Skip to main content
Back to overview

NIS2 Food Sector: Which Manufacturers and Distributors Are in Scope

By NIS2Certify
nis2food-sectormanufacturingscopeot-securitymsp
NIS2 Food Sector: Which Manufacturers and Distributors Are in Scope

A 60-person cheese producer runs its packing line on a PLC nobody has patched since installation. Cold-store temperatures stream to a cloud dashboard. Two supermarket chains send orders over EDI. Ask the owner whether NIS2 applies and you will usually hear: "We make food. We are not a bank."

That answer is wrong more often than it is right. The NIS2 food sector entry in Annex II covers industrial food production, processing and wholesale distribution. If your client sits there and passes the size test, it is an in-scope important entity, with a regulator, a register and a management body that answers for the result.

The NIS2 food sector entry: who it actually covers

Annex II of Directive (EU) 2022/2555 lists "production, processing and distribution of food" as one of the other critical sectors. The entities named are food businesses, as defined in Article 3(2) of Regulation (EC) No 178/2002, that are engaged in wholesale distribution and industrial production and processing.

Three things fall outside that wording unless a member state has designated them as critical under the CER Directive: primary production (farms), retail (shops), and food service (restaurants and caterers). The Finnish Food Authority states this explicitly in its guidance for the sector.

Food is an Annex II sector, so in-scope companies are important entities, not essential ones. That has a practical meaning: supervision is reactive rather than proactive. A regulator acts after evidence of non-compliance, such as an incident, a complaint or an unregistered company found through a sector list.

Size is the second gate. As a working rule, the company must be at least medium-sized: 50 or more employees, or annual turnover and balance sheet total both above EUR 10 million.

Does NIS2 Apply to Your Organisation?

1

Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?

Yes ↓No →
2

Does your organisation have 50 or more employees, or both an annual turnover and a balance sheet total exceeding €10 million?

Yes ↓No →
3

Is your organisation a critical infrastructure provider or a qualified trust service provider?

Yes ↓No →
✗

NIS2 does not directly apply to your organisation.

✓

NIS2 applies to your organisation as an Essential or Important Entity.

!

NIS2 may apply to your organisation — seek legal advice to confirm your status.

Applies
Possibly applies
Does not apply

Three edge cases that decide scope

The producer with its own shops. A bakery that produces industrially and also runs twelve retail outlets is in scope for the production side. The activity puts the entity in the sector; the size test is applied to the entity as a whole. Do not let a client argue itself out because "most of our revenue is retail" without reading the national text.

The subsidiary of a larger group. Size is measured under Commission Recommendation 2003/361/EC, which counts linked and partner enterprises. A 30-person packing subsidiary of a 400-person group can land in medium or large territory. Ask for the group structure before you accept "we are too small."

The wholesaler and the co-packer. Wholesale distribution is named in the text. An ingredient wholesaler or a contract co-packer supplying branded manufacturers is not a bystander to this sector. It is inside it.

If a client is unsure, our guide on whether NIS2 applies to your organisation walks through the general test.

What important-entity status means in practice

Important entities owe the same Article 21 risk-management measures as essential ones. The difference lies in supervision and penalties, not in the duty itself.

  • Management body accountability. Article 20 requires the management body to approve the measures and oversee them. In a family-owned food group that is the owner-manager, not the IT contractor.
  • Incident reporting. A significant incident triggers an early warning within 24 hours, a notification within 72 hours and a final report within one month. See the incident reporting deadlines for the mechanics.
  • Fines. For important entities the ceiling is EUR 7 million or 1.4% of worldwide annual turnover, whichever is higher, set in Article 34.
  • Registration. Nearly every member state requires in-scope companies to register with a national authority. Registration is binary and timestamped, which makes it the easiest thing for a regulator to check. Our registration overview lists the portals.

