NIS2 Food Industry Checklist: Annex II Exclusion Test, HACCP Evidence Mapping, and Article 21 Requirements
Most food businesses that fall under NIS2 discovered their scope status reactively — through a national competent authority communication, a sector trade body alert, or a peer’s compliance project. The Annex II food sector definition is narrower than most compliance teams expect: the restriction to “wholesale distribution and industrial production and processing” excludes several major activity categories from scope entirely.
This checklist resolves that question first. The opening section provides a four-category exclusion test derived directly from the Annex II text and guidance published by the Finnish Food Authority — one of the first national competent authorities to publish detailed food-sector scope guidance [1]. If your activities are excluded, the directive does not apply to you.
If you are in scope, the checklist addresses three practical problems: how existing HACCP food safety documentation can reduce the effort of building Article 21(2)(a) risk analysis evidence; what documentation each of the ten Article 21 measures requires from food operators specifically; and what registration and incident reporting obligations you face under national enforcement.
NIS2 Annex II: The Fast Exclusion Test for Food Businesses
The NIS2 food sector sits in Annex II of Directive (EU) 2022/2555 as Sector 4: “Production, processing and distribution of food.” The entity definition is precise: food businesses as defined in Article 3(2) of Regulation (EC) No 178/2002 which are engaged in wholesale distribution and industrial production and processing [3].
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Regulation 178/2002 Article 3(2) defines “food business” broadly — any undertaking carrying out activities at any stage of food production, processing, or distribution. Annex II restricts NIS2 coverage to those businesses engaged in two specific activity types: wholesale distribution, and industrial production and processing. That restriction creates a fast exclusion test.
Five Activity Categories Outside NIS2 Scope
| Activity | In NIS2 Scope? | Basis for Exclusion |
|---|---|---|
| Primary production (farming, growing, harvesting, aquaculture) | No — excluded | Falls outside the Annex II restriction to wholesale distribution and industrial production/processing. Primary production is a distinct activity category not referenced in the Annex II food sector entry [1][3] |
| Animal feed production | No — excluded | Feed businesses do not qualify as food businesses under Regulation (EC) No 178/2002 for the purposes of Annex II. Feed is regulated separately under Regulation (EC) No 183/2005 [1] |
| Retail trade (supermarkets, grocers, farm shops, direct-to-consumer sales) | No — excluded | Retail is end-consumer sales, not wholesale distribution. The two activity types are distinct for scope purposes [1] |
| Food service and catering (restaurants, canteens, caterers, food delivery services) | No — excluded | Catering and food service operations are neither wholesale distribution nor industrial production or processing [1] |
| Storage and transport services only (no wholesale distribution or processing activity) | No — excluded | Stand-alone logistics and warehousing without a wholesale distribution or industrial production function is excluded from the Annex II definition [1] |
Who is in scope under Annex II:
- Industrial-scale food processors (factories and large-scale manufacturing plants — meat, dairy, bakery, ready meals, beverages, food ingredients)
- Wholesale food distributors (large-scale warehousing, import/export operations, supply to retail chains and foodservice operators)
- Cold chain operators conducting wholesale distribution of food products
- Food ingredient and additive manufacturers operating at industrial scale
The activity test applies at the entity level, not the product level. A company that primarily retails but also operates a separate wholesale distribution centre is assessed on whether wholesale distribution constitutes a primary economic activity of the entity — not a minor ancillary function.
One important exception: national competent authorities may designate smaller operators as critical operators regardless of these category rules, where their disruption would pose significant public health risks, create cross-border systemic effects, or where they are the sole provider of essential services in their territory [4]. Check your national competent authority’s published sector guidance for member-state-specific critical operator criteria.
Size Thresholds and the Linked Enterprises Trap for Food Groups
Food businesses that pass the Annex II activity test must also meet size thresholds under Article 2(1) of Directive 2022/2555 [4]. The baseline: entities that qualify as medium-sized enterprises — defined as 50 or more employees or annual turnover and balance sheet total each exceeding €10 million — are in scope. Entities below both thresholds are outside NIS2 scope unless designated critical operators.
Size Calculation for Corporate Groups
For food companies operating as part of a corporate group, size thresholds are not assessed on a standalone entity basis. Commission Recommendation 2003/361/EC — referenced by NIS2 for enterprise classification — creates two consolidation rules that routinely catch food subsidiaries that appear SME-exempt in isolation [5]:
- Linked enterprises (parent ownership ≥50%): the subsidiary must fully consolidate headcount and financial data with the parent and all other linked entities in the group.
- Partner enterprises (ownership between 25% and 50%): a proportionate share of the partner entity’s headcount and financials is added to the entity’s own figures.
