Regulation & Network Architecture

Status: May 2026

NIS2 in Production Networks: What Needs to Be Done Now

NIS2 is no longer a distant prospect. The implementation act has been in force since December 2025 with no transition period, and the BSI registration deadline has already passed. For many manufacturing businesses, the question has therefore shifted from "Are we affected?" to "Would our OT network architecture actually withstand an audit?" And it is precisely there, in long-grown production environments, that the biggest gap lies.

By Jens Thies · IT by PASSION

The legal status in one paragraph (without guarantee)

The NIS2 Implementation Act (NIS2UmsuCG) has been in force since 6 December 2025 and fundamentally reforms the BSI Act. There is no grace period for the technical and organisational measures — anyone affected must meet the requirements from day one. Around 29,500 organisations fall under its scope, generally from 50 employees or €10 million in turnover upwards. This includes, among others, manufacturing and mechanical engineering, food production, pharmaceuticals, energy, water and logistics. The registration obligation with the BSI expired on 6 March 2026. Anyone who missed it is in default but remains obliged to comply. For critical infrastructure, the KRITIS Umbrella Act has also applied since 17 March 2026, with requirements for physical resilience. Violations can result in fines of up to €10 million or 2 per cent of global annual turnover, and management is held personally liable.

Why NIS2 weighs more heavily on OT networks than on office IT

In classic office IT, the required measures (patching, segmentation, access control, logging) have been routine for years. In production, reality looks different. Controllers run untouched for years because any intervention risks stopping the line. Plant equipment speaks protocols that were never designed for a hostile environment. And over time, a flat network has often emerged in which manufacturing, the control room and the office world are barely separated technically.

This collides directly with the core of Section 30 BSIG: the state of the art in risk management. NIS2 does not abstractly demand "more security", but demonstrably effective measures — and in a flat production network, effectiveness simply cannot be proven. The lever for change therefore lies less in purchasing new products than in network architecture.

Section 30 translated into network architecture

The statutory risk management requirements can be broken down for OT into four architectural cornerstones:

1. Segmentation and zoning

Separating IT and OT is the foundation. A proven organising model for this is the Purdue reference model combined with the zone-and-conduit concept from IEC 62443. Plant equipment is grouped into zones according to protection needs, and every connection between two zones (a conduit) is deliberately defined, controlled and monitored. What matters is that segmentation is technically justified and does not stop wherever laying another cable became inconvenient. And a link is only a conduit if traffic on the connection is strictly filtered.

2. Controlled transitions instead of a single "perimeter" firewall

A single firewall between office and production does not serve the purpose. Once an attacker overcomes this one boundary, the entire production network lies open to them. The architecture only becomes effective once the transitions between zones are each individually secured and traffic follows the principle of least privilege: only what is demonstrably necessary for operations is permitted.

3. Remote maintenance as a risk topic in its own right

Remote access provided by machine and plant suppliers is, in practice, the most common uncontrolled entry point. Permanently open VPN tunnels or vendor-specific maintenance access that no one keeps track of anymore directly contradict NIS2 risk management. Modern approaches replace blanket network access with identity-based access to exactly one system, time-limited and fully logged — the principle behind Zero Trust access. Furthermore, the principle of "safety before security" still applies in OT. On-site, there should therefore be an additional control instance to ensure that health and human life, as well as the product itself, are not endangered while someone is carrying out remote maintenance.

4. Visibility and logging

The tightened reporting obligations under Section 32 — an initial report within 24 hours, a follow-up report within 72 hours and a final report within one month — can only be met if you can actually see what is happening on the network. Anyone who cannot make OT traffic visible can neither report an incident on time nor contain it. Passive monitoring of production zones is therefore no longer optional, but a prerequisite for being able to report at all.

The typical gaps in long-grown networks

In project practice, certain patterns keep recurring: a historically flat network with no genuine IT/OT separation; remote maintenance access whose number and scope no one fully knows; identical default passwords used across plant equipment; and documentation that has not reflected the actual state of the network for years. None of these gaps is spectacular on its own. Together, however, they render a production network incapable of withstanding an audit under NIS2.

First steps, without stopping production

Every plant has a legitimate concern: security versus availability. The two can be reconciled if you proceed step by step and measurably, rather than attempting one big overhaul. A pragmatic starting point:

  1. Take stock instead of relying on gut feeling. First make the actual state of the network and all zone transitions visible. Important: including all remote maintenance access. Without a reliable picture, any measure is just guesswork.
  2. Define the target architecture. Design a target segmentation based on protection needs, to which all further steps are aligned, audit-ready and documented.
  3. Secure remote maintenance first. The greatest risk with the best cost-benefit ratio. Replace uncontrolled access with controlled, logged access.
  4. Introduce zones during ongoing operations. Segment by segment, starting with the highest-risk transitions, each with a fallback option.
  5. Establish monitoring and a reporting process. Create visibility and rehearse the 24-then-72-hour reporting chain organisationally, before a real incident forces you to.

Why this is a matter for top management

NIS2 explicitly holds management accountable. It must approve risk measures, oversee their implementation and undergo training. It is personally liable for violations. This means OT network architecture is no longer a purely technical question, but a matter of corporate leadership. The good news: a cleanly segmented, documented architecture not only satisfies the requirement, it also increases the availability and stability of production. Compliance and operational safety pull in the same direction here.

Note

This article reflects the author's personal professional assessment at the time of publication. It does not replace individual consultation. Details regarding standards, deadlines, versions and manufacturer functions should be verified before making any decisions. All content is provided without guarantee.