NIS2 & OT/IIoT: Operating Your IoT Platform Securely and Compliantly (August 2026)
NIS2 & OT/IIoT: Operating Your IoT Platform Securely and Compliantly (August 2026)
NIS2 applies and the registration deadline has passed: what Section 30 BSIG demands of OT and IIoT, and which building blocks an IoT platform delivers.
Content notice: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, pricing, versions, licensing models and external content are subject to change. Please verify the information independently, especially before making business-critical or security-relevant decisions. This article does not constitute individual professional, legal or tax advice.
WZ-IT operates thingshost. Current hosting starts from €159.80 net/month; setup and service level follow the proposal. Former package prices, location lists and cost comparisons in this dated article describe the previous offer, not current WZ-IT terms. View current service scope.
Since August 1, 2026, there has been no buffer left for NIS2 registration: in a letter distributed via industry associations in mid-June, the German Federal Office for Information Security (BSI) made clear that it expects all outstanding registrations to be completed by July 31, 2026, and that date has now passed. According to industry reports, only around 18,500 of an estimated 29,500 expected entities were registered with the BSI by the end of May 2026; thousands of manufacturing companies are still missing, even though manufacturing is explicitly listed in Annex 2 of the new BSI Act (BSIG). For manufacturers, the harder part starts now: implementing the ten areas of measures from Section 30 BSIG in an environment where machines, sensors, and an IoT platform interact. This article clarifies who is in scope, what Section 30 specifically demands of OT and IIoT, and which building blocks a platform like ThingsBoard 4.3 can contribute: from enforceable 2FA and audit logs to a demonstrable patch status of the platform layer.
Note: This article is a technical and organizational assessment, not legal advice. Whether and how your company falls under NIS2 and the new BSIG should be clarified with qualified legal counsel; the BSI's self-assessment tool is the starting point.
Also worth reading: EU Data Act and IoT Platforms 2026 · ThingsBoard Hosting: Cloud vs. Self-Hosted vs. Managed
NIS2 Applies and the Deadlines Are Over: Where Manufacturers Stand Now
Germany transposed the European NIS2 Directive with its NIS2 Implementation and Cybersecurity Strengthening Act. Its centerpiece is the new BSI Act of December 2, 2025 (Federal Law Gazette, BGBl. 2025 I No. 301), which entered into force on December 6, 2025 [1]. That started a chain of deadlines many companies underestimated:
| Date | Event |
|---|---|
| December 6, 2025 | New BSIG in force (BGBl. 2025 I No. 301) [1] |
| March 6, 2026 | End of the statutory registration deadline: Section 33 BSIG requires registration at the latest three months after an entity first qualifies as a particularly important or important entity [2] |
| July 31, 2026 | Date from a BSI letter of June 2026: by then, the BSI expected all outstanding registrations; this was not a formal statutory extension [3] |
The interim tally is sobering. According to industry reports, only around 18,500 entities were registered by the end of May 2026, against an estimated 29,500 to 30,000 expected; both figures are estimates from advisory and association reporting, not official statistics [4]. The BSI itself states plainly on its topic page that the statutory registration deadline has already passed [5]. In mid-June 2026, the authority then made clear in a letter distributed via industry associations that it expects all outstanding registrations by July 31, 2026; this was reported among others by BDO and Solidaris [3][4]. No further extension is known.
What does that mean in practice? Anyone subject to registration who has not yet registered should do so now, because failure to register is a separate administrative offense with fines of up to EUR 500,000 [6]. More important still: registration is only the administrative act. The obligations under Section 30 BSIG have applied since the law entered into force regardless of registration, and for violations Section 65 BSIG provides caps of up to EUR 10 million for particularly important entities and up to EUR 7 million for important entities; the often-quoted revenue-based ranges of 2 and 1.4 percent only apply to entities with total revenue above EUR 500 million [6].
In Scope or Not? Manufacturing Is Listed in Annex 2
The most common misconception in manufacturing goes: "But we are not critical infrastructure." For NIS2, that is the wrong yardstick. Annex 2 of the BSIG explicitly lists manufacturing as its own sector of important entities: manufacturers of medical devices and in-vitro diagnostics as well as NACE divisions C 26 (computer, electronic and optical products), C 27 (electrical equipment), C 28 (machinery and equipment), C 29 (motor vehicles and parts), and C 30 (other transport equipment) [7].
