35-Item NIS2 Checklist for Waste Processors: Scope Confirmation, SCADA OT Controls, Smart Waste IoT, and WEEE Asset Tracking Under Annex II
If your waste company employs 50 or more people or exceeds €10 million annual turnover, the NIS2 Directive (EU) 2022/2555 classifies your organisation as an important entity under Annex II, Section 2 — and national transposition across EU member states means enforcement is already live.
The compliance picture for waste operators is more complex than most NIS2 guides acknowledge. A waste business has operational technology assets — SCADA-controlled combustion systems at waste-to-energy plants, GPS-equipped collection fleets, connected bin sensors, weighbridge control systems — that fall under Article 21 obligations but cannot be addressed with standard IT security policies. There are also parallel digital obligations under the WEEE Directive (2012/19/EU) that intersect directly with NIS2 asset management requirements.
This checklist covers 35 controls where waste operators most commonly have gaps. Start with the scope confirmation section: many companies in adjacent sectors assume they are in scope (or out) without working through the principal activity test first. The checklist then covers asset inventory, SCADA and OT controls, smart waste IoT fleet security, WEEE digital tracking, and the governance obligations that bind your management body directly.
Are You Actually In Scope? The Processor vs. Producer Distinction
The most important NIS2 question for any waste company is not which controls to implement — it is whether you qualify at all. Annex II of the Directive lists waste management under Section 2 as covering “undertakings carrying out waste management as defined in Article 3, point (9), of Directive 2008/98/EC” but adds a limiting clause that most secondary guidance omits: “excluding those for which waste management is not their principal economic activity” [3].
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
This exclusion creates a clean but often misread dividing line. Waste processors — companies whose core business is operating collection routes, transfer stations, sorting facilities, composting operations, waste-to-energy plants, or WEEE treatment sites — are IN scope if they meet the size threshold. Waste producers — manufacturers, retailers, hospitals, or food processors that generate waste but outsource its handling to a third party — are OUT of scope under Annex II waste management, even if they use digital systems to manage their waste data. They may fall under other Annex sectors (manufacturing, food, healthcare), but the waste management entry does not cover them.
Work through the following seven items before committing resource to Article 21 implementation.
- Principal activity test passed: Waste collection, transport, treatment, recovery, or disposal is your organisation’s primary revenue-generating activity, not a support function. A manufacturer that sends waste to a contracted haulier is OUT. A composting operator that processes organic waste collected from third parties is IN. Reference: Directive 2008/98/EC Article 3(9); NIS2 Annex II Section 2 [3].
- Size threshold met — either condition: 50 or more employees OR €10 million or more in annual turnover. If your company is part of a corporate group, apply the EU SME Recommendation 2003/361/EC partner and linked enterprise methodology — a 40-person waste subsidiary of a 300-person group may inherit group-level thresholds [3] [4].
- EU operations confirmed: Your network and information systems supporting waste services are located in or directed at EU member state territories. Article 2(1) of the Directive applies to entities established in the EU; entities established outside the EU with services directed into the EU should seek advice on their NCA registration obligation [3].
- Default entity classification confirmed as Important: Unless your member state has specifically designated your category as an Essential Entity (permitted under Article 2(2) for entities critical to the national economy or public safety), waste management operators default to Important Entity status under Annex II. Verify with your national competent authority (NCA) [4].
- Group structure mapped for threshold purposes: Subsidiaries, parent companies, and linked enterprises count toward the size threshold. Document the group structure assessment and retain it as evidence of the threshold calculation [4].
- Edge cases resolved before registering: WEEE recyclers and e-waste treatment operators: IN scope (recovery is waste management under Directive 2008/98/EC Article 3(9)). Municipal waste authorities: typically IN scope even if government-owned, as their principal function is waste management. Retailers operating take-back collection points only: generally OUT (retail is the principal activity). Manufacturers with an on-site incinerator for their own process waste: OUT unless the incineration capacity is externally commercialised as a waste treatment service [3] [4].
- NCA registration submitted: Important Entity registration with your member state’s competent authority is required before you can be lawfully supervised. Check your NCA’s registration portal and deadline. Note that some member states (e.g., Germany’s BSI) have published registration windows with specific deadlines for entities in scope from their national NIS2 transposition date [4].
