Ley de Ciberresiliencia frente a NIS2: lo que los fabricantes deben saber

En este artículo

Puntos clave para los directivos de la industria manufacturera

  • Both regulations likely apply to you. If you manufacture connected products and operate in the EU, expect to comply with the CRA (product side) and NIS2 (operational side) simultaneously.
  • September 2026 is the first hard deadline. CRA vulnerability reporting obligations take effect over a year before full application. Start building your reporting process now.
  • IEC 62443 is your most efficient compliance framework. It bridges CRA product requirements and NIS2 operational requirements in a single, industry-recognized standard.
  • Supply chain security requires contractual action. Both regulations push accountability upstream and downstream. Audit your suppliers and update your agreements accordingly.
  • Uncertainty is not an excuse for inaction. Harmonized standards are still evolving, but the core obligations are clear. Organizations that wait for final guidance will run out of time.


Cyber Resilience Act vs NIS2

The European Union has drawn a line in the sand on cybersecurity. Two major regulations, the Cyber Resilience Act (CRA) and the revised Network and Information Security Directive (NIS2), are converging on the manufacturing sector between now and 2027. Both aim to harden Europe’s digital infrastructure against rising threats. But they do so from different angles, and manufacturers need to understand exactly where each one applies.

If you build products with embedded software, operate connected production lines, or sell into the EU market, both regulations likely affect you. This guide breaks down what matters, what overlaps, and what to do next.

Two Regulations, One Goal: Raising the Bar for EU Cybersecurity

NIS2, which took effect in January 2023 with a member-state transposition deadline of October 2024, targets operators of critical infrastructure and essential services. The CRA, published in the Official Journal in November 2024, targets products with digital elements placed on the EU market, with its core obligations applying from September 11, 2026, onward.

In practice, a mid-sized manufacturer of industrial sensors could fall under both regulations simultaneously: NIS2 because it operates as an essential or important entity within the manufacturing sector, and the CRA because it sells PLCs, HMIs, or IIoT gateways that qualify as products with digital elements. Understanding where each regulation begins and ends is the first step toward a workable compliance strategy.

CRA vs NIS2 at a Glance

DimensionCyber Resilience Act (CRA)NIS2 Directive
ÁmbitoProducts with digital elements on EU marketOperators of essential and important services across the EU
Who Must ComplyManufacturers, importers, and distributors of connected productsMedium and large entities in 18 critical sectors, including manufacturing
Key RequirementsSecure-by-design, vulnerability handling, SBOM, CE marking, conformity assessmentRisk management, incident reporting (24h/72h), supply chain security, governance accountability
PenaltiesUp to EUR 15M or 2.5% of global annual turnoverUp to EUR 10M or 2% of global annual turnover
TimelineReporting: Sept 2026; Full application: Dec 11, 2027Transposition deadline: Oct 2024; enforcement ongoing



What the Cyber Resilience Act Means for Manufacturers

Products with Digital Elements: Are You In Scope?

The CRA applies to any product with digital elements, meaning any software or hardware product with a data connection that is placed on the EU market (Article 2). For manufacturers, this includes PLCs, HMIs, IIoT gateways, industrial routers, smart sensors, and any device running embedded firmware. If your product connects to a network and you sell it in the EU, you are almost certainly in scope.

Annex III of the CRA further classifies products into “important” and “critical” categories. Industrial automation and control systems (IACS) fall under the important category, which triggers third-party conformity assessment rather than self-assessment.

Secure-by-Design, SBOM, and CE Marking

The CRA requires manufacturers to integrate cybersecurity throughout the product lifecycle. Annex I sets out essential requirements: secure default configurations, protection against unauthorized access, data integrity, and the ability to install security updates. Manufacturers must also generate and maintain a Software Bill of Materials (SBOM) to ensure transparency in their software supply chains.

For OT environments, this has significant implications. Legacy products without update mechanisms will need to be redesigned or retired. The CE marking process will now include a cybersecurity conformity assessment, meaning products cannot legally be sold in the EU without demonstrating CRA compliance.

The September 2026 Deadline You Cannot Miss

While full CRA application begins December 11, 2027, manufacturers must comply with vulnerability reporting obligations by September 11, 2026. That means establishing processes to report actively exploited vulnerabilities to ENISA within 24 hours. If your organization lacks a structured vulnerability disclosure and incident response process today, you have months, not years, to build one.

