The implementation of the NIS2 directive is the most important regulatory challenge for the Polish industry in years. It is no longer a question of “if,” but “how and when” to meet the new stringent requirements. For many managers, the enormity of the tasks - from risk analysis to network segmentation to business continuity plans - seems overwhelming. Where to start? What’s most important? How to fit all these investments into a tight budget? Trying to do everything at once is the easiest path to failure.
Successful implementation of NIS2 requires a strategic, phased approach. It is necessary to treat the process not as a single, gigantic project, but as a program composed of logically ordered, smaller initiatives, staggered over time. Such a prioritized roadmap allows for evolutionary, rather than revolutionary, maturity building. It allows time to acquire the necessary knowledge, spread investments over successive budget cycles and gradually adapt the organization to the new reality.
In this article, we will propose such a roadmap for the next two years. It’s a practical guide that will help bring order to chaos, define priorities, and transform overwhelming legal obligations into a manageable and realistic roadmap. It’s a strategy to achieve compliance without paralysis and unnecessary stress.
Shortcuts
- Which Polish factories and manufacturing companies must implement the NIS2 directive?
- What are the real financial penalties and consequences for management for non-compliance with NIS2?
- How to conduct a risk audit, which is the first and most important requirement of NIS2, in 30 days?
- What new OT incident reporting obligations does the directive impose on the industry?
- Does having ISO 27001 certification make it easier to implement NIS2 in a production environment?
- How do you prepare documentation for an OT environment to be ready for a regulator’s inspection?
- What SIEM tools support the monitoring and reporting processes required by NIS2?
- How should employees and management be trained in accordance with the new requirements?
- Priority Roadmap for implementation of NIS2 in industry (2025-2026)
- What does the NIS2 priority implementation roadmap for 2025-2026 look like?
- How much can a minimum NIS2 compliance program realistically cost for a medium-sized manufacturing company?
- Does NIS2 require encryption of OT backups and other specific technical controls?
- What to pay special attention to when choosing a partner to implement NIS2 requirements?
- How to turn the NIS2 compliance obligation into a strategic modernization opportunity?
- How can nFlo guide your company through the entire NIS2 compliance process - from audit to implementation?
Which Polish factories and manufacturing companies must implement the NIS2 directive?
The first step is to make sure your company falls under the new regulations. The NIS2 directive significantly expands the catalog of sectors considered critical or important. In the context of industry, the obligations will primarily cover companies operating in industries such as the production and distribution of chemicals, food production and processing, the manufacture of medical and medical devices, the manufacture of computers and electronic products, the manufacture of machinery and equipment, the manufacture of motor vehicles and the manufacture of other transportation equipment. As a rule, the directive will cover medium-sized (more than 50 employees and €10 million turnover) and large entities. Even if your company is smaller, it may be regulated if it is considered critical to the supply chain or national security.
📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać
What are the real financial penalties and consequences for management for non-compliance with NIS2?
Ignoring NIS2 requirements comes with very serious consequences. The directive introduces some of the highest penalties in the history of EU regulation, rivalling those known under RODO. For key entities, the penalty can be up to €10 million or 2% of total annual global turnover. For important entities, up to €7 million or 1.4% of turnover. These are amounts that can shake the financial stability of any company. Equally severe is the personal liability of board members, introduced for the first time. The regulator can impose severe fines on managers directly responsible for negligence, and even temporarily ban them from acting as managers. It’s a risk that moves the discussion of NIS2 from the server room straight to the CEO’s office.
How to conduct a risk audit, which is the first and most important requirement of NIS2, in 30 days?
The NIS2 directive is entirely based on a risk-based approach. This means that the first, absolutely fundamental step to compliance is to conduct and document a comprehensive risk assessment for the OT environment. It is this that provides the starting point for all further activities and investments. Contrary to appearances, such a process does not have to take many months. An experienced partner, using a structured methodology, can conduct such an audit in about 30 days. The process includes workshops with key personnel, passive infrastructure mapping, identification of key processes and assets, followed by an assessment of risks and potential consequences. The result is a prioritized risk map that becomes the foundation of the entire implementation strategy.
What new OT incident reporting obligations does the directive impose on the industry?