Whether the size threshold is met is governed by Section 28 BSIG: an important entity generally exists from 50 employees, or when both annual revenue and the annual balance sheet total each exceed EUR 10 million. Particularly important entities start at 250 employees, or at annual revenue above EUR 50 million combined with a balance sheet total above EUR 43 million [8]. A machine builder with 80 employees is therefore, as a rule, an important entity, even if it has never seen a critical-infrastructure form.
Here too: classification in individual cases, for example with group structures or special rules, is legal territory. Use the BSI's self-assessment as the starting point [5] and have edge cases clarified by qualified legal counsel; this article is a technical assessment and does not replace legal advice.
The Ten Areas of Measures from Section 30 BSIG, Translated for OT and IIoT
Section 30 (1) BSIG requires suitable, proportionate, and effective technical and organizational measures; paragraph 2 specifies ten areas [9]: concepts for risk analysis and IT security, handling of security incidents, business continuity including backup and crisis management, supply chain security, security in acquisition, development, and maintenance including vulnerability management, assessment of effectiveness, cyber hygiene and training, cryptography and encryption, personnel security with access control and management of ICT assets, and multi-factor authentication and secured communication.
In OT, these requirements meet conditions that office IT does not know: machine controllers speak legacy protocols without authentication of their own, patch windows only exist during planned downtime, and the priority order is reversed, availability comes before confidentiality. That is exactly why implementation needs a translation layer: the IoT platform that consolidates machine and sensor data is the place where access control, logging, and patch status can be enforced and evidenced centrally, while the control layer remains untouched.
Two flanking obligations belong in every implementation project. First, the reporting cascade from Section 32 BSIG for significant security incidents: an early report without undue delay, at the latest 24 hours after becoming aware, an updated report at the latest after 72 hours, and a final report at the latest one month after the updated report [10]. Second, the management duties from Section 38 BSIG: management must implement the risk management measures and monitor their implementation, is liable to its own entity under corporate law rules in case of culpable breach, and must regularly attend training [11].
IEC 62443 as the Reference Framework for OT
NIS2 does not prescribe a specific standard. For translating the generic Section 30 requirements into industrial environments, however, the IEC 62443 series has become the established choice, recognized as a horizontal IEC standard since 2021 [12]. Its core concepts map precisely onto the OT problem: zones and conduits structure segmentation, security levels define graded requirements, and the parts of the series distribute responsibility, from 62443-2-1 (2024) for the operator's security program through 62443-3-3 (2013) for system requirements to 62443-4-1 and 62443-4-2 (both 2018) for secure development and components [12]. For platform architecture, that means in practice: the IoT platform sits at the boundary between OT and IT and belongs in its own zone; controllers are never exposed directly but deliver telemetry to the platform through defined conduits.
What an IoT Platform Can Contribute, and What It Cannot
The honest framing first: no IoT platform makes your company NIS2 compliant, managed or not. Risk analysis, security concepts, reporting processes, training, and supplier management are and remain organizational tasks. What a central platform can do: it delivers technical building blocks for part of the ten areas of measures that you would otherwise have to implement and evidence individually per machine and per isolated solution.
| Section 30 (2) BSIG (abridged) [9] | Contribution of the IoT platform | Remains an organizational task |
|---|---|---|
| 1. Risk analysis, security concepts | Central device inventory as the data basis | Risk analysis, concepts, ISMS |
| 2. Handling of security incidents | Alarm logic (Alarm Rules 2.0) [13], audit logs for forensics [15] | Incident response process, BSI report under Section 32 |
| 3. Business continuity, crisis management | Managed operations with monitoring; HA cluster with 99.99% SLA in the Enterprise plan [17] | Contingency plans, backup strategy, exercises |
| 4. Supply chain security | Open-source, auditable code; German contractual partner with a data processing agreement [17] | Supplier assessment, contracts |
| 5. Acquisition, development, maintenance, vulnerabilities | Managed updates and security patches; LTS release with support until at least July 2027 [14] | Patch processes for machines and edge, vulnerability management overall |
| 6. Effectiveness assessment | Audit logs via REST API, export to Elasticsearch [15] | Audits, KPIs, management review |
| 7. Cyber hygiene, training | Role concept reduces operating errors [16] | Training program |
| 8. Cryptography | TLS transport encryption, X.509 device authentication | Crypto concept, key management |
| 9. Access control, asset management | RBAC (CE: basic roles, PE: granular with deny-by-default) [16], central device and asset inventory | Joiner-mover-leaver processes |
| 10. MFA, secured communication | Enforceable 2FA, API keys instead of shared credentials [13] | Emergency communication, MFA beyond the platform |
One area deserves special attention in the platform question: the supply chain (no. 4). Your platform vendor itself becomes a supplier you must assess, and that includes its lifecycle risk. How real that is was shown by the AWS IoT retirements of 2025 and 2026; we documented the full list in AWS Is Trimming Its IoT Portfolio: The 2026 Retirement List. To stay factual: US hyperscalers can deliver NIS2 building blocks too, the assessment of their supply chain including third-country aspects is simply more involved than for a German provider with an open-source foundation.
