SCADAPENTEST

GD-02 · Regulation

NIS2 and OT security testing: what Article 21 actually requires

Updated 8 min read

NIS2 has been sold to industrial operators as a testing mandate. It is not one. The directive never mentions penetration testing in the article that sets out risk-management measures, and reading what it does say is the difference between a proportionate programme and an expensive annual ritual that puts the plant at risk.

Which industrial sectors are covered

Directive (EU) 2022/2555 sorts covered entities into two annexes. Annex I is headed “Sectors of high criticality” and Annex II “Other critical sectors”. Both matter to industry, and the difference between them is not the difference between essential and important entities, which is decided separately in Article 3 using size thresholds and specific carve-outs.

Annex I, the heavy-OT entries

  • Energy, across five subsectors: electricity (including distribution and transmission system operators, producers and recharging-point operators), district heating and cooling, oil (including operators of oil transmission pipelines and of production, refining, treatment, storage and transmission facilities), gas (supply, distribution, transmission, storage and LNG system operators, and operators of natural gas refining and treatment facilities), and hydrogen production, storage and transmission.
  • Transport: air traffic control, rail infrastructure managers and railway undertakings, ports and their facilities, operators of vessel traffic services, road authorities responsible for traffic management control, and operators of intelligent transport systems.
  • Drinking water: suppliers and distributors of water intended for human consumption, excluding distributors for which that distribution is a non-essential part of their activity.
  • Waste water: undertakings collecting, disposing of or treating urban, domestic or industrial waste water, with the same non-essential-activity exclusion.

Annex II, where most manufacturers land

  • Manufacturing, defined by NACE Rev. 2 divisions: computer, electronic and optical products (26), electrical equipment (27), machinery and equipment not elsewhere classified (28), motor vehicles, trailers and semi-trailers (29), and other transport equipment (30). Medical devices and in vitro diagnostics are also listed, and are out of scope for this site.
  • Manufacture, production and distribution of chemicals, using the REACH definitions of substances, mixtures and articles.
  • Production, processing and distribution of food, limited to food businesses “engaged in wholesale distribution and industrial production and processing”.
  • Waste management, excluding undertakings for whom waste management is not their principal economic activity.

What Article 21 actually says

Article 21(1) requires “appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services”, taking into account the state of the art, relevant standards and the cost of implementation.

Article 21(2) then lists ten minimum measures, and says they “shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents”. That phrase is the reason an OT programme cannot be a pure cyber programme: physical access, power, cooling and the environment are inside the obligation.

Article 21(2) measures, read from an OT position
MeasureWhat it means on a plant
(a) Risk analysis and information system security policiesA risk assessment that treats process consequence, not data classification, as the impact axis.
(b) Incident handlingA plan that includes reverting to manual control and knowing who can authorise it.
(c) Business continuity, backup and crisis managementVerified restorable backups of controller projects and engineering workstations, not just servers.
(d) Supply chain securityThe integrator, the maintenance contractor and the remote support tunnel are inside the scope.
(e) Security in acquisition, development and maintenance, including vulnerability handlingProcurement clauses, and a route for advisories about your controllers to reach the person who can act.
(f) Policies and procedures to assess the effectiveness of measuresThe testing obligation. Assessment is mandatory; the method is yours to justify.
(g) Basic cyber hygiene and trainingIncluding the control engineers, not only office staff.
(h) Cryptography and encryption where appropriate“Where appropriate” is doing real work here: most field protocols cannot carry it.
(i) Human resources security, access control, asset managementShared operator accounts are the standing finding in this category.
(j) Multi-factor authentication and secured communications where appropriateStart with the remote-access path; joint agency advisories name it repeatedly.

Point (f) is the whole testing mandate

The directive requires “policies and procedures to assess the effectiveness of cybersecurity risk-management measures”. It does not name penetration testing, red teaming, vulnerability scanning or any interval. Compare that with DORA, which does name threat-led penetration testing and sets a cycle for the financial entities its authorities identify. NIS2 chose not to.

That is deliberate, and for operational technology it is a mercy. It means an operator can build an assessment programme that fits the plant: continuous passive monitoring, a periodic architecture and configuration assessment, testing of the edge and remote access whenever the perimeter changes, and intrusive work aligned to turnarounds. What it also means is that the operator has to be able to show the policy, the procedure and the results. An assessment programme that exists only as an annual invoice does not satisfy point (f).

Management liability, and why it changes the conversation

Article 20(1) requires Member States to ensure that management bodies of essential and important entities “approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article”. Article 20(2) requires members of those management bodies to follow training.