In practice: a food processing subsidiary with 40 employees appears below the 50-employee medium enterprise threshold when assessed alone. If its parent company holds a majority stake and the group employs 900 people, the subsidiary’s consolidated employee count exceeds the medium enterprise ceiling. That subsidiary is in scope — even though its standalone headcount would have kept it outside NIS2 [5].
Every operating subsidiary in a food group that conducts wholesale distribution or industrial processing must assess its consolidated size, not its standalone figures. Where multiple subsidiaries in different EU member states qualify individually, each legal entity registers with its own national competent authority and manages compliance obligations separately — a single group-level registration does not satisfy the directive’s per-entity requirements.
A limited exception applies in some member states: entities operating genuinely independent network and information systems — not sharing IT infrastructure, systems, or services with the parent or sibling entities — may be assessed on standalone size figures under the enterprise independence provisions in Commission Recommendation 2003/361/EC. National implementations vary on whether and how this carve-out is available; consult your NCA’s published guidance before relying on it [5].
For a complete guide to scope determination under Article 2, including the critical operator designation process, see the NIS2 scope determination guide.
Your HACCP System as Article 21(2)(a) Evidence — The Dual-Use Opportunity
Article 21(2)(a) of Directive 2022/2555 requires entities to implement “policies on risk analysis and information system security” [2]. This is the foundational measure of NIS2’s security framework — the documented risk analysis process from which all other Article 21 controls flow. During a supervisory inspection, an auditor reviewing your Art.21(2)(a) compliance expects a documented methodology for identifying risks, assessing severity and likelihood, and determining treatment.
Food businesses operating under HACCP — Hazard Analysis and Critical Control Points, required by EU food hygiene legislation for most food operators — already maintain a structured, documented risk analysis system. The structural parallel between HACCP methodology and the Article 21(2)(a) all-hazards analysis is direct:
| HACCP Element | Article 21(2)(a) Equivalent |
|---|---|
| Hazard identification across the production process | Cyber asset and threat identification across the information system boundary |
| Severity and likelihood matrix for each identified hazard | Impact and likelihood scoring for each identified cyber risk |
| Critical Control Points (CCPs) with defined monitoring procedures | Key security controls with defined monitoring and alerting procedures |
| Corrective action procedures for CCP deviations | Incident response and remediation workflow for security control failures |
| Verification and periodic review schedule | Effectiveness assessment policy (Art.21(2)(f)) and periodic risk review |
| HACCP team with defined roles and sign-off authority | Cybersecurity risk ownership structure with RACI matrix |
Three specific ways HACCP documentation supports NIS2 compliance:
1. Methodology transfer. The HACCP severity × likelihood scoring approach can be adopted as the documented basis for cybersecurity risk assessments. This satisfies the “policies on risk analysis” component of Art.21(2)(a) and provides an auditable, consistent methodology — one already embedded in operational culture rather than built from scratch for regulatory compliance.
2. Document discipline as evidence. HACCP systems generate version-controlled records, review schedules, and team sign-offs. Applying the same document control discipline to cybersecurity policies and risk treatment plans satisfies the documentation, review, and verification components that NIS2 supervisors expect under Article 21(2)(a) and 21(2)(f). An organisation that maintains rigorous HACCP records is already operating at the documentation discipline level NIS2 requires — the task is extending that discipline to the cybersecurity domain.
3. Audit posture. Presenting HACCP records alongside cybersecurity policies demonstrates to national competent authorities that the organisation has an established culture of systematic, documented risk management. This context can support the credibility of an Art.21(2)(a) submission — particularly where the cybersecurity programme is still maturing and the procedural documentation is less extensive than a long-established IT security operation would produce.
The important limit: HACCP covers biological, chemical, and physical food safety hazards. Article 21(2)(a) requires information security risk analysis — a distinct domain. HACCP records do not satisfy Art.21(2)(a) on their own. What they provide is a proven methodology framework and a documented evidence culture that reduces the effort of building NIS2 cybersecurity documentation from scratch. The output — a cyber risk assessment addressing information systems, cyber threats, and security controls — must still be produced independently. HACCP records inform its structure, not its content.
For a risk assessment framework aligned with Article 21(2)(a) requirements, see the NIS2 risk assessment guide and the food sector risk management guide.
The Article 21 Compliance Checklist for Food Operators
Food sector entities under Annex II are classified as Important entities. Article 21(1) requires measures that are “appropriate and proportionate” to the risk exposure of the specific entity — not a prescriptive minimum floor that applies uniformly to all [2]. The CIR 2024/2690 implementing regulation provides additional technical specifics for Important entities at the higher end of the risk scale.