ThingsBoard 4.3 in Concrete Terms: Enforcing 2FA, API Keys, Audit Logs, RBAC
ThingsBoard 4.3, released on January 20, 2026, brings exactly the functions auditors ask about first in IIoT environments: Enforced 2FA, with which administrators make two-factor authentication mandatory system-wide, API keys for token-based, individually revocable programmatic access instead of shared integration passwords, plus Alarm Rules 2.0 for alarm logic [13].
At least as important for evidencing is the existing feature set: audit logs are available in all editions, including the Community Edition. They record which user changed which entity and when, can be retrieved via the REST API, and can be fed into an existing log management setup with Elasticsearch as a sink [15]. Access control is where the editions diverge: Advanced RBAC with generic and group roles, user groups, and deny-by-default is reserved for the Professional Edition, while the Community Edition offers the basic roles Tenant Administrator and Customer User [16]. Whether the CE is enough for your role model or the PE is needed is broken down in ThingsBoard CE vs. PE 2026.
And the patch argument for Section 30 no. 5: the 4.3 line is an LTS release with support until at least July 2027, and the predecessor line 4.2 is already running as Maintenance LTS until February 15, 2027 [14]. The lifecycle of the platform layer is thus publicly documented in a release table, and it is precisely such documented support windows that turn "we patch regularly" into robust evidence.
Operating Model Under NIS2: Self-Hosted or Managed?
Self-hosting is entirely legitimate under NIS2 when three things come together: an ops team with Linux, database, and platform experience plus capacity for defined patch windows, OT security expertise with hardening and patch processes already anchored in the ISMS, and possibly hard requirements such as an air-gapped or on-premise obligation from customer contracts.
Managed hosting is the better-fitting building block when the area of acquisition, development, and maintenance (Section 30 no. 5) is to be fulfilled demonstrably without building a dedicated platform team, when a German contractual partner with a data processing agreement and hosting in Germany is desired for supply chain evidence, or when your IT team should focus on OT integration and processes rather than platform operations. The fundamental trade-off between vendor cloud, self-hosting, and managed hosting is covered in ThingsBoard Hosting: Cloud vs. Self-Hosted vs. Managed.
Important for context: with managed hosting you delegate work, not responsibility. The provider itself becomes part of your supply chain under Section 30 no. 4 and belongs in your supplier assessment; with a data processing agreement, a German location, and documented services, however, that assessment is considerably leaner than for a complex third-country setup.
thingshost operates dedicated ThingsBoard instances as a managed service with setup, updates, security patches, and monitoring, hosted in Germany by default: the Germany region runs in data centers with ISO 27001 and BSI C5 certification, the other regions with ISO 27001 and SOC 2 Type II; the certificates are held by the respective data center operators [17]. Standard (Community Edition) costs EUR 149.90 per month in the Germany region and EUR 169.90 per month in the other regions (plus VAT), Premium with an official PE license starts at EUR 249.90 per month, and Enterprise with an HA cluster and a 99.99% SLA is available on request; a data processing agreement is part of the package [17].
The honest counter-direction as well: if customer contracts require air-gapped operations without external connectivity, if you only need SCADA and control system functions without an IoT data platform, or if your compliance processes are already deeply established in a hyperscaler stack, switching is not automatically the right step; switching costs belong honestly in the calculation.