For an OT programme this has a practical effect that is easy to miss. If the board is personally exposed, the board will want assurance, and the fastest-looking route to assurance is a test report with a lot of red in it. That is precisely the pressure that produces an active scan on a live control network. The counterweight is a written assessment policy, approved at board level, that states which methods are excluded on safety grounds and why. Making the exclusion a governance decision rather than a technical preference protects both the plant and the people who signed it.

Supply chain: your integrator is in scope

Article 21(2)(d) requires supply-chain security “including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”, and Article 21(3) says entities must take into account “the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures”.

In an industrial estate the direct supplier is usually the system integrator or the equipment manufacturer, and they usually hold a remote support tunnel into the plant. That tunnel is simultaneously a supply-chain control, an access-control question and the most likely route in. Testing it is straightforward, permitted on a live plant, and frequently the single highest-value activity in a first engagement. What it needs is written notice: support can be lost if third-party software is introduced without the vendor’s agreement, and in some contracts the tunnel is theirs to close, not yours.

Recital 86 also records the Union view of firms like the one publishing this site: “Among service providers, managed security service providers in areas such as incident response, penetration testing, security audits and consultancy play a particularly important role in assisting entities in their efforts to prevent, detect, respond to or recover from incidents.” Useful context, and worth reading with the commercial interest declared on our about page in mind.

Where the sectors actually stand

ENISA’s NIS360 assessment of sector maturity against criticality is blunt about the spread. Electricity, telecoms and banking “stand out above the rest in terms of overall maturity and criticality”. Within energy, “gas shows moderate maturity”, while “district heating and cooling, hydrogen, and oil lag significantly, ranking in the low end of maturity among all sectors assessed”. In water, “drinking water demonstrates higher maturity than waste water with both sectors’ scores being on the lower end of the maturity scores ranking”.

ENISA also observes that these sectors “utilise Operational Technology (OT) in varying degrees”, with “sectors like oil and drinking water being more dependent on OT for safety and efficiency than others like road transport or hydrogen”, and that ICT dependency is “moderate, with ongoing digitisation offset by widespread legacy systems and reliance on suppliers and third parties for updates and maintenance”. That last clause is the entire supply-chain problem in one sentence.

What to do first

  • Confirm which annex entry you fall under, and whether Article 3 makes you an essential or an important entity. The supervisory regime differs; the Article 21 measures do not.
  • Write the assessment policy required by point (f) before commissioning any testing, so that the scope decisions are governed rather than improvised.
  • Get an accurate asset and conduit inventory. Almost every other measure depends on it and none of the safe methods threaten the process.
  • Test the edge and the remote-access path now. It is permitted on a live plant, it is where intrusions start, and it satisfies several measures at once.
  • Book the intrusive work against the next planned outage, and say so in the policy, so nobody is later surprised that it did not happen in the calendar year.

For which methods are actually safe on your environment, see what can safely be tested on a live OT network. For the standard your remediation plan will be measured against, see which part of IEC 62443 applies to you, and use the approach selector to turn all of it into a specific answer.

Sources

  1. Directive (EU) 2022/2555 (NIS2) Official Journal of the European Union, L 333, 27.12.2022 · 2022 Articles 20 and 21 and recitals 79 and 86; Annex I (sectors of high criticality) and Annex II (other critical sectors).
  2. ENISA NIS360 2024 European Union Agency for Cybersecurity · 2025 Sector maturity against criticality, including the energy subsectors and the drinking water and waste water comparison.
  3. NIST SP 800-82r3, Guide to Operational Technology (OT) Security National Institute of Standards and Technology · 2023 Used here for the constraints that make an OT assessment programme look different from an IT one.

FAQ-950 · Questions

Related questions

Does NIS2 set a testing frequency for OT?
No. Article 21(2)(f) requires policies and procedures to assess the effectiveness of cybersecurity risk-management measures, without naming a method or an interval. Any annual figure you have been quoted comes from a national implementation, a sector code, an insurer or a supplier, not from the directive. Check which, because the answer determines whether it is negotiable.
Are we an essential or an important entity?
The annexes do not decide this. Annex I lists sectors of high criticality and Annex II other critical sectors; Article 3 then applies size thresholds and specific rules to classify entities as essential or important. The practical difference is supervisory: essential entities face proactive supervision, important entities are supervised after the fact. The Article 21 measures apply to both.
Our OT is air-gapped. Does NIS2 still apply?
Yes, if your entity is in scope. The obligation attaches to the entity and its network and information systems, not to whether a particular segment is routable. In practice very few estates are genuinely air-gapped once maintenance laptops, USB transfer, vendor tunnels and wireless telemetry are counted, and demonstrating the gap is itself a piece of assessment evidence worth having.
Does a NIS2 audit replace technical testing?
They answer different questions. An audit checks that the measures exist and are documented; assessment under point (f) checks that they work. A documented network segmentation policy and a firewall ruleset that actually enforces it are two separate findings, and only the second is technical evidence.