NIS2 unifies and tightens incident reporting obligations across the Union. Any “major” incident, i.e. one that causes significant service disruption or financial loss, must be reported to the national CSIRT team. The process is a multi-step one with very short deadlines. A company must send ** an “early warning” within 24 hours** of discovering an incident, followed by a detailed notification within 72 hours. Meeting these requirements is impossible without having ready-made, practiced procedures for crisis response and communication. This is another area that should be addressed first.
Does having ISO 27001 certification make it easier to implement NIS2 in a production environment?
Yes, having an ISO 27001-compliant Information Security Management System (ISMS) implemented and certified is a huge benefit and gives your company a significant advantage. Many of the organizational and process requirements of NIS2 - such as the need for policies, risk analysis and incident management - overlap with those of ISO 27001. By having this certified, you already have a solid foundation. Keep in mind, however, that NIS2 goes further in many places, especially in the areas of network and OT information system security and supply chain security. It will therefore be necessary to conduct a gap analysis and expand your existing system to include those specific, technical requirements that ISO 27001 does not specify as much.
How do you prepare documentation for an OT environment to be ready for a regulator’s inspection?
In the world of regulation, the rule is simple: “if something is not documented, it does not exist.” Preparing for an audit is all about making sure your documentation is complete and up-to-date. Auditors will want to see not only the technologies implemented, but more importantly, evidence of a mature management system. Key documents that should be prepared include a formal security policy for the OT, the results of a risk analysis, a risk register, Incident Response Plans (IRPs) and Business Continuity Plans (BCPs), change and vulnerability management procedures, as well as reports on training and exercises conducted. It is important that this documentation is “live” - regularly reviewed, updated and, most importantly, known and used by employees.
What SIEM tools support the monitoring and reporting processes required by NIS2?
Effective detection and reporting of incidents within the timeframe required by NIS2 is impossible without technology support. Security Information and Event Management (SIEM) systems, which centrally collect and correlate logs from across the infrastructure, play a key role. Modern SIEM systems, equipped with modules for behavioral analysis (UEBA) and mechanisms for orchestration and automation (SOAR), make it possible to quickly detect complex attack patterns and partially automate the response. When selecting a tool for an OT environment, it is crucial to make sure it can integrate with specific data sources from the industrial network and “understand” its protocols.
How should employees and management be trained in accordance with the new requirements?
NIS2 explicitly requires regular cybersecurity training. This must include two key groups. The first is all employees, who must receive security awareness training that teaches them to recognize threats, such as phishing, and apply basic digital hygiene principles. The second, and extremely important group, is the executives themselves. The directive requires them to receive training to understand risks and assess the effectiveness of cyber security management practices. This training must be tailored to the roles and responsibilities of each group, and its delivery and effectiveness carefully documented.
Priority Roadmap for implementation of NIS2 in industry (2025-2026)
| Phase | Period | Key Activities | Target |
|---|---|---|---|
| I. Foundations | Q4 2025 | Establish a steering committee. Conducting an audit and risk analysis. Create a compliance plan. | Understanding the status quo, defining the roadmap and gaining board support. |
| II. Critical Actions | Q1-Q2 2026 | Implementation of IRP/BCP plans. Segmentation of key network zones. Securing remote access (MFA). Launching awareness program. | Address the greatest risks and meet the most pressing regulatory requirements. |
| III. Building Maturity | Q3-Q4 2026 | Implement central monitoring (SIEM/SOC). Launch of a vulnerability management process. Supply chain audits. | Building advanced detection, response and proactive risk management capabilities. |
What does the NIS2 priority implementation roadmap for 2025-2026 look like?
Trying to do everything at once is impossible. The key is to divide the project into logical, consecutive phases. The first phase, still to be completed in 2025, is to lay the foundation. It includes establishing a cross-functional steering committee, conducting a comprehensive risk analysis and creating a detailed, budgeted roadmap for the entire program. This is the strategic planning phase. The second phase, scheduled for the first half of 2026, is the implementation of critical activities. The focus should be on those elements that yield the greatest risk reduction and are critical from a legal perspective - the creation of IRP/BCP plans, basic network segmentation and securing remote access. The third phase, in the second half of 2026 and beyond, is to build maturity - implementing more advanced systems, such as SIEM, and improving processes.
How much can a minimum NIS2 compliance program realistically cost for a medium-sized manufacturing company?