Article 21 — 10 NIS2 Cybersecurity Measures

Article 21

10 Cybersecurity Measures

Governance & Strategy

1Risk analysis & information security policies
6Effectiveness assessment of security measures

Incident & Continuity

2Incident handling & notification
3Business continuity & disaster recovery

Supply Chain & Systems

4Supply chain security
5Security in network & information systems development

Technical Controls

8Cryptography & encryption
10Multi-factor authentication & secure communications

People & Assets

7Cyber hygiene & training
9HR security & access control

Where food companies fail: the OT floor and the cold chain

A food plant is an operational technology environment with a canteen-grade IT network wrapped around it. That is where audits find gaps.

The systems that matter are the ones that stop production or spoil product: PLCs and SCADA on filling and packing lines, MES for batch tracking, cold-chain monitoring for temperature and humidity, laboratory systems (LIMS) that release batches, and the ERP that drives orders. Compromise any of them and the plant stops, or worse, ships product whose safety records cannot be trusted.

Four measures carry most of the weight:

  1. Segmentation between office IT and production. The pattern in our manufacturing OT/IT segmentation guide applies directly: a flat network turns a phishing email into a stopped line.
  2. Remote access with strong authentication. Machine vendors often keep standing remote access to PLCs. Every such path is a supplier access route under Article 21(2)(d).
  3. Backups you can restore, including PLC programs and recipes. Article 21(2)(c) is about restoring operations. A backup of the file server that omits the line controller configuration does not restore a plant.
  4. Integrity of food-safety records. Cold-chain logs and batch release data are evidence for both the food safety authority and the NIS2 regulator. Protect them accordingly.

Supply chain security cuts both ways. The retailers buying from your client will start asking for proof, and supplier contracts are already part of NIS2 compliance.

The same sector, different starting points across the EU

The directive is one text; the obligations depend on national law. Where things stand as checked in September 2026:

  • Finland. The Cybersecurity Act 124/2025 has applied since 8 April 2025. The Finnish Food Authority supervises food companies, and its registration deadline was 8 May 2025.
  • Germany. The NIS2 implementation act amended the BSIG. Food producers of medium size are important entities under section 28(2), and the BSI runs the register. A food company can become a particularly important entity only through critical-infrastructure thresholds.
  • Netherlands. The Cyberbeveiligingswet has applied since 15 August 2026. Registration runs through the NCSC.
  • Poland. The amended KSC lists food production, processing and distribution as an important sector. The Minister for Digital Affairs keeps the register.
  • Italy. Legislative Decree 138/2024 has been in force since October 2024, and the ACN sets the phased deadlines.
  • France. No transposition law yet. A resilience bill is still moving through parliament, while ANSSI has published its ReCyF framework.
  • Spain. Not transposed, and referred to the Court of Justice in July 2026.

NIS2 transposition by country

  • NetherlandsIn force
    • In force since August 15, 2026
    • Act: Cyberbeveiligingswet (Stb. 2026, 187)
    • Registration required, no transition period

    Authority: NCSC (MijnNCSC) · Source

  • LuxembourgIn force
    • In force since May 10, 2026
    • Act: Law of 5 May 2026
    • Registration due July 10, 2026

    Authority: ILR (CSSF for finance) · Source

  • PolandIn force
    • In force since April 3, 2026
    • Act: UKSC (Dz.U. 2026 poz. 252)
    • Registration due October 3, 2026
    • Measures due April 3, 2027

    Authority: Minister Cyfryzacji (Wykaz KSC) · Source

  • PortugalIn force
    • In force since April 3, 2026
    • Act: Decree-Law 125/2025 (RJC)

    Authority: CNCS · Source

  • BulgariaIn force
    • In force since February 13, 2026
    • Act: Cybersecurity Act amendment (State Gazette No 17/2026)

    Authority: Ministry of e-Government · Source

  • MaltaIn force
    • In force since January 23, 2026
    • Act: S.L. 460.41

    Authority: Critical Infrastructure Protection Department · Source

  • SwedenIn force
    • In force since January 15, 2026
    • Act: SFS 2025:1506

    Authority: NCSC-SE · Source

  • EstoniaIn force
    • In force since January 1, 2026
    • Act: Cybersecurity Act (KüTS) amendment
    • Registration within 3 months

