NIS2 and ServiceNow OT Management: What Buyers Need to Know Before They Sign
- Tereza Schneider

- Aug 27
- 5 min read
Updated: 1 day ago
How the Cyberbeveiligingswet is changing OT risk management, why ServiceNow is entering the conversation, and where buyers can retain negotiating leverage.
A regulator asks for a complete inventory of every device running your production lines. Your plant teams cannot provide one. The board asks whether the factory could withstand a ransomware attack, but no one can give a confident answer. Meanwhile, the compliance deadline has already passed.
For many Dutch organisations, this is no longer a hypothetical scenario. Since the Cyberbeveiligingswet (Cbw), the Dutch implementation of the EU's NIS2 Directive, entered into force on 15 August 2026, operational technology has become a board-level regulatory concern. Industrial control systems, production equipment, sensors and plant infrastructure must now be accounted for, assessed and protected with the same discipline expected elsewhere in the business.
That creates an urgent question: how do you gain control of an OT environment that was never designed to be centrally visible?
ServiceNow is positioning OT Management as an answer, and compliance pressure is helping to move it rapidly onto executive roadmaps. The urgency can make an expensive platform proposal appear inevitable.
It is not.
This article explains what the new requirements mean for OT, why they so often lead to a ServiceNow conversation, which alternatives deserve consideration, and where buyers can find leverage before committing to a deal that may drive their IT spend for years.
What does NIS2 actually require?
In practical terms, NIS2 does three things. It brings more organisations under statutory cybersecurity requirements. It makes clear that the factory floor cannot be treated as someone else's problem. And it attaches serious financial consequences, including potential personal liability, to being unprepared.
The rules divide organisations into “essential” and “important” entities. The classification depends first on sector and then on factors such as size. A large organisation in a higher-stakes sector, including energy, transport, banking, healthcare or digital infrastructure, will generally be classified as essential. The maximum fine is €10 million or 2% of worldwide annual turnover.
Important entities, including qualifying organisations in sectors such as chemicals, food and waste management, face a maximum of €7 million or 1.4% of worldwide annual turnover.
For organisations in scope, the operational requirements are more straightforward than the terminology suggests. They must:
Assess and document their cybersecurity risks
Maintain a credible incident-response plan
Manage supply-chain risk
Apply appropriate measures such as encryption and multi-factor authentication
Ensure that the board takes responsibility for cybersecurity
When a significant incident occurs, the reporting clock starts quickly:
01 — Within 24 hours
Early warning to the National Cyber Security Centre
02 — Within 72 hours
Fuller incident notification
03 — Within one month
Final incident report
In the Netherlands, board members who fail to complete the required cybersecurity training may also face a personal fine of up to €25,000. That requirement has a two-year transition period, running until August 2028.
The legislation does not need to name operational technology explicitly for OT to fall within an organisation's overall cybersecurity and risk-management responsibilities. Production-line control systems matter just as much as head-office laptops.
This is where many organisations encounter their first serious gap. IT asset inventories are often reasonably mature. OT inventories are not. Industrial control systems, sensors, production equipment and plant infrastructure were rarely designed to report into a single central system.
Why does this often lead to a ServiceNow purchase?
You cannot assess the risk of assets you cannot identify.
For OT, establishing that inventory is often the hardest part. Industrial systems accumulate over many years, supplied by different vendors, connected to separate networks, and sometimes installed without central IT ever knowing they exist.
ServiceNow is not the only provider addressing this problem, but it has made OT visibility a clear strategic priority. Its Operational Technology Management product brings OT asset data into the same platform many organizations already use for their configuration management database. For existing ServiceNow customers, the appeal is clear: one system of record instead of disconnected IT and OT inventories.
ServiceNow strengthened that position by acquiring Mission Secure in 2024. It went further with its $7.75 billion acquisition of Armis, worth roughly 5% of ServiceNow's entire market capitalization and a clear indication of how important cyber-exposure management across IT, OT, and connected devices has become to its strategy.
The consolidation has also changed the competitive field. Before the acquisition, Armis was one of the more credible independent options for exposure management across IT, OT, and IoT. Nozomi Networks, another established name in the category, was acquired by Mitsubishi Electric in 2025. Claroty remains independent and offers its xDome platform, while also integrating with ServiceNow OT Management rather than positioning itself solely as a direct platform replacement.
Despite the competitive field becoming narrower, buyers should still examine credible alternatives. Dragos offers an OT-native platform built specifically for industrial environments and may suit organizations that want OT security to remain on a dedicated system. Microsoft Defender for IoT can be a strong option for businesses already committed to Azure and Microsoft's security stack, where another platform could add complexity rather than reduce it.
ServiceNow therefore remains a credible response to the visibility and risk-analysis challenge created by the Cbw. It is not, however, the only possible response. That distinction matters when the commercial conversation begins.
The number on the first proposal is not the number to accept
Compliance-driven purchases create a particular negotiating risk: they appear to run on the vendor's timeline rather than the buyer's. When a deadline has passed, the pressure to move quickly can make valuable commercial and contractual protections feel secondary.
Vendors understand that pressure.
The compliance requirement is real, but it does not change the fundamentals of enterprise software negotiation. Even under a genuine deadline, buyers retain leverage. Three issues deserve attention before the first serious commercial discussion with ServiceNow.
First, ServiceNow does not have a monopoly on the problem
A preliminary proposal or short proof of concept from Dragos or Microsoft Defender for IoT is not merely a negotiating tactic. It establishes a credible alternative. Account teams approach pricing differently when they know the customer has another workable path.
Second, understand how the OT estate will be measured
ServiceNow moved OT Management pricing from an asset-based model to a site-based model, but licensing conditions may still place limits on the number of assets associated with each site.
The contract should therefore define what constitutes a site, which assets fall within it, how future growth will be treated and when the baseline will be established. Without that clarity, sensors, duplicate records, dormant equipment or assets planned for later deployment can create unexpected exposure and future costs.
Third, protect the renewal
ServiceNow restructured its pricing model in April 2026, moving from five tiers to Foundation, Advanced and Prime, with greater emphasis on AI-driven consumption.
Even customers that started with a clear commercial model may face migration to materially different packaging at renewal. Price protection, renewal caps, metric definitions, product-use rights and safeguards against forced migration should be agreed in the contract rather than left to the vendor's discretion.
None of this requires delaying a necessary implementation. It requires deciding what you need, how your use may grow and which protections matter before negotiating from the proposal the vendor chose to put in front of you.
How LicenseCrafts helps you secure the right deal
If NIS2 or the Cyberbeveiligingswet has placed a ServiceNow OT Management purchase on your agenda, it is the right time to involve an independent advisor to get a clear read on the deal.
LicenseCrafts brings a proven methodology and structured process to complex software negotiations. We identify the leverage you already have, test the vendor's assumptions and translate that leverage into commercial and contractual advantages.
For a ServiceNow OT Management purchase, this means looking beyond the headline discount. We examine:
Scope and licensing metrics
Asset and site baselines
Credible alternatives and competitive leverage
Future price increases
Product repackaging
Compliance may create the urgency, but it should not dictate the commercial outcome.
Our objective is to help you secure an agreement that meets today's compliance needs and remains sustainable for years to come.
Before you accept the proposal in front of you, let LicenseCrafts show you what is negotiable and help you turn it into the right long-term deal.
.png)
Comments