
September 21, 2026
From EU Policy to the Plant Floor: What NIS2 and CER Mean for OT Resilience
Introduction
Critical infrastructure is becoming increasingly dependent on interconnected digital and operational technologies. Energy systems, transport networks, water infrastructure, manufacturing environments, and other essential services now rely on OT systems that must remain secure, available, and resilient under increasingly complex threat conditions.
At the same time, the European Union is strengthening its regulatory approach to cybersecurity and critical infrastructure resilience through frameworks such as the NIS2 Directive and the Critical Entities Resilience (CER) Directive. While both directives establish high-level requirements, their real impact is felt much closer to operations, where organisations must translate policy into practical controls, processes, and response capabilities.
For OT environments, compliance is therefore not only about documentation, reporting, or governance. It is also about whether organisations can detect disruption, understand its operational impact, respond safely, and continue delivering essential services. This raises a practical question for operators of critical infrastructure: how should EU cybersecurity and resilience requirements be implemented on the plant floor?

NIS2: Cybersecurity Becomes an Operational Requirement
NIS2 applies across a wide range of critical and important sectors, including energy, transport, drinking water, wastewater, healthcare, digital infrastructure, and manufacturing. Its cybersecurity risk-management requirements go beyond the deployment of security tools and include areas such as risk analysis, incident handling, business continuity, crisis management, supply-chain security, vulnerability management, access control, and asset management.
Many of these concepts are already well established in traditional IT environments, but their implementation can be significantly more complex in OT. A critical PLC cannot always be patched immediately, a production system cannot necessarily be isolated without understanding the physical consequences, and an engineering workstation may require privileged access to controllers as part of normal operations.
Applying NIS2 to OT therefore requires more than extending corporate IT controls into industrial networks. Security measures must also account for process availability, safety requirements, equipment dependencies, operational constraints, and the consequences that a security action could have on the physical environment.
CER Expands the Focus from Cybersecurity to Resilience
The CER Directive approaches critical infrastructure from a broader perspective by introducing an all-hazards approach to resilience. Rather than focusing only on cyber incidents, it also considers physical attacks, sabotage, natural disasters, accidents, and other disruptions that could affect the delivery of essential services.
For OT operators, this significantly expands the security conversation. An electricity substation, for example, could be disrupted by malware targeting an engineering workstation, compromised remote-access credentials, manipulation of a control system, communications failure, physical damage to equipment, loss of supporting infrastructure, or a coordinated cyber and physical attack.
Although the origin of each incident may differ, the operational objective remains similar: the organisation must identify the disruption, understand its impact on the process, and maintain or restore the essential service safely. This is where the CER perspective becomes particularly relevant to OT, because resilience depends on how well security, operations, engineering, and continuity planning work together.

Where NIS2 and CER Meet OT
NIS2 and CER should not be treated as completely separate compliance exercises. For critical-infrastructure operators, they address different parts of the same resilience problem, with NIS2 focusing on cybersecurity risk and CER focusing more broadly on the continuity and resilience of essential services.
OT is where these requirements become operational. Consider an industrial environment in which a PLC unexpectedly changes the state of a pump. From a cybersecurity perspective, the investigation may focus on who issued the command, whether the account was authorised, whether remote access was involved, whether network behaviour changed, and whether a vulnerability was exploited.
From an operational-resilience perspective, the organisation must also determine what process the pump supports, whether redundant equipment is available, whether the change creates a safety condition, which other systems depend on the pump, and how quickly the process must be restored. In OT, both perspectives are necessary because cyber risk and operational consequence are closely connected.
Visibility Is the Foundation
Effective OT security depends on understanding the environment in enough detail to identify what matters operationally. A simple asset inventory is not sufficient if it only records IP addresses, hostnames, or device vendors without showing how those assets relate to industrial processes.
A more useful model connects each asset with its function, process, network zone, dependencies, and operational criticality. Two identical industrial controllers may contain the same vulnerability, but their risk can be very different if one supports a laboratory environment while the other controls a critical production process.
The same principle applies to vulnerability prioritisation. A vulnerability should not be assessed only by its technical severity; its relevance also depends on where the affected asset sits and what process it supports.