Asset Inventory — What NIS2 Counts for Waste Companies
Article 21(2)(i) of the Directive requires “human resources security, access control policies and asset management” [1] — which means a documented inventory of every system supporting your waste services must exist before a single policy document is written. For waste companies, the asset landscape differs from a generic corporate IT environment: you have operational technology managing physical processes, GPS-connected fleet hardware, weighbridge control systems, and sector-specific ERP platforms alongside standard office infrastructure. Most generic NIS2 asset register templates are not structured for this mix.
Six asset categories apply to most waste operators [4]. Document each category with: system name, vendor, owner role, criticality tier (A = critical to service delivery; B = operational but not directly service-critical; C = administrative), and the Article 21(2) sub-clause it falls under. For SCADA and OT systems, add firmware version and end-of-life date.
- Fleet management and GPS systems documented and criticality-tiered: Route optimisation software, driver scheduling tools, telematics platforms, and real-time GPS tracking all fall under Article 21(2)(i) as assets AND under Article 21(2)(d) as supply chain relationships when hosted by a third-party SaaS provider. Classify these as Tier A if a fleet management outage halts waste collections [4].
- Weighbridge and site access control systems inventoried: Electronic weighing systems at transfer stations, processing sites, and gates record incoming and outgoing material weights for billing and regulatory reporting. A breach or manipulation of these records constitutes both a NIS2 significant incident and a potential compliance failure under waste sector permits. Classify as Tier A if billing or regulatory reporting is automated from weighbridge data [4].
- ERP and billing platforms documented with vendor details and access controls listed: Sector-specific solutions such as RECY, Wastebox, or Wasteserv qualify alongside generic platforms such as SAP Business One or DATEV. For each ERP, record which staff roles have write access, which vendor staff hold administrative credentials, and whether the platform is cloud-hosted (triggering Art.21(2)(d) supplier assessment) [4].
- SCADA, DCS, and plant control systems listed separately from IT assets: Include firmware versions, end-of-life dates, network connectivity status, and whether each system is air-gapped, isolated behind a DMZ, or directly connected to corporate IT. Systems at sorting plants, composting facilities, anaerobic digestion plants, or waste-to-energy operations are Tier A assets under Article 21(2)(i). Record the engineering workstation (EWS) that programs each PLC or DCS as a linked asset [4] [5].
- IoT devices and sensor networks inventoried: Smart bin fill-level sensors, weighbridge RFID readers, remote PLC telemetry endpoints, vehicle-mounted PDAs, and cellular-connected telematics hardware all qualify as network and information system assets. For each device class, log: communication protocol, data destination, cellular provider or network path, and vendor identity [7].
- Wide-area network infrastructure across operational sites documented: Include routers, switches, firewalls, VPN concentrators, and cellular data connections between head office, transfer stations, and plant sites. Identify any direct IT-to-OT network paths that lack segmentation — these are immediate Article 21(2)(e) remediation priorities [5].
SCADA and OT Security Controls for Waste-to-Energy and Processing Plants
The hardest NIS2 compliance gap for most waste operators is applying Article 21’s requirements to operational technology that was never designed with cybersecurity in mind. A Siemens S7-1500-based combustion control system at a waste-to-energy facility, a PLC managing anaerobic digester temperature, or a DCS controlling flue gas treatment cannot run conventional endpoint agents. Patching them disrupts processes. Yet Article 21(2)(e) — covering “security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure” — applies to them directly [1].
The IEC 62443-3-2 Zone and Conduit model is the industry-standard architecture for meeting Article 21(2)(e) in OT environments: group assets with similar risk profiles into security zones, connect zones only through documented conduits with enforced controls, and assign Security Level Targets (SL-T 1–4) to each zone based on threat scenarios. For waste-to-energy plants, combustion control zones typically warrant SL-T 2 (process control environment); safety instrumented systems for over-temperature protection warrant SL-T 3. You do not need to reach SL-T 2 on day one, but you must document the target and show progress [6].
For more detail on how NIS2 Article 21 applies to OT environments across industrial sectors, see our guide to NIS2 waste management compliance obligations.
- IT/OT network segmentation implemented with documented DMZ: No direct connectivity exists between corporate office workstations and SCADA historian or PLC management networks. A dedicated DMZ separates the two, and firewall rules permit only documented, required communications between zones. Record the conduit architecture, allowed protocols, and source/destination pairs in a firewall rule register [5] [6].
