NIS2 for manufacturing companies: who it applies to and what it requires

Manufacturing is newly regulated. Five sectors under CZ-NACE 26–30, medium and large enterprises, lower obligations by default. How to tell whether it applies to you — and what changes when you run production lines.

When people hear "cybersecurity law", they picture a bank, a hospital or a power plant. Manufacturing was not on that list for a long time — which is why plenty of manufacturers still assume the new Czech Cybersecurity Act has nothing to do with them.

It does. Manufacturing is one of the 22 sectors in which the implementing decree defines 102 regulated services in total. It had never been systematically regulated before, so these are entirely new obligations for companies with no prior experience of anything similar.

The good news: finding out whether this applies to you takes a few minutes. The bad news: if it does, your clock is already running.

Does it apply to your company? Both conditions must hold

There are two conditions and they must be met at the same time — the sector and the size.

1. The sector: five services under the CZ-NACE classification

Within the manufacturing sector, the decree lists five regulated services, defined by the CZ-NACE classification of economic activities:

If your production falls under any of those five divisions, the first condition is met.

2. The size: a medium-sized or large enterprise

The second condition is size, measured by the European definition of small and medium-sized enterprises (Commission Recommendation 2003/361/EC) — the same one you know from grant applications.

Simply put: from 50 employees upwards you are in scope. A smaller company only comes into scope if it also exceeds the financial thresholds (annual turnover, or balance sheet total, above EUR 10 million).

Watch out for one detail that is badly underestimated: linked enterprises count towards your size. If you are a subsidiary of a larger group, the group is counted, not just your plant. This is how a lot of "small" manufacturers suddenly discover they are a large enterprise.

Two traps companies fall into

Trap one: the NACE code in the register does not decide it. The classification recorded for your company is kept mainly for statistics and is only indicative. What decides is what you actually do. In practice that means two things: you cannot defend yourself by saying the activity isn't registered against your company — and conversely, a registered activity you no longer perform does not by itself put you in scope. What matters is the real extent of the services provided.

Trap two: food and chemicals are not "manufacturing". The food industry and the chemical industry are separate sectors in the regulation, with their own services and their own criteria. If you make food or chemicals, you will not find yourself in divisions 26 to 30 — and the Act may still apply to you. Look for yourself in your own sector, not this one.

You are in scope. What now?

Companies have to determine their own classification — the authority sends nobody a letter. The sequence is always the same:

  1. Verify both conditions (division 26 to 30 based on what you actually manufacture, plus size including linked enterprises).
  2. Notify the service through the portal of the National Cyber and Information Security Agency. The deadline is 60 days from the day you met the conditions — for most companies that was the Act taking effect, in November 2025.
  3. Wait for the registration decision. The date it is delivered is the key one, because the implementation period runs from it: one year.
  4. Implement the measures. Incident reporting within 24 hours, however, applies immediately after registration — not a year later.

If you missed the notification deadline, the obligation has not gone away. Notify as soon as you can — the sooner the decision arrives, the sooner the year starts, and you will need all of it anyway.

Which regime manufacturing falls into

The default regime for all manufacturing services is the lower obligations regime, for medium-sized and large enterprises alike. The decree sets it that way in line with the European directive.

What that means in practice: a narrower scope, lighter formal requirements, less documentation than in the higher regime, where energy or healthcare sit. What it does not mean: that it is free. The areas are the same — access and multi-factor authentication, logging, backup and recovery, supplier management, incident handling. And above all, reporting a significant incident within 24 hours applies in the lower regime too, right after registration, not once the implementation period ends.

We describe the difference between the regimes in plain language on the NIS2 hub.

What is different in manufacturing

General NIS2 guidance assumes a company where everyone sits at a computer. Manufacturing has four differences you hit immediately.

Machines run on Windows nobody is allowed to update

Next to a production line there is usually a computer with an old operating system, because that is what the machine vendor supplied and a newer version is not supported. You are not allowed to update it — you would lose the warranty or the functionality.

The answer is not updating but separation. That computer belongs in its own part of the network, with no internet access and no shared folders with the office network. The Act does not demand the impossible; it demands that you know the risk, describe it and limit it. A segregated network plus a record of why it is like that is a legitimate answer.

Machine vendors connect in from outside

This is the biggest difference from an office-only company. The press manufacturer, the control-system supplier, a service technician abroad — each of them often has permanently open remote access, because they "have to". Sometimes only one maintenance technician knows about it.

