OT security readiness with NIS2 and IEC 62443 means combining regulatory outcomes with industrial security engineering. NIS2 defines cybersecurity risk management, incident reporting, management accountability and resilience expectations for essential and important entities. IEC 62443 provides the practical OT method through asset inventory, zones and conduits, risk-based security levels, segmentation, secure remote access, supplier requirements and OT-specific controls.
For factories, utilities and process plants, readiness should start with OT asset inventory, consequence-based risk assessment, industrial network segmentation, controlled vendor access, tested backups, OT-aware monitoring and incident response playbooks that support NIS2 reporting timelines.
Executive Summary
Operational Technology environments run physical processes such as manufacturing lines, utilities, plants, safety systems and industrial control networks. These environments have different security priorities from IT because availability, safety and process continuity often matter more than rapid patching or aggressive scanning.
NIS2 increases regulatory pressure on many European essential and important entities, including critical infrastructure and several manufacturing sectors. It requires risk management measures, incident reporting, management accountability and stronger supply chain oversight.
IEC 62443 helps translate these outcomes into engineering practice. It gives OT teams a structured way to identify assets, group systems into zones, define conduits, assign target security levels and apply OT-specific security controls.
The strongest readiness model uses both together: NIS2 for governance, accountability and reporting obligations, and IEC 62443 for technical OT security design, implementation and evidence.
Why OT Security Readiness Matters
Factories, utilities and process plants now face a regulation with teeth and a standard with depth. NIS2 tells European operators what outcomes they must achieve and what happens if they do not. IEC 62443 tells engineers how to achieve those outcomes in industrial environments. Readiness means using them together.
The threat picture has hardened. Ransomware crews learned that halting production forces faster payment than encrypting file shares. State linked actors have demonstrated OT specific malware against power grids and safety systems. And digitalization keeps dissolving the old air gap: remote vendor access, cloud analytics, and IIoT sensors all create paths from the internet to the plant floor. That combination of rising impact and rising exposure is exactly why NIS2 exists.
Why OT Is Different from IT
Operational Technology runs physical processes: PLCs opening valves, SCADA systems supervising grids, safety instrumented systems keeping reactions inside safe limits. The security priorities invert compared to IT. Availability and safety come first, because a mistimed patch or an aggressive network scan can trip a plant or endanger people. Asset lifetimes stretch to decades, protocols such as Modbus and PROFINET were designed without authentication, and maintenance windows arrive twice a year rather than every Tuesday night.
What NIS2 Demands from OT Operators
The NIS2 Directive, applicable across EU member states since late 2024 through national transpositions, dramatically widens the scope of regulated entities. Essential entities include energy, water, transport, health and digital infrastructure; important entities add manufacturing sectors such as chemicals, food, medical devices, machinery and electronics. Mid sized and large companies in these sectors are covered automatically, and supply chain obligations pull in many smaller partners indirectly.
The obligations that matter most for OT operators are:
- Risk management measures (Article 21): policies for risk analysis, incident handling, business continuity and crisis management, supply chain security, secure development and procurement, effectiveness assessment, cryptography, access control, asset management and MFA, all applied with an all hazards view that explicitly includes industrial systems.
- Incident reporting (Article 23): an early warning to the national CSIRT or authority within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month.
- Management accountability: boards must approve the risk measures, oversee implementation and undergo training. Individual liability and temporary bans on management functions are on the table for essential entities.
Sanctions: up to 10 million euros or 2 percent of global turnover for essential entities, and 7 million or 1.4 percent for important entities.
What IEC 62443 Provides
IEC 62443 is a family of standards for Industrial Automation and Control System security, addressing three audiences: asset owners who operate plants, system integrators who build automation solutions, and product suppliers who make components. The parts most relevant to readiness are:
| Part | Audience | What It Covers |
|---|---|---|
| 62443-2-1 | Asset owner | Establishing an OT security program: policies, organization, and management system elements comparable to an ISO 27001 ISMS but tuned for industrial operations |
| 62443-3-2 | Asset owner and integrator | Risk assessment method: partition the system into zones and conduits, assess risk per zone, assign target security levels |
| 62443-3-3 | Integrator | System level security requirements mapped to Security Levels 1 through 4 |
| 62443-4-1 and 4-2 | Product supplier | Secure development lifecycle requirements and component level technical requirements, useful as procurement criteria |
How NIS2 and IEC 62443 Work Together
The key insight: NIS2 states outcomes, not engineering detail. It never explains how to segment a plant network or harden a PLC. That is precisely the gap IEC 62443 fills, and several national authorities and ENISA guidance point toward it as good practice for the industrial scope.