- Passive OT asset discovery deployed: Active network scanning can disrupt legacy PLCs and RTUs. Deploy passive network detection and response (NDR) tools that detect communicating assets by monitoring network traffic without sending probes. Passive discovery also provides the real-time visibility needed to identify new, unauthorised devices — a requirement under Article 21(2)(i) asset management [5] [6].
- Engineering workstation (EWS) controls enforced: Application allowlisting prevents unauthorised software execution on the workstations used to program PLCs and DCS controllers. USB ports are disabled by default. No direct internet access is permitted from the EWS; all software updates are staged through a DMZ-approved update server or isolated patch management system. Activity on the EWS is logged and forwarded to the SIEM [6].
- Shared and default credentials eliminated on all OT assets: Every SCADA server, HMI, historian, and PLC management interface has a unique, non-default credential with role-based access assigned to individual accounts. For legacy PLCs without individual account support, document a compensating control (e.g., network-level access restriction limiting connections to named EWS IP addresses only) in a formal compensating control register [6].
- Vendor Remote Access Platform (VRAP) in place for all third-party OT maintenance: All SCADA vendor or OEM maintenance access goes through a jump server in the OT DMZ. Sessions are time-limited, require prior authorisation per-session, and are recorded (video and keystroke). No persistent VPN connections into process networks are permitted. Vendor access logs are retained for at least 12 months to support Article 21(2)(b) incident investigation [6].
- Compensating control register maintained for unpatchable OT assets: Legacy PLCs and control systems that cannot be patched without process disruption require a documented risk acceptance entry covering: reason patching is not feasible, compensating controls applied (network isolation, NDR monitoring, vendor patch schedule), and planned lifecycle replacement date. This is your Article 21(2)(e) vulnerability management evidence for those specific assets [5] [6].
- OT-specific threat detection rules configured: Monitor Modbus function codes FC6 (Write Single Register) and FC16 (Write Multiple Registers) from unexpected source IP addresses — unexpected write commands from non-engineering workstation IPs are an indicator of lateral movement or operator-station compromise. Alert on new device enumeration on process networks and on connections to external OT protocol ports (Modbus/502, S7/102, DNP3/20000, EtherNet•IP/44818) [6].
- SBOM (Software Bill of Materials) collected for critical OT components: Maintain a bill of materials for combustion controller firmware, DCS software, SCADA historian, and safety system firmware. When a vendor releases a CVE against a component in your SBOM, you can immediately identify affected assets and prioritise response. This satisfies both Article 21(2)(e) vulnerability handling and Article 21(2)(d) supply chain security for OT component suppliers [6].
- OT-specific Business Continuity Plan documented with manual fallback procedures: Define Recovery Time Objectives (RTOs) for critical plant functions — how long can the facility operate without SCADA connectivity? Document manual fallback procedures for combustion control, gate access, and weighbridge operations during a cyber-related outage. Test these procedures annually. A waste-to-energy plant that cannot demonstrate a tested manual operating procedure during a SCADA outage fails Article 21(2)(c) business continuity requirements [1] [5].
Smart Waste IoT Fleet — Supply Chain Security Under Article 21(2)(d)
Modern waste collection increasingly relies on a connected IoT layer that most NIS2 guides do not address: fill-level sensors on public litter bins, RFID readers at collection points, cellular-connected vehicle telematics, and SaaS-hosted route optimisation platforms receiving live GPS coordinates from every truck in the fleet. Each of these creates a supply chain relationship under Article 21(2)(d), which requires entities to address supply chain security “taking into account the vulnerabilities specific to each direct supplier” [1].
The risk is not the bin sensor itself — it is the telemetry path and the vendor holding the platform. A route optimisation SaaS provider with administrative access to your vehicle location data, driver schedule, and facility gate sensor feeds is an Article 21(2)(d) supplier whose security posture you are required to assess. If that provider suffers a breach that exposes your operational data, the resulting disclosure may trigger your Article 23 incident reporting obligation. The cellular network operator providing SIM connectivity for fleet telematics is a second, distinct supplier requiring the same assessment [1] [7].
For a deeper look at how Article 21(2)(d) applies to third-party relationships in operational sectors, see our article on NIS2 supply chain security obligations.
