NIS2: where to start when you run an industrial site
The European NIS2 directive has been in force at Union level since late 2024, and its French transposition is coming. For thousands of industrial SMEs and mid-caps, it will be their first encounter with cybersecurity regulation. The good news: the first obligations are also the most useful ones, and they can be prepared today, calmly.
Who is concerned, and when
NIS2 massively widens the scope of its predecessor: the French agency ANSSI mentions around 15,000 entities in France, against some 500 operators under NIS1. Industrial sectors feature prominently: food processing, chemicals, medical devices, electronics and machinery, water and waste management, energy. Depending on size and sector, a company will be classified as an "essential" or "important" entity, with graduated requirements and penalties.
On the timeline side, France is late with transposition: the resilience bill passed the Senate in early 2025 and has been awaiting its reading at the National Assembly since. This delay is an opportunity: obligations are coming, but nothing forces urgency yet. Companies that start today reach compliance at their own pace - those who wait for the decree will do it in the crowd.
What the regulation will concretely require
The reference framework published by ANSSI to implement NIS2 in France (ReCyF, still a working version) describes some twenty security objectives. Two of them, applicable to all regulated entities, directly concern the shop floor:
- Mapping of assets and information systems - knowing what is connected, including on the production side: PLCs, HMIs, SCADA, gateways, remote maintenance.
- Risk analysis, reviewed at least once a year - identifying feared scenarios, scoring the risk, deciding measures, and documenting everything.
Essential entities face additional requirements: regular audits, hardening, supervision. But for the vast majority of industrial sites, everything starts with those two building blocks: know your network, then score your risk.
The classic trap: starting with IT and forgetting the shop floor
Many companies approach NIS2 through their corporate IT: email, workstations, servers. That is necessary, but the industrial network - the machines' network - is precisely the least known and the most exposed to severe consequences. A PLC reachable from the office network, a supplier remote-access tunnel left permanently open, an industrial protocol crossing levels: these very common situations are invisible from IT. They only show in the shop-floor network traffic.
A pragmatic path in four steps
- 1. Map passively. A listening probe plugged into a mirrored port of the industrial network inventories equipment and flows without emitting a single packet - zero risk for production. Within days, the real map of the site exists.
- 2. Structure into zones and conduits. IEC 62443, the technical reference regulators converge towards, organises the site into homogeneous zones linked by controlled conduits - built from the real map, not a theoretical diagram.
- 3. Analyse and score the risk. Threats, vulnerabilities, scenarios per zone, risk scoring before and after countermeasures. That is NIS2's risk-analysis requirement, addressed with the industrial lens of IEC 62443.
- 4. Document and review. A report dating the analysis, its assumptions and its action plan - reviewed yearly, as the regulation will require, and presentable as-is to an auditor, an insurer or a principal.
How Ultrametrix helps
Our UMX suite covers exactly these four steps: UMX Explorer performs the passive mapping of the industrial network (inventory, Purdue architecture, cross-level flows), and UMX Risk Manager turns that map into an IEC 62443 risk analysis - zones and conduits, scenarios, scoring, and a report ready to present. And because a tool does not replace a method, our experts carry out or co-produce the analysis with your teams, on site, up to the final report and your autonomy.
Everything runs offline, without telemetry, on a probe whose source code is open and auditable - a requirement we apply to ourselves before anyone asks.