It is impossible to give a one-size-fits-all amount, since the cost depends on the size of the company, the complexity of the infrastructure and the current level of maturity. However, based on experience from similar projects, some orders of magnitude can be estimated. For a medium-sized manufacturing company, the cost of the first, fundamental phase (audit, risk analysis, creation of documentation) is usually an expense of tens to hundreds of thousands of zlotys. Phase two, which includes the purchase of basic technologies (e.g., firewalls for segmentation) and implementation of processes, is another **150-300 thousand zlotys **. Implementing advanced monitoring (SIEM/SOC) is an expense on the order of **200-500 thousand zlotys or more **, depending on the model. However, it should be remembered that thanks to grant programs, a significant part of these costs can be financed by external funds.
Does NIS2 require encryption of OT backups and other specific technical controls?
In principle, the NIS2 directive is technology-neutral - it does not mandate the use of specific, named technologies. Instead, it mandates the implementation of measures “appropriate” to the risk. However, in Article 21, the directive provides an illustrative, open-ended list of such measures. Among them is “the use of cryptography and, where appropriate, encryption.” In practice, in today’s threat landscape, encryption of critical data, including backups, is considered an absolutely fundamental and necessary security measure. It can therefore be assumed with a high degree of certainty that regulators will expect companies, especially those in the key sector, to use encryption as one of their fundamental safeguards.
What to pay special attention to when choosing a partner to implement NIS2 requirements?
Choosing a consulting partner is one of the most important decisions in the entire process. It is crucial that it is a company with real, proven experience at the interface of IT, OT and law. The partner must understand not only the technical aspects of security, but also the specifics of production environments and the nuances of new regulations. It is worth asking about references from similar projects, certifications held by the team (e.g., IEC 62443, ISO 27001 auditors) and the methodology used. A good partner will not come with a ready-made, one-size-fits-all template, but will start the work with a thorough understanding of your unique business and operational context.
How to turn the NIS2 compliance obligation into a strategic modernization opportunity?
Although NIS2 is a legal requirement, smart managers can turn it into a strategic opportunity. There is an unprecedented argument to finally get the budget and mandate to carry out a deep modernization and clean-up of the OT environment, which has often been neglected for years. NIS2 compliance need not be an end in itself. The goal should be to use this momentum to build a real resilient, secure and ultimately more reliable and efficient production infrastructure. Projects such as network segmentation and monitoring deployment, in addition to improving security, often bring operational benefits such as greater network stability and faster fault diagnosis. By treating NIS2 as a catalyst, goals that go far beyond mere compliance can be realized.
How can nFlo guide your company through the entire NIS2 compliance process - from audit to implementation?
At nFlo, we specialize in providing comprehensive support to industrial companies in achieving NIS2 compliance. Our unique value lies in our combination of deep OT safety expertise, knowledge of IEC 62443, and practical understanding of regulatory requirements. We guide you by the hand through the entire journey: We start with an audit and Gap Analysis, which shows precisely where your organization is not yet compliant with the directive. Based on this, we create a prioritized roadmap that takes you step-by-step to full compliance in a realistic and embedded way within your budget. Our consultants help create the necessary documentation (policies, procedures, IRP/BCP plans), and our engineers support the design and implementation of key technologies such as network segmentation and monitoring systems. With us, the complex and overwhelming process of NIS2 compliance becomes a manageable and structured program that culminates in a real strengthening of your company’s resilience.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Ransomware — Ransomware is a type of malicious software (malware) that blocks access to a…
- Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
- SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
- Network Security — Network security is a set of practices, technologies, and strategies aimed at…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
Learn More
Explore related articles in our knowledge base:
- Amendment to the NSC Act (NIS2): What new obligations await Polish companies and how to prepare for them?
- How to implement NIS2 and not go crazy? Use regulation as leverage to get a budget for OT security
- National Security and Cyber Resilience - How will PLN 20 billion from the NIP change Polish defense and implement NIS2?
- Personal board liability for cybersecurity under NIS2
- Board Responsibility for OT Cybersecurity Under NIS2
Explore Our Services
Need cybersecurity support? Check out:
- NIS2 Compliance - NIS2 directive compliance
- NIS2 Readiness Check - NIS2 readiness assessment
- Security Audits - comprehensive security assessment
Related topics
See also:
- NIS2 for hospitals — implementation and funding
- Security Audit Pricing Calculator
- NIS2 for hospitals — compliance