    Authority: RIA · Source

  • GermanyIn force
    • In force since December 6, 2025
    • Act: NIS2UmsuCG
    • Registration due March 6, 2026
    • 17,729 registered by June 30, 2026

    Authority: BSI · Source

  • CzechiaIn force
    • In force since November 1, 2025
    • Act: Act No 264/2025 Coll.
    • Registration within 60 days

    Authority: NÚKIB · Source

  • DenmarkIn force
    • In force since July 1, 2025
    • Act: NIS 2 Act No 434 of 6 May 2025
    • Registration due October 1, 2025

    Authority: Danish Agency for Societal Security · Source

  • SloveniaIn force
    • In force since June 19, 2025
    • Act: ZInfV-1 (OG 40/25)
    • Registration within 30 days

    Authority: URSIV · Source

  • CyprusIn force
    • In force since April 25, 2025
    • Act: Law 60(I)/2025

    Authority: Digital Security Authority · Source

  • FinlandIn force
    • In force since April 8, 2025
    • Act: Cybersecurity Act 124/2025
    • Registration due May 8, 2025
    • Measures due July 8, 2025

    Authority: Traficom (NCSC-FI) · Source

  • HungaryIn force
    • In force since January 1, 2025
    • Act: Act LXIX of 2024

    Authority: SZTFH · Source

  • SlovakiaIn force
    • In force since January 1, 2025
    • Act: Act No 366/2024 Coll.
    • Registration within 60 days

    Authority: NBÚ · Source

  • RomaniaIn force
    • In force since December 31, 2024
    • Act: GEO 155/2024 (Law 124/2025)
    • Registration within 30 days

    Authority: DNSC · Source

  • GreeceIn force
    • In force since November 27, 2024
    • Act: Law 5160/2024 (Gazette A' 195)

    Authority: National Cybersecurity Authority · Source

  • BelgiumIn force
    • In force since October 18, 2024
    • Registration due March 18, 2025

    Authority: CCB · Source

  • LithuaniaIn force
    • In force since October 18, 2024
    • Act: Law No XIV-2902

    Authority: NCSC (MoND) · Source

  • ItalyIn force
    • In force since October 16, 2024
    • Act: D.Lgs. 138/2024
    • Baseline measures due by October 2026 (entities listed in 2025)

    Authority: ACN · Source

  • LatviaIn force
    • In force since September 1, 2024
    • Act: National Cybersecurity Law

    Authority: National Cybersecurity Centre · Source

  • CroatiaIn force
    • In force since February 15, 2024
    • Act: Cybersecurity Act (OG 14/2024)

    Authority: NCSC (SOA) · Source

  • AustriaAdopted, not yet in force
    • Applies from October 1, 2026
    • Act: NISG 2026 (BGBl. I Nr. 94/2025)
    • Registration due December 31, 2026

    Authority: Federal Office for Cybersecurity · Source

  • FranceNot yet transposed
    • Senate adopted the law on March 12, 2025
    • Regulator published its framework on March 17, 2026
    • Pre-registration open

    Authority: ANSSI · Source

  • SpainNot yet transposed
    • Draft bill approved on January 14, 2025
    • The NIS1 regime still applies

    Authority: CCN / INCIBE · Source

  • IrelandNot yet transposed
    • Referred to the Court of Justice on July 8, 2026
    • Bill not yet enacted

    Authority: NCSC Ireland · Source

Status as of September 28, 2026. Other member states: see the country-by-country timeline.

What to do with a food client this month

Run the scope test first, in writing: activity, entity size including group, and country. Record the answer even when it is "out of scope," because a regulator will ask how you decided.

If the client is in scope, check registration before anything else, then inventory the OT assets that stop production. Map who has remote access, test one restore of a line controller, and write down the 24-hour reporting path with a named person.

A readiness assessment shows the gaps against Article 21 in a structured format, and you can start one with the NIS2Certify quick scan. Food companies rarely lack effort. They lack a documented picture of which systems matter, and that is the first thing a supervisor asks to see.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.

    NIS2 Food Sector: Who Is in Scope and What to Prove