Industry · Food & export

NIS2 compliance for seafood exporters

Food, production, processing and distribution, sits in NIS2 Annex II. Seafood production and export fall here, with requirements for risk management, supply chain, and incident readiness.

Why is the seafood industry covered?

The food sector is in NIS2 Annex II (important entities). Seafood production, processing and distribution fall under food. The directive uses the term “food”, not “seafood” specifically, but the activity is covered. In addition, large customers and chains impose compliance requirements that cascade down the supply chain.

Industry-specific risks

Traceability and food safety

Traceability and quality systems are critical for both regulation and reputation, and for export access.

Cold chain and OT

Chilling, freezing and process equipment are run by industrial systems where downtime quickly becomes costly.

ERP and export documentation

Order, customs and export systems tie together many integrations and external parties.

Cascading customer requirements

Large buyers and chains audit their suppliers. Without documentation you risk losing contracts.

What Havvakt delivers

  • Mapping of production, traceability and export systems, including OT.
  • Risk assessment based on NSM Basic Principles, prioritized by operational impact.
  • Supplier and customer-requirement register, with audit-ready documentation.
  • Incident readiness with templates for 24-hour notification.

This is what the requirements look like for your industry. Let’s talk.

Questions from the seafood industry

Does seafood really count as “food” in NIS2?

Yes. The food sector, production, processing and distribution, is in Annex II, and seafood falls under food. The directive does not use the word “seafood” specifically, but the activity is covered.

A large customer demands documentation now, can you help fast?

Yes. We start with mapping (normally 2–3 weeks) and have baseline documentation in place within the first month, so you can answer the customer with something concrete.

We already have quality systems, do they count?

Quality and food-safety systems are a good starting point, but do not cover the cyber requirements of NIS2. We build on what you have.