Supply-chain security is one of the areas of the Act, and this is exactly it. Make a list: who connects, how, when they last used it, and who approved it. The target state is access on request rather than permanently open, and ideally through your tool, not theirs.

Continuous operation versus a maintenance window

In a company running three shifts there is never a good time to reboot. Updates get postponed, and the postponement becomes permanent. Only one thing helps here: having a maintenance window agreed in advance and in the calendar, rather than negotiating it every time. A regular two hours a month is cheaper than one unplanned outage.

When a line stops, you don't lose data — you lose shifts

In an office company the worst case is data loss. In manufacturing the worst case is a stopped line: wages run, the order has a deadline, the material has been delivered. That is why recovery of operations carries far more weight here than the backup itself.

The question to ask: how long would it take us to produce the first part if we lost the control system? Anyone who doesn't know the answer has no recovery plan — they have a backup. Those are two different things, and the Act wants the second.

Most measures still get done in Microsoft 365

A manufacturer has production, but it also has offices, sales, engineering and accounting. And those almost always run on Microsoft 365 — which is where most of what the Act requires can be satisfied: multi-factor authentication, access control, logging, mail protection, laptop encryption.

The ten things most often broken in Microsoft 365 are covered in a separate article, NIS2 and Microsoft 365: the 10 gaps we find most often. For a manufacturer, the most important items on that list are separating administrator accounts and disabling legacy sign-in protocols — legacy protocols are exactly what integrations with older production systems tend to rely on.

A 90-day plan

WhenWhatWho
Weeks 1–2Verify whether you are in scope (CZ-NACE division + size including linked companies). If you are and are not registered, notify.management + finance
Weeks 3–4Inventory: servers, applications, production systems, domains, accounts. List of vendors' remote access.IT + maintenance
Month 2Quick technical measures: MFA with no exceptions, separated admin accounts, DMARC, legacy protocols off.IT
Months 2–3Separate the production and office networks. Close permanently open vendor remote access.IT + machine vendors
Month 3Test a restore: one server and one production system. Measure the time. Decide who reports incidents and test the portal sign-in.IT + management

What doesn't fit into 90 days — documentation, training, supplier contracts — belongs in the second quarter. A detailed breakdown by deadline is in NÚKIB registration is done. What you must finish before the deadline.

Where to start if you don't know where you stand

The fastest first step is the outside view: the free on-line security audit checks what is publicly visible about your domain — SPF and DMARC, certificates, leaked passwords. Five minutes, no meeting.

If you want the inside checked too, the NIS2 Microsoft 365 audit costs CZK 14,900 — roughly fifty specific settings against the areas of the Act, with read-only access.

Neither of those covers the production part of your network. That one you have to walk through yourself, or with someone who knows your machines — and no scan replaces that work.

Frequently asked questions

We are a small automotive supplier. Does it reach us through our customer?

Not directly under the Act — if you don't meet both the sector and size conditions, you are not a regulated entity. Contractually, though, yes, and increasingly so. Large buyers handle their own supply-chain obligation by passing the requirements down: questionnaires, contract clauses, audits. So in practice prepare for most of it anyway — it's just that the customer is making you, not the authority.

Our lines are not connected to the internet. Is that enough?

Not on its own. First, "not connected" often turns out to be untrue on inspection — a service modem, a USB stick for loading programs, or a technician's laptop shows up. Second, the obligations don't cover only the lines, but the whole regulated service including the offices. A segregated network is a correct and effective measure, but it is one measure among many, not a substitute for the rest.

Who should own this internally?

Responsibility sits with management; the Act says so explicitly. In manufacturing, though, the measures touch maintenance and process engineers as much as IT, so it makes sense to name a pair: someone for IT and someone for production. Vendors' remote access cannot be mapped without maintenance.

What does it cost and how long does it take?

The honest answer: it depends on how much you already have. A company with a reasonably configured Microsoft 365 that knows its machines can reach compliance within one or two quarters, mostly in-house. A company starting from zero with a fifteen-year-old server room is counting in years and in equipment spend. Nobody can seriously quote you a price without seeing what you have — and anyone who quotes one immediately is guessing.

This article is an orientation overview, not legal advice. Your specific classification and regime follow from the decree and from your own registration decision.