Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIS2 IEC 62443 mapping chart for cybersecurity governance.

NIS2 IEC 62443 Mapping: The Complete 2026 Guide

A NIS2 IEC 62443 mapping is the fastest route an industrial operator has from a legal obligation written in general terms to a set of controls specific enough to implement. NIS2 tells you that you must manage cybersecurity risk. It does not tell you what a zone is, how to assign a security level, or what evidence an assessor should see. IEC 62443 does.

This guide maps the ten measures in Article 21(2) to the requirements that satisfy them for an operational technology estate, covers incident reporting, and is explicit about what the mapping does and does not claim.

What this guide covers

NIS2 IEC 62443 explained
The ten Article 21(2) measures mapped to the IEC 62443 asset owner programme.

NIS2 IEC 62443: what the directive actually requires

Directive (EU) 2022/2555 obliges essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to their network and information systems, on an all-hazards basis. Article 21(2) lists ten measure categories as a minimum. Article 23 sets incident reporting timelines. Article 20 makes management bodies approve and oversee the measures, with personal liability attached. Fines reach at least €10,000,000 or 2% of total worldwide annual turnover for essential entities, whichever is higher, and at least €7,000,000 or 1.4% for important entities.

What Article 21 does not contain is a control set. That gap is what a NIS2 IEC 62443 mapping fills for anyone whose network and information systems include a plant.

The NIS2 IEC 62443 mapping, measure by measure

Each row shows the Article 21(2) measure and where the corresponding capability lives in the asset owner programme.

Article 21(2) Measure Where IEC 62443 addresses it
(a) Risk analysis and information system security policies Organisational programme element: security policy, risk management process, high-level and detailed IACS risk assessment, target security levels per zone
(b) Incident handling Event and incident management element: detection, classification by process consequence, response, forensics, lessons learned
(c) Business continuity, backup, disaster recovery, crisis management Availability element: backup and restoration of control system configurations, tested recovery, continuity of the process itself
(d) Supply chain security, including direct suppliers and service providers Service provider requirements in 2-4, procurement security specifications, supplier evidence obligations, product supplier assurance from 4-1 and 4-2
(e) Security in acquisition, development and maintenance, including vulnerability handling Component element: vulnerability monitoring, patch verification and testing, secure configuration, change control across the lifecycle
(f) Assessing the effectiveness of risk-management measures Maturity level scoring per requirement, internal audit, conformity evidence register, management review
(g) Basic cyber hygiene and cybersecurity training User and organisational elements: awareness, role-based competence for engineering and operations staff, training records
(h) Cryptography and encryption, where appropriate Data element: protection in transit and at rest, key management, with the “where appropriate” test applied against real control system constraints
(i) Human resources security, access control, asset management Asset inventory as the foundation of the programme, personnel screening, account management, authorisation enforcement per zone
(j) Multi-factor authentication, secured communications, emergency communications Network and user elements: MFA on remote and privileged access, conduit protection, out-of-band communication paths

Read down the right-hand column and the shape of the NIS2 IEC 62443 relationship is clear. Every Article 21(2) measure has a home. None of them has a home that is only about IT.

What the NIS2 IEC 62443 mapping does not claim

This is the part worth stating plainly, because plenty of marketing gets it wrong.

A NIS2 IEC 62443 mapping is not a compliance-equivalence claim. NIS2 is transposed into national law by each Member State, and it is national law you are compliant with — not a standard. A national authority assesses you against its own transposition, which may add requirements the standard does not contain.

There is no certificate that discharges the obligation. No accredited body issues a NIS2 certificate, and an IEC 62443 certificate does not function as one. What a certificate does is evidence the measures.

The scope boundaries differ. NIS2 covers your network and information systems as a whole, including corporate IT, cloud services and the systems supporting them. IEC 62443 covers the industrial automation and control system. For an operator, a NIS2 IEC 62443 mapping is a partial answer that needs an information security management system alongside it for everything outside the plant.

Governance sits outside the NIS2 IEC 62443 mapping entirely. Article 20 requires management bodies to approve the measures, oversee implementation and undergo training. That is a corporate governance act no standard performs for you.

Why the mapping is still worth building

Because a regulator, a customer or an insurer asking how you manage OT risk gets a far better answer from “here is our zone model, our target security levels, our maturity scores per requirement and the evidence behind them” than from a policy statement. The NIS2 IEC 62443 mapping turns an abstract legal duty into an auditable position, and Article 25 explicitly encourages the use of European and international standards for exactly this purpose.