The checklist below identifies, per measure, the documentation NIS2 supervisory authorities expect during inspections or investigations, and the food-sector considerations that distinguish a food operator’s compliance from a generic IT-sector implementation.
| Art. 21(2) | Measure | Evidence Required | Food-Sector Consideration |
|---|---|---|---|
| (a) | Risk analysis and information system security | Information security policy; risk assessment methodology; IT and OT asset register; risk treatment plan with owner assignments | Include OT and ERP system assets in scope — not only office IT. HACCP methodology provides a structural template for the risk analysis approach (see Section 3 above) |
| (b) | Incident handling | Incident handling policy; incident response procedures; incident log template; defined escalation paths and role responsibilities | Production-line disruption scenarios must be explicitly included — ransomware stopping a filling, packaging, or cold chain line has different recovery priority and timeline than email downtime. See the food sector incident response guide |
| (c) | Business continuity, backup management, disaster recovery, and crisis management | Business continuity plan (BCP); backup policy with test logs; disaster recovery plan (DRP); crisis management plan; documented RTO and RPO targets per system category | Define separate RTO and RPO targets for ERP systems (order management, supply chain) versus OT and SCADA systems (production control, cold chain monitoring). A generic IT recovery plan that does not address production continuity will not satisfy Art.21(2)(c) for a food manufacturing entity |
| (d) | Supply chain security | Supply chain security policy; security clauses in supplier contracts; supplier self-assessment questionnaires or audit records; supplier directory with risk tier classification | Raw material suppliers with digital interfaces — temperature monitoring portals, traceability APIs, EDI ordering connections — fall within the scope of Art.21(2)(d) supplier assessment. See the food supply chain security guide |
| (e) | Security in network and information systems acquisition, development, and maintenance | Vulnerability management policy; patch management schedule and records; ICT acquisition security requirements; documented risk acceptance decisions for systems that cannot be patched | Legacy SCADA and OT systems (PLCs, HMIs, historian software) common in food processing often cannot be patched on a standard cycle. Each unpatched system needs documented risk acceptance with compensating controls specified — network segmentation, enhanced monitoring, restricted access. Undocumented risk acceptance is itself an audit finding |
| (f) | Policies and procedures to assess effectiveness of cybersecurity risk-management measures | Internal audit plan and completed audit reports; KPI measurement methodology; management review minutes documenting cybersecurity performance review | Board briefing packs documenting cybersecurity KPIs and control testing results satisfy both Art.21(2)(f) and the management accountability obligation under Art.20, which requires management bodies to oversee and be responsible for NIS2 compliance |
| (g) | Cyber hygiene practices and cybersecurity training | Cyber hygiene policy; training programme with schedule; attendance and completion records; role-specific awareness materials | Production floor staff and OT engineers require separate training content from office staff. Role-specific training — covering physical media handling, remote access discipline, and social engineering targeting operational staff — is more auditable and more effective than a single generic eLearning module applied across all roles |
| (h) | Cryptography and encryption | Cryptography policy; evidence of encryption implementation on critical data in storage and in transit; documented exceptions where encryption is not applied and the risk basis for those exceptions | Production-critical data — product recipes, process parameters, quality control thresholds, formulations — warrants encryption at rest and in transit. The business sensitivity of this data typically exceeds standard IT data classification, making encryption a proportionate measure regardless of system age |
| (i) | Human resources security, access control, and asset management | HR security policy; access control policy; IT and OT asset register; documented onboarding and offboarding procedures including access rights management | Temporary and seasonal staff are common in food production. Onboarding and offboarding access procedures must be designed to work at the pace of high staff turnover — documented processes that function in principle but fail at volume are an operational risk and produce an audit gap at the next inspection cycle |
| (j) | Multi-factor authentication and secured communications | Authentication policy specifying MFA scope and requirements; evidence of MFA implementation on critical systems; secure communications policy | Remote access to SCADA, OT control systems, and cold chain monitoring platforms is the primary attack vector for food processing entities. MFA must cover all remote administrative access to production systems — not only corporate IT access. VPN access without MFA does not satisfy Art.21(2)(j) for remote OT connectivity |
For guidance on incident handling procedures and the 72-hour notification timeline under Art.21(2)(b), see the Article 23 incident notification guide.
Registration Deadlines, Incident Reporting, and Enforcement Exposure
Food sector entities confirmed in NIS2 scope face three immediate administrative obligations distinct from the Article 21 technical measures.
NCA Registration
Entities must self-register with the national competent authority (NCA) in each EU member state where they operate. Registration timelines vary by national transposition. The Finnish Food Authority — designated as the NIS2 competent authority for the food sector in Finland — required food sector entities to complete registration by 8 May 2025 [1]. Other member states transposed on comparable timelines, with enforcement proceeding in those jurisdictions.
