NIS2 for Manufacturing
Product security and corporate security collide. The Cyber Resilience Act governs what you ship; NIS2 governs how you run. Teams routinely conflate the two and satisfy neither.
Which entities are covered
Manufacturers of medical devices and in vitro diagnostic medical devices; manufacturers of computer, electronic and optical products; electrical equipment; machinery and equipment n.e.c.; motor vehicles, trailers and semi-trailers; other transport equipment.
Sub-sectors named in the annex
- Medical devices and in vitro diagnostics
- Computer, electronic and optical products
- Electrical equipment
- Machinery and equipment
- Motor vehicles, trailers and semi-trailers
- Other transport equipment
Scope traps specific to this sector
Trap 1
Scope is defined by NACE divisions, so the answer depends on your registered activity code rather than on self-description.
Trap 2
The Cyber Resilience Act (Regulation (EU) 2024/2847) covers products with digital elements. It is a separate obligation from NIS2, not an alternative.
Trap 3
Automotive suppliers face UNECE R155 for vehicle type approval on top of NIS2.
What else applies to you
Cyber Resilience Act; MDR and IVDR; UNECE R155 and R156; the Machinery Regulation.
NIS2 rarely arrives alone. Where another EU act covers the same ground and is at least equivalent in effect, article 4 disapplies the corresponding NIS2 provisions — but only those, and only where that test is met.