- IoT connectivity traffic segmented off the public internet: Smart bin sensors, vehicle telematics, and remote RFID readers should use private APNs or encrypted tunnels (VPN over cellular) rather than open public internet paths. A private APN prevents lateral movement from a compromised IoT device toward back-office ERP or fleet management systems [7].
- Route optimisation and fleet management SaaS vendors assessed under Article 21(2)(d): Document each vendor’s security certifications (ISO 27001, SOC 2 Type II), incident notification commitments (what do they notify you of, and within what timeframe?), and sub-contracting practices. Obtain a supplier security declaration or equivalent contractual commitment covering cybersecurity standards [1] [7].
- Smart bin sensor supply chain mapped as three distinct Article 21(2)(d) relationships: For any connected bin deployment, identify: (a) the sensor hardware manufacturer, (b) the cellular connectivity provider (SIM issuer and network operator), and (c) the telemetry aggregation platform operator. These are three separate supply chain relationships, each requiring documented assessment. Security failure at any tier can create a data exposure or service disruption event [7].
- IoT device authentication enforced at the network layer: No smart waste IoT devices use default credentials or shared certificates. Where device capability is limited, authentication is enforced at the APN gateway or network layer (allowlisted IMEI or certificate at the point of SIM activation). Document the authentication mechanism for each IoT device class in your asset inventory [7].
- Real-time IoT device visibility implemented to support Article 23 reporting: NIS2’s 24-hour early warning window begins at the moment of “becoming aware” of a significant incident [2]. If your fleet telemetry or bin sensor data is processed with a 48-hour delay, you cannot confirm operational disruption within the Art.23(3)(a) significance window. Implement real-time device status monitoring for Tier A IoT assets (vehicle GPS, high-volume collection point sensors) [2] [7].
- Component registry maintained for connected fleet hardware: Track device model, firmware version, cellular modem firmware version, and communication chip identity for vehicle-mounted and bin-mounted IoT devices. When a CVE is published against a common cellular module supplier (Quectel, Sierra Wireless, or similar), a component registry allows you to identify which vehicles and bin sites carry the affected hardware within hours rather than weeks [6] [7].
WEEE/RoHS Digital Tracking and Article 21(2)(i) Asset Management
Waste Electrical and Electronic Equipment (WEEE) recyclers and treatment facilities occupy a specific compliance corner where the WEEE Directive (2012/19/EU) and NIS2 intersect. WEEE treatment operators’ principal economic activity is waste management — so they are unambiguously IN scope under Annex II [3]. The point most WEEE operators miss is that the digital systems used to track and report WEEE streams are themselves NIS2-regulated information assets under Article 21(2)(i).
Producer responsibility data platforms (where recyclers log collected and processed volumes by WEEE category), R2 certification audit trail systems, and chain-of-custody databases for RoHS-restricted materials — lead, cadmium, hexavalent chromium, mercury — all qualify as network and information systems supporting critical waste services. A breach or manipulation of these records has regulatory consequences beyond NIS2: falsified WEEE treatment volumes can trigger enforcement under the WEEE Directive and national producer responsibility legislation. That dual exposure makes these systems high-priority Article 21(2)(i) assets that many organisations fail to include in their initial NIS2 asset inventories.
For context on how asset management obligations apply to operators handling regulated materials, see our overview of NIS2 asset management requirements.
- WEEE producer responsibility reporting systems classified as Tier A assets: Any system used to report collected, recycled, or recovered WEEE volumes to national producer responsibility schemes (PROs) is a critical data integrity asset. Unauthorised modification of these records is both a NIS2 significant incident under Article 23(3)(a) — operational and regulatory disruption — and a WEEE Directive compliance breach [1] [2].
- Chain-of-custody records for hazardous waste streams protected with integrity controls: Digital records for RoHS-restricted material disposition, hazardous waste manifests, and Basel Convention cross-border transfer notifications require integrity controls under Article 21(2)(i) and Article 21(2)(h) (cryptography policies). Where records are legally required to be immutable, implement cryptographic audit logging to detect tampering before regulators query the data [1].
