NIS2 and connected robots: why cybersecurity is now a service obligation, not an IT footnote
The service layer is now a legal boundary
When a European manufacturer deploys a fleet of collaborative robots on a production line, the robots’ connectivity is not just a feature—it is an attack surface. Under the revised Network and Information Security Directive (NIS2, Directive (EU) 2022/2555), that surface is no longer a purely technical concern. For operators classified as essential or important entities, the directive imposes concrete obligations on risk management, incident reporting, and supply chain security. These obligations extend to the maintenance and patching of connected robots, because the service infrastructure that keeps them running is part of the ‘network and information systems’ that NIS2 protects.
The key shift is that cybersecurity is now a service obligation. A maintenance contract that only covers mechanical repairs is insufficient. It must include vulnerability management, timely patching, and incident response—because a compromised robot can disrupt production, exfiltrate data, or serve as a pivot to other systems. This article explains how NIS2 applies to connected robot fleets, what it means for maintenance and patching, and how it interacts with the Cyber Resilience Act (CRA).
NIS2: who is in scope and what is required
NIS2 entered into force on 16 January 2023, and EU member states had until 17 October 2024 to transpose it into national law. It replaces the original NIS Directive and expands the sectors and entities covered. The directive applies to ‘essential’ and ‘important’ entities across sectors such as energy, transport, banking, health, digital infrastructure, and manufacturing. For manufacturing, the directive covers ‘manufacture of basic metals’, ‘manufacture of electrical equipment’, ‘manufacture of machinery and equipment n.e.c.’, and ‘manufacture of motor vehicles, trailers and semi-trailers’, among others. If your company operates in these sectors and has 50 or more employees or an annual turnover exceeding €10 million, you are likely in scope as an important entity. Smaller companies may also be captured if they are the sole provider of a service that is critical for an essential entity.
The core obligations under NIS2 are set out in Article 21, which requires entities to take ‘appropriate and proportionate technical, operational and organisational measures’ to manage risks to their network and information systems. These measures must include:
- Policies on risk analysis and information system security
- Incident handling, including prevention, detection, and response
- Business continuity, such as backup management and disaster recovery
- Supply chain security, including security aspects of relationships with suppliers and service providers
- Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure
- Policies and procedures to assess the effectiveness of cybersecurity risk-management measures
- Basic cyber hygiene practices and cybersecurity training
- Cryptography and encryption where relevant
- Human resources security, access control, and asset management
- Use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems
These are not optional. The directive requires that measures be ‘appropriate and proportionate’—meaning they must be tailored to the risk profile, size, and sector of the entity. But the baseline is high. For a robot fleet operator, this means that the entire lifecycle of the robots—from procurement to decommissioning—must be considered from a cybersecurity perspective.
Connected robots: a concrete example of NIS2 in practice
Consider a mid-sized automotive parts manufacturer that uses a fleet of 40 collaborative robots (cobots) for assembly and welding. The cobots are connected to a local network, which also links to the company’s ERP system and to a cloud-based monitoring platform provided by the robot manufacturer. Under NIS2, this manufacturer is likely an important entity in the manufacturing sector. The cobots are part of its ‘network and information systems’, and the monitoring platform is a supply chain service.
What does NIS2 require in this scenario?
- Risk assessment: The manufacturer must conduct a risk analysis that includes the robots and their connectivity. This means identifying threats such as malware, unauthorized access, and denial-of-service attacks that could disrupt production.
- Incident response: The manufacturer must have a plan to detect, report, and respond to incidents. If a robot is compromised, the incident must be reported to the relevant national authority (CSIRT) within 24 hours of becoming aware, with an initial notification, and a final report within 72 hours.
- Supply chain security: The manufacturer must ensure that its robot supplier and maintenance provider also meet cybersecurity standards. This includes contractual clauses on security, and regular audits of the provider’s practices.
- Patching and maintenance: The manufacturer must have a process for applying security patches to the robots’ software and firmware. This is not just an IT task—it is a maintenance task that must be coordinated with production schedules.
The maintenance provider, whether internal or external, becomes a critical part of the cybersecurity chain. If the provider does not have a robust patching process, the manufacturer is non-compliant. This is why cybersecurity is now a service obligation: it must be embedded in the service level agreements (SLAs) for maintenance and support.
NIS2 vs. CRA: complementary but distinct
The Cyber Resilience Act (CRA) is a separate regulation that imposes cybersecurity requirements on products with digital elements, including robots. While NIS2 targets operators (the users of the technology), the CRA targets manufacturers (the producers of the technology). The CRA requires that products be designed and developed with security in mind, that they be free of known vulnerabilities, and that manufacturers provide security updates for a defined period. The CRA also introduces a ‘CE’ marking for cybersecurity, similar to other CE markings.
