NIS2 sets one cybersecurity baseline for essential and important entities in 18 sectors. It is a directive: the duties that bind you live in national law. In the Netherlands that is the Cyberbeveiligingswet, in force 15 August 2026. The directive decides the floor: risk management, reporting, and management accountability.
Essential or important is decided by sector and size in your national law: large companies in the high-criticality sectors are essential; medium-sized ones are typically important; some types qualify regardless of size. The fine floors are real: up to €10 million or 2% of worldwide turnover for essential entities, €7 million or 1.4% for important ones. Member states may go higher.
Whether you are in scope is a national-law question. In the Netherlands: check the Cbw and register at mijn.ncsc.nl, mandatory per 15 August 2026.
The directive never says PLC, zone or safety system. It says "appropriate". For an installation, appropriate is decided by a per-system risk assessment. IEC 62443-3-2 is how OT does that demonstrably.
No. It requires measures you can defend as appropriate. For OT, a IEC 62443-3-2 assessment makes "appropriate" demonstrable. That is why we built on it.
The directive is the floor; each country transposed its own version. One evidence base mapped to the directive’s articles serves all of them; presentation differs per regulator.
Sector plus size decides it, in your national law. In the Netherlands: the Cyberbeveiligingswet, with registration at mijn.ncsc.nl from 15 August 2026.
A good foundation: it governs the management system. NIS2’s "appropriate measures" for an installation still need the OT-level risk assessment underneath.
Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.