- Access to WEEE and regulatory data platforms limited to authorised roles with least privilege: Apply role-based access control: a recycling facility operator needs write access on active processing records but not edit access to historical records already submitted to the PRO or regulator. Implement an immutable audit trail for all changes to submitted records. Review access rights quarterly and remove accounts within 24 hours of staff departure [1].
- WEEE data integrity backup and validation procedure documented and tested: WEEE reporting platforms must have offline backups validated monthly against live data. A ransomware event targeting these records creates both an Article 23 significant incident (operational disruption plus regulatory consequence) and a WEEE compliance gap that may require regulatory notification under national WEEE law. Define and test RTO for restoration of WEEE reporting capability as a distinct business continuity scenario [1] [2].
Governance, Incident Reporting, and Penalty Exposure
Article 20 of the Directive requires management bodies to approve cybersecurity risk-management measures and oversee their implementation — and enforcement authorities treat this as an independently actionable obligation, separate from whether technical controls pass inspection. For waste companies, this means the board or executive team must formally review and sign off the policies produced by the checklist above, not delegate them to IT without documented oversight.
The penalty ceiling for Important Entities under Article 34(5) is €7 million or 1.4% of total worldwide annual turnover, whichever is higher [9]. Article 33 supervisory measures for Important Entities include the right to carry out security audits, on-site inspections, and issue binding remediation orders following an incident or credible report of non-compliance — without waiting for a breach to occur. The governance items below directly affect your exposure to both fine and supervisory action.
For the Article 23 reporting process in detail, see our dedicated guide on NIS2 incident reporting obligations.
- Management body formally approved cybersecurity risk-management measures: Document the board or executive approval of your Article 21 policies (information security policy, risk assessment methodology, incident response procedures) in a board resolution, management decision record, or formal sign-off template. Retain this as your Article 20 evidence package for supervisory inspection. Approval must be renewed each time policies are substantively revised [1].
- Incident reporting procedure tested and timed against Article 23 deadlines: Run a tabletop exercise targeting a SCADA ransomware event at your processing plant. Can your team confirm significance under Article 23(3)(a) (severe operational disruption), draft the early warning notification, and submit it to your national CSIRT within 24 hours of awareness? Clock the exercise. If the answer is no, your current procedure fails the Article 23 timeline requirement [2].
- NCA registration completed and point of contact filed and maintained: Your member state NCA registration is the legal precondition for supervised operation. Keep the registration current: changes to the registered entity’s size, structure, or primary contacts must be notified. Maintain your NCA contact details, your NIS2 Officer’s contact information, and your CSIRT reporting endpoint on file and tested [4].
Key Takeaways
- Scope first: If waste management is not your principal economic activity, Annex II does not apply to you under the waste management entry. Confirm the principal activity test before committing to Article 21 implementation.
- Six asset categories define your NIS2 perimeter: Fleet management, weighbridge, ERP, SCADA/plant controls, IoT sensors, and network infrastructure. Document all six before writing a single policy.
- SCADA and OT need a different control set: IEC 62443-3-2 zone segmentation, passive NDR, VRAP for vendor access, and compensating controls for unpatchable PLCs are not optional additions — they are how Article 21(2)(e) applies in plant environments.
- IoT fleet and WEEE tracking are information assets: Route optimisation SaaS vendors, bin sensor cellular providers, and WEEE reporting platforms are all Article 21(2)(d) supply chain relationships or Article 21(2)(i) assets — not just software subscriptions.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS2 Directive (EU) 2022/2555, Article 21 — Cybersecurity risk-management measures. nis-2-directive.com
- NIS2 Directive (EU) 2022/2555, Article 23 — Reporting obligations. nis-2-directive.com
- NIS2 Directive (EU) 2022/2555, Annex II — Other Critical Sectors. LuxGAP Annex II (primary directive text)
- NISD2.eu, NIS2 for Waste Management. nisd2.eu/en/nis2-waste-management
- Rockwell Automation, What OT Security Teams Need to Know About NIS2. rockwellautomation.com
- Shieldworkz, Achieving NIS2 Compliance Through IEC 62443. shieldworkz.com
- IXT.io, What NIS2 Means for Your IoT Connectivity. ixt.io
- ENISA, NIS2 Technical Implementation Guidance (June 2025). enisa.europa.eu
- NIS2 Directive (EU) 2022/2555, Article 34 — General provisions on penalties. nis-2-directive.com
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