Registration typically requires: legal entity name and registration details, sector classification (Important entity, Annex II, food sector), a designated contact for cybersecurity incident communication, and confirmation of in-scope activities. For entity registration guidance across member states, see the NIS2 entity registration guide.
Incident Reporting Under Article 23
Significant cybersecurity incidents must be reported to the NCA under Article 23 of Directive 2022/2555. The reporting timeline operates in four stages [1][2]:
- Early warning: within 24 hours of first becoming aware of the incident
- Full notification: within 72 hours, including an initial assessment of severity, impact, and indicators of compromise
- Intermediate report: provided on request from the NCA
- Final report: within one month of the full notification, including root cause analysis and remediation steps taken
For food operators, a significant incident typically includes events causing substantial disruption to production continuity, compromising the integrity of production or supply chain data at scale, or involving unauthorised access to systems controlling physical production processes. The 24-hour early warning obligation runs from the moment of awareness — not from the completion of an internal investigation. Delay in reporting while awaiting full forensic analysis is a compliance breach in itself.
For food-sector incident response procedures aligned with Article 23, see the food incident response guide and the incident reporting guide.
Enforcement Exposure
Important entities under Annex II — which includes the food sector — face administrative fines of up to €7,000,000 or 1.4% of total worldwide annual turnover for the preceding financial year, whichever is higher, for breaches of Articles 21 or 23 [6]. This is the minimum ceiling member states must provide under Article 34(5); individual member states may set higher maximum fines in their national transposition.
Management bodies are personally accountable under Article 20 of the Directive, which requires management to approve and oversee cybersecurity risk-management measures and to receive cybersecurity training. This is a material change from most national NIS1 implementations, where liability resided with the organisation rather than individual executives.
Supervisory activity in early-transposing member states has advanced from initial registration audits to substantive compliance inspections. Entities that have not yet begun Article 21 documentation work face both a compliance risk and a registration compliance gap that is increasingly visible to regulators.
Frequently Asked Questions
Does NIS2 apply to a farm that also operates an on-site processing unit?
Primary production — farming, growing, harvesting — is excluded from Annex II. However, if the farm also operates an industrial-scale processing facility that sells wholesale to retailers or distributors, the processing and distribution activities are assessed independently of the farming operation. The activity test applies per activity type. If the consolidated entity meets size thresholds and the processing and wholesale functions qualify under Annex II, NIS2 obligations apply to those operations. A legal assessment of specific activities and corporate structure is recommended for mixed-activity entities.
Our food group has subsidiaries across three EU member states. Do we file one registration?
No. Each legal entity registers separately with the national competent authority in its member state of operation. Group-level cybersecurity policies, risk assessments, and documentation frameworks can and should be shared and adapted across subsidiaries for efficiency and consistency. But registration, incident reporting, and enforcement are per-legal entity in each jurisdiction. A parent company’s registration in one member state does not cover its subsidiaries operating in other member states.
We are ISO 22000-certified. Does that reduce our NIS2 documentation workload?
ISO 22000 governs food safety management systems — not information security. The two standards share structural discipline: documented risk processes, management review, internal audit, and corrective action workflows. ISO 22000 certification demonstrates that your organisation is accustomed to audit-ready, document-controlled management, and that foundation can reduce the effort required to build NIS2-compliant documentation. But ISO 22000 does not substitute for any Article 21 measure. NIS2 requires cybersecurity-specific risk analysis, incident handling procedures, and technical controls that fall entirely outside ISO 22000’s scope.
What is the difference between an Essential and an Important entity for food companies?
Food sector entities under Annex II are classified as Important entities — not Essential entities (Annex I). The Article 21 compliance obligations are the same in category for both classifications, but Important entities are subject to ex post supervision — triggered by evidence of a breach or by complaint — rather than the proactive ex ante oversight applied to Essential entities. Penalty ceilings also differ: up to €7M or 1.4% of global annual turnover for Important entities under Article 34(5), versus up to €10M or 2% for Essential entities under Article 34(4) [6].
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Finnish Food Authority — “Cybersecurity Directive (NIS2) in the food industry” — ruokavirasto.fi
- Directive (EU) 2022/2555 (NIS2), Article 21 — nis2resources.eu
- Directive (EU) 2022/2555 (NIS2), Annex II — streamlex.eu
- Directive (EU) 2022/2555 (NIS2), Article 2 — nis2resources.eu
- Arthur Cox LLP — “NIS2 & SME guidelines: How do they apply and thresholds” — arthurcox.com
- Directive (EU) 2022/2555 (NIS2), Article 34 — nis2resources.eu
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
