Theme: Start with the correct entity, jurisdiction and operational risk picture
Quick definition
NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It entered into force on 16 January 2023, and Member States were required to transpose it by 17 October 2024. Applicable national law gives practical effect to local rights and duties.
In context: who may be in scope
The Directive describes essential and important entities in listed sectors. Assessment depends on the legal entity, activities, sector, size or special status, and jurisdiction. An OT system, building or industry label alone does not determine whether an organisation is in scope.
Management, risk and incidents
For in-scope entities, NIS2 addresses management accountability, proportionate risk-management measures, continuity, supply chains, access and incident reporting. Exact deadlines, supervision and penalties must be checked against the Directive, implementing acts and the national law applicable to the entity.
A concrete OT scenario
A group operates a Swedish production site, a central IT service and remote support from several suppliers. Scope is assessed for each relevant legal entity and jurisdiction. Critical processes, systems, supplier dependencies and incident paths are then connected to organisational risk management and reporting.
IEC 62443 as engineering support
IEC 62443 can support technical and organisational IACS work, including accountability, security programmes and system requirements. A standards reference or certified product does not establish NIS2 compliance. Legal scope, governance, incident reporting and national requirements require separate assessment.
Opportunities and trade-offs
NIS2 work can improve ownership, asset visibility, supplier governance and exercises across IT and OT. A generic checklist can still miss different consequences and national rules. Evidence should be reused where relevant, but every control needs a real owner and defined scope.
HubMind’s view
Separate the legal scope assessment from the technical delivery plan while keeping them traceably connected. Qualified legal expertise determines applicable law. Engineering and operations demonstrate systems, risks, measures and tests. IEC 62443 can structure part of that work without becoming a compliance claim.
A practical next step
Confirm the legal entity, activities, sector, size, Member State and competent authority against current national law. Then map critical services, OT dependencies, suppliers and incident paths. Record assumptions, evidence and open questions, and reassess when the business or law changes.
Related concepts
Cybersecurity (OT), IEC 62443, Network Segmentation, Asset Management.
Sources and further reading
Scope and freshness
Directive (EU) 2022/2555 and supporting ENISA information, reviewed 2026-08-31. NIS2 is implemented through national law; this page does not determine Swedish or other national legal applicability and is not legal advice. Reviewed 31 August 2026.