NIS2 and IEC 62443 Alignment
| NIS2 Requirement Area | IEC 62443 Support |
|---|---|
| Risk management measures | 62443-3-2 risk assessment, zones and conduits, target security levels |
| Incident handling and reporting | OT incident response playbooks, monitoring, escalation and evidence |
| Business continuity and crisis management | ICT readiness, backup, recovery, segmentation and resilience planning |
| Supply chain security | 62443-4-1 and 62443-4-2 supplier and component security expectations |
| Access control and MFA | Secure remote access, role-based access and controlled engineering access |
| Asset management | OT asset inventory covering PLCs, HMIs, SCADA, firmware and network paths |
| Effectiveness assessment | Metrics, audits, testing and periodic review of OT security controls |
| Management accountability | Board-approved OT risk measures, roles, training and governance evidence |
Figure 2. Pairing directive obligations with standard mechanisms gives auditors and authorities a coherent story.
Zones, Conduits and Security Levels
Two concepts do the heavy lifting. Zones and conduits: group assets with similar criticality into zones, and control every communication path between zones through defined conduits with security controls. Security Levels: SL1 protects against casual violation, SL2 against intentional attack with simple means, SL3 against sophisticated attackers with moderate resources, and SL4 against state grade capability. Each zone gets a target level based on the consequence of its compromise, which turns vague ambitions into checkable requirements.
Figure 3. A zones and conduits model in the spirit of IEC 62443 and the Purdue reference levels.
Practical OT Security Readiness Roadmap
Readiness is best built in phases, each producing evidence the next phase depends on. The five phases below move from visibility to risk decisions to controls, response capability and sustained governance.
Phase 1: Build the OT Asset Inventory
You cannot defend or report on assets you cannot name. Build an OT asset inventory covering controllers, HMIs, engineering stations, network gear, remote access paths and installed firmware versions. Passive network monitoring tools built for industrial protocols do this without touching fragile devices. This single artifact serves NIS2 asset management duties, 62443 risk assessment inputs, and the incident reporting clock, because you cannot judge significance in 24 hours without knowing what was hit.
Phase 2: Assess Risk by Consequence
Apply the 62443-3-2 method: partition into zones, then assess each zone by asking what happens physically and financially if it is compromised. Loss of view, loss of control, and loss of safety are the consequence categories that resonate with plant leadership far more than confidentiality ratings. Assign target security levels per zone and record the gaps against current state. This risk assessment is simultaneously your Article 21 risk analysis evidence.
Phase 3: Close High-Leverage OT Security Gaps
- Segmentation first: establish the industrial DMZ and kill any direct enterprise to control paths, since this one measure blunts most ransomware propagation.
- Remote access under control: a single brokered path for vendors and staff with MFA, per session approval, recording and time limits. Uncontrolled vendor VPNs are the most common real world entry point.
- Backups that restore: offline copies of PLC logic, HMI projects and historian data, with restoration actually rehearsed.
- Hardening within reality: disable unused services, replace default credentials, and use compensating controls such as allow listing where patching is impossible.
- Detection tuned for OT: monitor conduits and controller communications for anomalies like new engineering connections or logic downloads, feeding an alert path the SOC and plant engineers share.
Phase 4: Build Incident Response and NIS2 Reporting Muscle
Write incident response playbooks jointly with operations, deciding in advance who may isolate a cell, when production stops, and how safety systems are verified. Then exercise against the NIS2 clock: run a tabletop where the team must produce an early warning within 24 hours and a notification within 72, including the practical questions of who calls the authority and what the template says. Include management, because their accountability under NIS2 is personal.
Phase 5: Govern and Sustain the OT Security Program
Anchor the program in a 62443-2-1 style management system: policy approved by the board, defined OT security roles bridging IT and engineering, supplier requirements referencing 62443-4-1 and 4-2 in procurement, training for operators and engineers, and yearly effectiveness reviews with metrics such as inventory coverage, conduit rule violations, remote session audit results and patch or compensating control status per zone.
Common OT Security Pitfalls to Avoid
Do not copy IT controls into the plant unmodified: an authenticated vulnerability scan that is routine in IT can crash a 15 year old controller. Do not treat NIS2 as a paperwork project owned solely by compliance, because authorities can audit technical reality, and incidents certainly will. Do not defer the asset inventory while writing policies, since every later step depends on it. And do not forget the safety system zone: it deserves the strictest target level and the most conservative change control, because it is the last line between a cyber event and a physical one.
Handled well, NIS2 readiness is not a tax. Segmentation reduces unplanned downtime from malware regardless of regulators. Asset visibility improves maintenance planning. Controlled remote access ends the sprawl of vendor connections nobody could list. The directive supplies the mandate and the deadline; IEC 62443 supplies the engineering method; and the result is a plant that is both compliant on paper and genuinely harder to break.