What NIS2 Means for Manufacturers

Essential vs Important Entity: How to Classify Yourself

NIS2 divides entities into two tiers. Essential entities include large enterprises (250+ employees or EUR 50M+ turnover) in high-criticality sectors. Important entities include medium enterprises (50+ employees or EUR 10M+ turnover) in the same or additional sectors. Manufacturing is explicitly listed in Annex I of the directive, particularly the manufacture of electrical equipment, machinery, motor vehicles, and medical devices.

Classification determines supervision intensity: essential entities face proactive regulatory oversight, while important entities are subject to reactive enforcement. Both tiers carry the same baseline obligations.

Risk Management and Incident Reporting

Article 21 of NIS2 mandates a set of risk management measures, including incident handling, business continuity, supply chain security, and encryption where appropriate. Article 23 requires a tiered incident reporting process: an early warning within 24 hours, a full notification within 72 hours, and a final report within one month.

For manufacturers running converged IT/OT environments, this creates a real operational challenge. Security monitoring on legacy OT networks is often limited, and detecting incidents on a flat network segment running 15-year-old PLCs is fundamentally different from monitoring a modern IT environment.

Supply Chain Security Is Now Your Responsibility

NIS2 explicitly requires entities to address cybersecurity risks in their supply chains (Article 21(2)(d)). This means manufacturers must evaluate the security practices of their component suppliers, software vendors, and system integrators. Contractual obligations around security will need to flow downstream.

Where CRA and NIS2 Overlap

Both regulations require vulnerability management, incident reporting, and risk-based security measures. Both impose board-level accountability. And both reference supply chain security as a core obligation. For manufacturers who both build connected products and operate connected infrastructure, the overlap is substantial.

Using IEC 62443 as Your Compliance Bridge

IEC 62443 is the international standard series for industrial automation and control system security. It addresses both product development (IEC 62443-4-1, 4-2) and operational security (IEC 62443-2-1, 3-3), making it a natural bridge between CRA product requirements and NIS2 operational requirements. While the European Commission is still finalizing harmonized standards for the CRA, IEC 62443 is widely expected to serve as a primary reference. Aligning with it now gives manufacturers a defensible compliance posture across both regulations.

The 2026-2027 Compliance Timeline

  • Now through mid-2026: Conduct gap analyses, begin SBOM tooling, establish vulnerability reporting processes.
  • September 11, 2026: CRA vulnerability reporting obligations take effect. Manufacturers must report actively exploited vulnerabilities to ENISA.
  • October 2024 onward: NIS2 transposition deadlines have passed. Member-state enforcement timelines vary, but obligations are live.
  • December 11, 2027: Full CRA application. All products with digital elements placed on the EU market must meet Annex I requirements and carry CE marking with cybersecurity conformity.

It is worth noting that some uncertainty remains. Harmonized standards under the CRA are still being developed, and member-state transposition of NIS2 has been uneven. Compliance teams should track updates from the European Commission and ENISA closely.

Building a Unified Compliance Roadmap

Step 1: Gap Analysis

Map your current security posture against CRA Annex I requirements and NIS2 Article 21 obligations. Identify which products fall under CRA scope and whether your entity qualifies as essential or important under NIS2. Pay particular attention to OT assets that lack basic security controls.

Step 2: Align with IEC 62443 and ISO 27001

Use IEC 62443 for product and OT system security. Layer ISO 27001 for enterprise-wide information security management. Together, these standards cover the vast majority of requirements under both regulations and provide auditable evidence of compliance.

Step 3: Update Supplier Contracts

Review contracts with component suppliers, software vendors, and integrators. Include cybersecurity requirements, vulnerability notification clauses, and SBOM delivery obligations. Both NIS2 and the CRA make supply chain security a shared responsibility.

Step 4: Set Up Cross-Functional Ownership

Compliance cannot sit in IT alone. Product engineering, OT operations, procurement, and legal all have roles to play. Establish a cross-functional working group with clear accountability and direct reporting to executive leadership, as both regulations impose management-level responsibility.

Suscríbase a nuestro boletín informativo

¿Qué busca?

Acelere la eficacia de su producción

Obtenga la guía de Accevo Smart Factory.

Al facilitar su dirección de correo electrónico y hacer clic en el botón "Descargar un catálogo", acepta recibir nuestro boletín.

Meet us at Pharma MES 1 - 2 October 2026 | Berlin, Germany