiate a notification clause with a vendor who has already been told they won.
The lesson generalises past NIS2: the compliance questions are cheap when they are asked in week one and expensive when they are asked in week twelve. The same pattern applies to the vendor security questionnaire and to GDPR and data residency.
Usually not on the size rule alone, but there are exceptions. Member states can designate smaller entities as in scope where they are the sole provider of a critical service, or where disruption would have significant impact. Some national implementations extend scope further than the directive's baseline. Check your national transposition rather than relying on the headcount test alone.
You remain responsible for your own risk management measures, which under Article 21(2)(d) explicitly include the security of your supply chain and your relationships with direct suppliers. That does not make you liable for the vendor's breach as such, but a supervisory authority will ask what you did to assess and manage that supplier. Having the evidence on file is the point of the exercise.
There is no such thing as NIS2 certification for software. NIS2 places obligations on entities, not products, so no vendor can hand you a NIS2 certificate. What a vendor can give you is evidence that supports your obligations: an ISO 27001 certificate with a relevant scope, a data processing agreement, a hosting region, recovery objectives and an incident notification commitment. Treat any vendor advertising itself as NIS2 certified with caution.
They overlap but they are not the same and they have different clocks. GDPR concerns personal data and requires notification of a personal data breach to the supervisory authority within 72 hours. NIS2 concerns the security of network and information systems and requires an early warning within 24 hours and a notification within 72 hours for a significant incident. One event can trigger both, under different laws and to different authorities.
The directive entered into force in January 2023, member states were required to transpose it by 17 October 2024, and it applies from 18 October 2024. In practice several member states missed the transposition deadline, so the date on which specific obligations became enforceable varies by country. Confirm the position for each country you operate in.
This article is general information about a regulatory framework and is not legal advice. Confirm your obligations with qualified counsel and against your national implementing law.
To see how Fabrico's evidence pack lines up against your gap analysis, book a demo, or start with the OEE for manufacturing guide if you are still defining what the platform has to measure.
Last updated: 7 August 2026.