Incident reporting: what NIS2 IEC 62443 alignment must add

Article 23 imposes timelines a standard-driven incident process will not produce on its own:

  • 24 hours from becoming aware — early warning to the CSIRT or competent authority, indicating where applicable whether the incident is suspected of being caused by unlawful or malicious acts, or could have a cross-border impact.
  • 72 hours from becoming aware — incident notification updating the early warning, with an initial assessment of severity and impact and, where available, indicators of compromise.
  • On request — an intermediate report on relevant status updates, whenever the CSIRT or competent authority asks for one.
  • One month after the 72-hour notification — not one month after the incident. The final report covers a detailed description including severity and impact, the type of threat or root cause likely to have triggered it, applied and ongoing mitigation measures, and any cross-border impact. Where the incident is still ongoing at that point, a progress report goes in instead and the final report follows within one month of the incident being handled.

Build these into the NIS2 IEC 62443 incident procedure as explicit decision points with named roles, because 24 hours is short and the clock starts at awareness. The specifically industrial problem is deciding what counts as significant when the impact is physical: a process trip, a batch loss, a safety system demand or an environmental release may all qualify, and that judgement should be pre-agreed with operations rather than made under time pressure.

The one exercise that finds the gap

Run a tabletop against a plant scenario and time the 24-hour decision. Most organisations discover the same three things: nobody is certain who makes the significance call at 3am, the plant’s operational record and the security team’s log are not correlated, and the contact route to the national CSIRT has never been tested. All three are cheap to fix once you have seen them.

Building a NIS2 IEC 62443 programme in sequence

  1. Confirm scope. Which legal entities are essential or important, in which Member States, and which of your sites sit inside them.
  2. Define the system under consideration and complete the asset inventory. Everything downstream depends on it.
  3. Partition into zones and conduits and assign target security levels.
  4. Run the risk assessment on an all-hazards basis, which satisfies Article 21(2)(a) and selects the requirements that apply to you.
  5. Complete an applicability statement across all 87 asset owner requirements, justifying every exclusion.
  6. Build the mapping — Article 21(2)(a)–(j) against requirements against evidence — as a maintained document, not a one-off exercise.
  7. Implement, operate and score maturity, then take the result to the management body for the Article 20 approval.

Step 6 is the artefact a supervisory authority actually engages with, and it is the one most programmes leave until last.

Frequently asked questions

Does IEC 62443 conformance make us NIS2 compliant?

No. It provides strong evidence for the OT portion of your Article 21(2) measures, which is genuinely valuable, but compliance is with the national law transposing the directive. Treat a NIS2 IEC 62443 mapping as your evidence base and your national transposition as the requirement.

We already hold ISO 27001. Do we need IEC 62443 as well?

If your scope includes an industrial plant, yes — and the two are complementary rather than competing. ISO 27001 gives you the management system, the risk process and the governance NIS2 expects. IEC 62443 gives you the OT-specific technical and process requirements that an information security management system scoped on corporate IT does not reach.

Which parts of the series matter for NIS2 IEC 62443 work?

As an operator, 2-1 is the one you are measured against, supported by 3-2 for partitioning and 3-3 for system requirements. Article 21(2)(d) on supply chain is where 2-4, 4-1 and 4-2 earn their place, because those are the parts you require evidence against from integrators and product suppliers.

How much of this applies to a small operator?

The measures are explicitly proportionate — Article 21(1) refers to the entity’s exposure to risk, its size, and the likelihood and severity of incidents. A small operator can meet the same measure categories with a much lighter programme. What is not proportionate is skipping the asset inventory or the risk assessment, because everything else derives from them.

Where to start with NIS2 IEC 62443

The design work comes before the mapping: zones and conduits first, then IEC 62443 security levels. Article 21(2)(e) is covered in practice by OT patch management, and (j) largely by OT secure remote access.

If you are weighing whether to seek assessment, IEC 62443 certification covers what is and is not certifiable. The directive text is on EUR-Lex, and the asset owner standard is IEC 62443-2-1:2024.

Our IEC 62443 Toolkit includes the applicability statement across all 87 requirements, the maturity assessment workbook, the conformity evidence register and the incident management procedure with the Article 23 timelines built in as decision points. Those four documents are the substance of a NIS2 IEC 62443 evidence base — and they are what turns “we take cybersecurity seriously” into something a supervisory authority can actually read.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.