Roadmap for the Next 90 Days
- Clarify scope: Check sector (Annex 2) and thresholds (Section 28) and document the result; the BSI's self-assessment is the starting point, edge cases go to legal counsel [5].
- Catch up on or update registration: Register even after the passed dates; changes to registered details must be reported within two weeks [2].
- Build the asset inventory: Record machines, sensors, gateways, and data flows; the IoT platform's device registry provides the central data basis.
- Harden access: Make 2FA mandatory, assign roles on a need-to-know basis, switch integrations to API keys instead of shared credentials [13].
- Activate and connect audit logging: Feed logs into central log management via the REST API or the Elasticsearch export [15].
- Define the patch process: Adopt the platform's documented LTS roadmap into patch planning, or delegate the platform part to a managed operator [14].
- Rehearse the reporting process: Define owners and contact paths and dry-run the cascade of 24 hours, 72 hours, and one month [10].
- Involve management: Implementing and monitoring the measures is a leadership duty, regular training is mandatory [11].
New article: How to sort vulnerability findings in practice is shown by the 2026 ThingsBoard CVE list: one platform flaw, ten from dependencies.
Conclusion: Building Block, Not Checkbox
NIS2 is no longer a future topic for manufacturing: the BSIG has applied since December 2025 [1], the statutory registration deadline passed in March, and the end-of-July date communicated by the BSI has passed as well [3]. The real yardstick, however, is not registration but the demonstrable implementation of the ten areas of measures from Section 30 BSIG [9]. An IoT platform does not turn that into compliance, but it delivers solid building blocks: a central inventory, enforceable 2FA, audit logs, a clean role model, and a publicly documented patch roadmap. If you delegate operation of the platform layer including updates and monitoring to a German managed provider, you complete a clearly delineated part of the homework demonstrably; the rest remains organizational work, and that is exactly where your focus belongs. With the EU Data Act, the next piece of IoT regulation is already on the calendar.
Recommended reading: EU Data Act and IoT Platforms 2026 · ThingsBoard CE vs. PE 2026 · ThingsBoard Hosting: Cloud vs. Self-Hosted vs. Managed
Which operational evidence we provide for your instance, and which certifications are held by the data center operator, is set out on the ThingsBoard hosting in Germany page.
Sources
- BSI Act of December 2, 2025 (BGBl. 2025 I No. 301), header data and entry into force
- Section 33 BSIG, registration obligation
- BDO: NIS-2, BSI expects outstanding registrations by the end of July 2026
- Solidaris: BSI sets new date of July 31, 2026 for NIS-2 registration (registration figures)
- BSI: NIS-2-regulated companies (registration, self-assessment)
- Section 65 BSIG, fine provisions
- Annex 2 BSIG, sectors of important entities (manufacturing)
- Section 28 BSIG, particularly important and important entities (thresholds)
- Section 30 BSIG, risk management measures
- Section 32 BSIG, reporting obligations
- Section 38 BSIG, implementation, monitoring, and training duties of management
- ISA/IEC 62443 Series of Standards (parts, horizontal standard since 2021)
- ThingsBoard v4.3 release notes (Enforced 2FA, API keys, Alarm Rules 2.0)
- ThingsBoard releases overview (LTS roadmap, support windows)
- ThingsBoard audit log documentation (all editions, REST API, Elasticsearch sink)
- ThingsBoard PE: role based access control (Advanced RBAC, deny-by-default)
- thingshost.de, Managed ThingsBoard Hosting (pricing, regions, certifications)
Frequently Asked Questions
Does NIS2 also apply to manufacturing companies?▼
Which measures does Section 30 BSIG actually require?▼
The registration deadline has passed. What now?▼
What does IEC 62443 have to do with NIS2?▼
Does an IoT platform make my company NIS2 compliant?▼
Which NIS2-relevant security features does ThingsBoard 4.3 bring?▼
How does the platform help with asset management and logging?▼
Self-hosted or managed: which makes more sense in a NIS2 context?▼
What does Managed ThingsBoard at thingshost cost?▼
Do I get a data processing agreement and German hosting?▼
Written by
Timo Wevelsiep
Co-founder, WZ-IT
Founder of WZ-IT. Managed ThingsBoard IoT Platform hosting. Focused on IoT architecture, device management and scalable IoT infrastructure.
LinkedIn