This is why asset visibility, industrial-protocol monitoring, network analysis, and contextual risk assessment are important not only for cybersecurity, but also for resilience. They provide the operational context needed to prioritise risks and understand whether a technical security event could affect the delivery of an essential service.
Incident Response Must Understand the Physical Process
OT also changes the way incident response needs to be performed. In a traditional IT environment, isolating a compromised endpoint can often be an appropriate first response, but in an industrial environment, disconnecting equipment without understanding its function can cause additional disruption or create safety risks.
OT incident response therefore requires coordination between cybersecurity teams, engineers, and plant operators. An event such as unexpected PLC communication may need to be analysed alongside controller state, process variables, engineering activity, asset criticality, and physical conditions before the appropriate response can be determined.
The objective is not simply to generate more alerts or react faster. The objective is to determine whether a security event can affect a physical process and to respond in a way that reduces risk without unnecessarily disrupting operations.
Supply-Chain Risk Extends Into the Plant
Supply-chain security is another important area under NIS2, and it has particular significance in industrial environments. OT systems often depend on equipment manufacturers, system integrators, remote maintenance providers, specialised contractors, proprietary software, long-lived hardware, and third-party communication gateways.
A compromise involving one of these external parties can create a direct pathway into systems that control physical processes. As a result, the security boundary of an industrial organisation can no longer be viewed as ending at the internal network perimeter.
Third-party access, supplier dependencies, remote maintenance paths, and external communications must all be considered part of the organisation’s operational risk picture. In practice, this means that supplier security and OT resilience are increasingly interconnected.
From Compliance to Continuous Resilience
One of the main risks for organisations implementing NIS2 and CER is treating them primarily as documentation exercises. Policies, procedures, risk assessments, and reporting mechanisms are necessary, but critical infrastructure operates continuously and its security posture changes over time.
Assets are replaced, contractors connect to networks, firmware is updated, vulnerabilities are discovered, remote-access paths are created, and threat actors modify their techniques. A control framework that was accurate several months ago may no longer reflect the real operational environment.
For OT environments, resilience therefore needs to be continuous rather than static. Security teams need reliable visibility into what assets are operating, how they communicate, which systems support critical processes, what has changed, and whether those changes could affect an essential service.
Behavioural analytics and AI-assisted monitoring can support this process by correlating OT telemetry with asset, network, and process context. Their value is not simply in identifying anomalies, but in helping operators distinguish meaningful operational risks from normal industrial behaviour.
Bringing EU Policy to the Plant Floor
NIS2 and CER reflect a broader shift in the way Europe approaches critical infrastructure security. Cybersecurity, physical protection, operational continuity, and resilience are becoming increasingly connected, and OT environments sit at the centre of that convergence.
For operators of critical infrastructure, compliance will therefore depend on more than meeting a regulatory checklist. It will depend on whether organisations can understand their industrial environments, identify meaningful risks, detect abnormal behaviour, respond safely to incidents, and maintain the essential services that depend on those systems.
EU policy may define the resilience requirements at a regulatory level, but their effectiveness will ultimately be determined by how well they are implemented in real operational environments.
Conclusion
NIS2 and CER make it clear that compliance in critical infrastructure cannot remain a static, documentation-driven exercise. Organisations need continuous visibility into their OT environments, the ability to identify meaningful changes and anomalies, and enough operational context to understand whether a cybersecurity event could affect the continuity of an essential service.
This is where AICOT connects directly to the challenges discussed in this article. AICOT is developing an AI-powered cybersecurity platform specifically for Operational Technology and critical infrastructure, designed to support continuous monitoring of industrial environments through OT-specific machine learning, anomaly detection, protocol analysis, and security analytics. By correlating asset, network, and operational data, AICOT aims to help organisations identify abnormal behaviour, monitor changes in their OT environment, and provide the evidence and visibility needed to support ongoing cybersecurity and resilience activities aligned with frameworks such as NIS2 and CER.
Led by Logstail, the project builds on expertise in SIEM, data analytics, and security operations while extending these capabilities to the specific requirements and constraints of OT environments.
Follow the AICOT project on LinkedIn and X for project updates and practical insights into AI-driven OT cybersecurity.
AICOT is funded by the European Union’s Digital Europe Programme under Grant Agreement No. 101249826. Views expressed are those of the authors and do not necessarily represent the European Union or the European Cybersecurity Competence Centre.