INDUSTRY · Energy
Energy: NIS2, critical infrastructure and connected equipment
Energy combines the heaviest NIS2 operator obligations with full CRA exposure for the connected equipment that increasingly makes up grid infrastructure.
LAST REVIEWED
Regulatory picture
NIS2 lists energy among its 'essential entities' sectors, covering electricity, district heating and cooling, oil, gas and hydrogen, with correspondingly strict risk management and incident reporting obligations and a higher level of supervisory scrutiny than 'important entities' sectors. Energy operators typically also work within sector-specific technical frameworks such as IEC 62443 for operational technology security and IEC 61850 for substation automation communication. Connected equipment manufacturers — smart meter vendors, grid automation equipment suppliers, inverter and battery management system manufacturers — fall within CRA scope as manufacturers of products with digital elements, with no general sector exclusion. Functional safety for energy infrastructure typically follows IEC 61508 and sector derivatives, with additional national grid codes and technical connection requirements layered on top.
Typical engineering challenges
- Securing operational technology (OT) environments that were historically air-gapped and are now increasingly connected for remote monitoring and demand response.
- Meeting NIS2's stricter supervisory regime as an essential entity, including proactive audits rather than only reactive enforcement.
- Managing vulnerability handling and update deployment for distributed field equipment such as smart meters and grid sensors, often numbering in the millions per operator.
- Coordinating cybersecurity risk assessment across IT and OT domains that have historically used different tools, vocabularies and risk tolerances.
- Aligning CRA manufacturer obligations for grid equipment vendors with the operator-level NIS2 obligations of the utilities that deploy that equipment.
How CRA interacts with sector rules
An energy utility operating as a NIS2 essential entity depends heavily on the CRA compliance of the equipment it procures: a utility's own incident response capability is only as good as the vulnerability disclosure and patch support commitments its equipment vendors provide under their CRA obligations. Procurement specifications for grid equipment increasingly reference CRA-equivalent evidence — technical documentation, vulnerability handling processes, defined support periods — as a proxy for supplier trustworthiness, independent of whether the specific product falls under the CRA's stricter Annex III or IV categories.
What a typical engagement covers
- NIS2 risk management measure gap assessment for energy operators against essential-entity obligations.
- CRA scoping and conformity route determination for grid, metering and control equipment manufacturers.
- IT/OT security risk assessment integration using IEC 62443 as the operational technology framework.
- Vulnerability handling and update deployment process design for large distributed field equipment fleets.
Frequently asked questions
Is the energy sector 'essential' or 'important' under NIS2?
Energy is listed among NIS2's 'essential entities' sectors, alongside transport, banking, health and digital infrastructure, which carry stricter supervisory obligations, including proactive audits, compared with the 'important entities' sectors.
Do smart meters fall under the CRA?
Smart meters are products with digital elements and generally fall within CRA scope as manufactured products, subject to the manufacturer meeting the essential requirements and appropriate conformity assessment route based on the meter's specific classification.
How does OT security differ from IT security in energy infrastructure?
Operational technology environments prioritise availability and safety continuity over confidentiality, often run on long equipment lifecycles with limited patching windows, and require security measures, such as those in IEC 62443, that account for real-time control requirements not present in typical IT environments.
Does a utility's NIS2 compliance depend on its equipment suppliers?
Yes, in practice. NIS2 requires operators to manage supply chain cybersecurity risk, meaning a utility's overall risk posture depends on the security practices, vulnerability handling and support commitments of the equipment vendors whose products form its infrastructure.