For a robot fleet operator, the CRA means that the robots they buy should be secure by design. But NIS2 means that the operator must also manage the risks associated with using those robots. The two regulations are complementary: the CRA ensures that the product has a baseline of security, while NIS2 ensures that the operator uses it securely.
| Aspect | NIS2 (Directive (EU) 2022/2555) | CRA (Regulation (EU) 2024/2847) |
|---|---|---|
| Primary target | Operators of essential/important entities (users) | Manufacturers of digital products (producers) |
| Legal nature | Directive, transposed into national law | Regulation, directly applicable in all EU states |
| Scope | Network and information systems of entities in critical sectors | All products with digital elements, including robots, IoT devices, software |
| Key obligations | Risk management, incident reporting, supply chain security | Security by design, vulnerability handling, security updates for a defined period |
| Enforcement | National authorities, penalties vary by member state | Market surveillance authorities, fines up to €15 million or 2.5% of global turnover |
| Relationship | Applies to the operator’s use of technology | Applies to the product’s inherent security |
For a service provider like a maintenance network, both regulations matter. The provider must ensure that the robots it services are patched and maintained in a way that meets NIS2 requirements for the operator, and it must also be aware of the CRA’s requirements on the manufacturer, because the provider may be involved in applying updates.
Maintenance and patching: the new frontline
Under NIS2, patching is not just a best practice—it is a legal obligation. Article 21 specifically mentions ‘vulnerability handling and disclosure’ as part of the required measures. This means that operators must have a process for identifying, assessing, and remediating vulnerabilities in their robots. For a fleet of robots, this is a significant operational challenge.
Robots are often deployed for years, and their software may become outdated. The manufacturer may release patches, but applying them requires downtime, which conflicts with production targets. NIS2 forces operators to balance these priorities. The directive does not prescribe a specific patching frequency, but it requires that measures be ‘appropriate and proportionate’ to the risk. A robot that is exposed to the internet or to a wide network will need more frequent patching than one that is isolated.
Maintenance contracts must now include:
- Regular vulnerability scanning and assessment
- Defined service windows for patching, with minimal production disruption
- Clear escalation paths for critical vulnerabilities
- Documentation of all patching activities, for compliance audits
- Coordination with the robot manufacturer to ensure patches are available and validated
For a service network like Robanchor—a local service network being set up to support Chinese robotics manufacturers in Europe—this is a core value proposition. The network can provide certified technicians who are trained not only in mechanical repair but also in cybersecurity hygiene. They can ensure that patches are applied correctly and that the robot’s configuration is secure. This is a differentiator in a market where many maintenance providers are still focused on hardware.
Incident reporting: a new operational reality
NIS2 introduces strict incident reporting requirements. Article 23 requires essential and important entities to notify their CSIRT (Computer Security Incident Response Team) of any incident that has a significant impact on the provision of their services. The notification must be made without undue delay, and in any case within 24 hours of becoming aware of the incident, with an initial notification. A final report is due within 72 hours, and a detailed final report within one month.
For a robot fleet operator, this means that a cyber incident that disrupts production must be reported to the national authority. This is a significant change from the past, where such incidents might have been handled internally. It also means that the operator must have the ability to detect incidents quickly, which requires monitoring and logging on the robots and their network.
Service providers must be prepared to support this reporting process. They need to have incident response plans that include notifying the operator’s designated contact, and they must be able to provide forensic data to help with the investigation. The service contract should specify the roles and responsibilities of each party in the event of an incident.
Practical steps for operators and service providers
To comply with NIS2, operators of connected robot fleets should take the following steps:
- Identify your status: Determine if you are an essential or important entity under NIS2. This depends on your sector and size. If you are in scope, you must comply.
- Conduct a risk assessment: Map your robot fleet, its connectivity, and its dependencies. Identify potential threats and vulnerabilities.
- Implement security measures: Based on the risk assessment, put in place the technical and organizational measures required by Article 21. This includes access control, network segmentation, and patching processes.
- Review your supply chain: Ensure that your robot manufacturer and maintenance providers meet cybersecurity standards. Include security requirements in your contracts.
- Develop an incident response plan: Define how you will detect, report, and respond to incidents. Ensure that your service providers are integrated into this plan.
- Train your staff: Cybersecurity awareness is not just for IT. Operators, maintenance technicians, and managers should all understand the risks and their roles.
For service providers, the opportunity is to become a trusted cybersecurity partner. This requires investing in training, tools, and processes. It also requires a deep understanding of the regulatory landscape, which is still evolving. The NIS2 directive is being transposed into national laws, and there may be differences in how member states implement it. Service providers should monitor these developments and adapt their offerings accordingly.
Conclusion
NIS2 has turned cybersecurity from an IT footnote into a board-level obligation. For operators of connected robot fleets, this means that maintenance and patching are no longer optional extras—they are legal requirements. The service layer is now a critical part of the security posture. A service network that can provide not only mechanical expertise but also cybersecurity support will be invaluable in this new landscape. As the European market for robotics grows, the demand for such services will only increase. The time to prepare is now.
Sources
- EUR-Lex — Directive (EU) 2022/2555 (NIS2) — https://eur-lex.europa.eu/eli/dir/2022/2555/oj (accessed 2025-10-10)
- European Commission — Cybersecurity policies — https://digital-strategy.ec.europa.eu/ (accessed 2025-10-10)