OT Security Readiness Checklist
Organizations preparing for NIS2 and IEC 62443 should validate the following:
- Build an OT asset inventory covering PLCs, HMIs, SCADA, engineering workstations, network devices, remote access paths and firmware versions.
- Identify essential and important entity obligations under applicable NIS2 national transposition rules.
- Partition the OT environment into IEC 62443 zones and conduits.
- Assign target security levels based on safety, availability, financial and operational consequences.
- Establish an industrial DMZ between enterprise IT and control networks.
- Remove direct enterprise-to-control paths wherever possible.
- Centralize vendor remote access through a brokered path with MFA, approval, recording and time limits.
- Maintain offline backups of PLC logic, HMI projects, historian data and critical OT configurations.
- Test backup restoration and recovery procedures.
- Monitor conduits and controller communications for new engineering connections, logic downloads and unusual behavior.
- Build OT incident response playbooks with operations, engineering, safety and security teams.
- Exercise the NIS2 reporting clock for early warning, incident notification and final reporting.
- Include management in tabletop exercises because NIS2 includes management accountability.
- Apply supplier requirements aligned to IEC 62443-4-1 and IEC 62443-4-2 where relevant.
- Review OT security metrics such as inventory coverage, remote access sessions, conduit violations and compensating control status.
How ServQual and SUSAN Help
ServQual helps organizations strengthen industrial cybersecurity, network security, incident response, GRC, operational resilience, cloud security and audit readiness.
OT security readiness should not be treated as a paperwork exercise. NIS2 requires governance, accountability and incident reporting capability, while IEC 62443 requires engineering-level discipline across assets, zones, conduits, suppliers and technical controls.
SUSAN can help teams connect OT security findings, risk visibility, remediation ownership, control evidence and audit readiness into one governance view. This helps security, engineering, operations, risk and leadership teams track whether OT risks are identified, assigned, remediated and evidenced.
With ServQual and SUSAN, organizations can:
- Review OT security readiness against NIS2 and IEC 62443 principles
- Track OT asset inventory and ownership gaps
- Prioritize remediation for segmentation, remote access, backups and detection
- Connect OT findings with GRC and compliance workflows
- Support audit-ready evidence for risk and control reviews
- Improve leadership visibility into OT cyber resilience
- Align incident response with regulatory reporting expectations
- Move from point-in-time OT reviews to continuous assurance
Explore Cybersecurity Services: https://srql.com/services/cyber-security-solutions/
Explore Incident Response & Managed Security: https://srql.com/services/incident-response-managed-security/
Explore Governance, Risk, Compliance & Audits: https://srql.com/services/governance-risk-compliance-audits/
Explore SUSAN: https://srql.com/services/susan/
"NIS2 defines the accountability. IEC 62443 defines the OT engineering discipline."
Jayesh Thakkar
Solutions Consultant | ServQual
FAQ
Most frequent questions and answers
OT security readiness is the ability to identify, protect, monitor and respond to cyber risk in industrial environments such as factories, utilities, plants, SCADA systems and control networks.
NIS2 affects many essential and important entities that rely on operational technology, including energy, water, transport, health and certain manufacturing sectors. It requires cybersecurity risk management, incident reporting, management accountability and supply chain security.
IEC 62443 is a family of standards for Industrial Automation and Control System security. It provides guidance for asset owners, system integrators and product suppliers.
Zones group OT assets with similar risk and criticality. Conduits define and control the communication paths between those zones.
Security levels define the target protection level for a zone or system, from basic protection against casual violation to protection against sophisticated attackers with greater resources.
OT asset inventory is essential because teams cannot assess risk, segment networks, respond to incidents or meet reporting expectations without knowing which assets exist and how they connect.
Remote vendor access can create a path from external networks to control systems. It should be controlled through MFA, session approval, recording, time limits and centralized access paths.
SUSAN can help teams connect OT security findings, risk visibility, remediation ownership, control evidence and audit readiness into a structured GRC and continuous assurance workflow.
Move OT Security Readiness from Paperwork to Engineering Evidence
OT environments need more than policy documents. NIS2 requires governance, accountability and reporting readiness, while IEC 62443 helps structure OT security through asset inventory, zones, conduits, target security levels, controlled remote access, supplier requirements and incident response.
ServQual helps organizations assess OT security readiness, review industrial network segmentation, strengthen vendor access controls, improve incident response capability and align findings with GRC evidence. Explore SUSAN or contact ServQual to connect OT findings, remediation ownership, control evidence and audit readiness into one Continuous Assurance view.
Disclaimer: This article is provided for general informational purposes only and does not constitute legal or regulatory advice. NIS2 obligations depend on national transposition laws and each organization’s sector, size and circumstances, and IEC 62443 application varies by environment. Organizations should consult qualified legal and engineering advisors for guidance on their specific obligations.