Defence & Security · Open-access guide

Does NIS2 apply to a defence manufacturer or supplier?

Determine NIS2 exposure by legal entity, activity, size and national rules, separating direct obligations from security requirements imposed by customers.

Stroncature Research · Sources checked · Editorial method

A defence manufacturer or supplier can fall within NIS2, depending on its legal entity, activities, sector, size and national rules. There is no standalone defence-industry category or blanket exemption for private suppliers. Customer security clauses can apply outside direct scope; supplying defence does not by itself make a company directly regulated.

Activity, sector and size tests

The assessment begins with the legal entity and the activities it actually carries out. The NIS2 Directive lists sectors and entity types in two annexes. The defence label used in a company presentation is not one of those tests. A group may contain manufacturing, managed-service and infrastructure businesses with different routes into scope. Treating the whole group as one undifferentiated defence supplier can obscure both a regulated activity and a genuinely separate entity.

Manufacturing is an important route, but it is bounded. Annex II includes computer, electronic and optical products, electrical equipment, machinery, motor vehicles and other transport equipment through specified NACE Rev. 2 divisions. A defence electronics manufacturer therefore needs to examine its classification directly. The existence of these categories does not mean every company making a defence product is included. Other listed sectors, such as chemicals, may also require assessment where the actual activity fits them.

Size is a separate test. The Commission’s NIS2 overview describes medium-sized and large entities in the covered sectors as the general rule, with exceptions. The applicable SME framework can require consideration of linked and partner enterprises, so counting staff at one small subsidiary may not settle the question. Certain entity types and nationally identified critical entities can be covered regardless of size. A scope file should record the calculation and the legal route, not merely attach an SME label.

Defence exemptions and national implementation

The defence-related provisions need particularly careful treatment. Article 2 excludes specified public administration activities and permits Member States to exempt particular entities from risk-management or reporting obligations for defined security or defence activities or services. This is not automatic exclusion of private defence industry. A company relying on an exemption needs its national legal basis and the activities it actually covers. Mixed civilian and defence operations should not be assumed to share an exemption simply because they belong to the same corporate group.

National implementation makes the conclusion operational. The relevant law, competent authority, registration process and any identification or exemption decision must be checked in the country concerned. The EU transposition deadline does not prove that all national procedures are identical or that each country has completed the same legislative steps. As checked on 28 September 2026, the Commission's policy page also describes targeted EU amendments as a proposal. A proposed simplification should not be applied as though it already changed a company's obligations.

Customer clauses and applicable technical guidance

Direct scope and contractual exposure then need separate treatment. Article 21 requires covered entities to address security in relationships with direct suppliers and service providers. A prime may consequently ask a smaller supplier for incident procedures, access controls, assurance evidence or audit rights. Those contractual demands can have real cost and commercial consequences even when the supplier is outside direct scope. They do not, by themselves, make the supplier an essential or important entity under NIS2.

The detailed control source also matters. ENISA’s technical implementation guidance supports the implementing regulation for specified digital infrastructure, ICT service management and digital-provider categories. It is useful evidence guidance within that scope. Its technical annex should not automatically be described as the directly applicable EU rulebook for every manufacturer. Manufacturing obligations require the directive's risk-management framework and the relevant national measures to be read together, alongside any customer requirements.

The useful output is a dated conclusion for each relevant entity. It should explain the activity classification, size assessment, applicable inclusion or exemption route and any unresolved authority question. From there, the company can assign governance, risk-management and incident responsibilities appropriate to its actual position. Programme security and funding eligibility remain separate assessments: a NIS2 compliance file can contribute evidence, but it does not establish an EDF or EDIP participation entitlement or replace classified-information approvals.

Email newsletter

Defence Finance Monitor

Defence Finance Monitor examines how cyber rules affect European defence companies and their suppliers. Continuing coverage helps advisers assess the consequences for governance, customer contracts, procurement and industrial participation.

Sign up for the free newsletter

Newsletter sign-up is free. Access to paid reports depends on the subscription selected.

About this publication