OT and IT convergence under NIS2
Industrial control systems integrated with corporate IT. ICS networks must now meet cybersecurity standards under NIS2.
GDPR, NIS2, and OT/IT security for manufacturers and industrial IoT
One business day reply. Clear next steps and indicative pricing.
From automotive supply to chemicals and food processing. Each sub-sector triggers a different combination of product regulations, sustainability rules and OT cybersecurity.
R155 cyber type approval, CRA for ECUs, CSDDD due diligence, conflict minerals.
Machinery Regulation 2023, CE marking, AI Act for safety-critical machine vision.
CRA for connected products, RoHS and WEEE, semiconductor supply chain, REACH.
REACH registration, CLP labelling, BREF emissions, OT cyber for hazardous processes.
Food safety, traceability, NIS2 (food sub-sector), sustainability reporting.
GMP, serialisation, falsified medicines, integration with healthcare regimes.
Multiple regimes interlock. We sequence them around your operating cadence.
Employee monitoring, ERP and CRM systems, dealer and after-sales data flows, transfers to non-EU plants.
Registration, evaluation, authorisation and restriction of chemicals. SVHC notifications and SCIP database.
Risk analysis, supplier code, remediation tracker, annual report. From 1,000 employees in Germany.
Replaces 2006 directive. Cybersecurity essential requirements, digital documentation, conformity assessment.
Date of application from 14 January 2027. Notified body submissions need 18-month lead time.
AI in machinery safety functions, predictive maintenance with safety impact, machine-vision quality control.
Connected products (hardware + software) must meet essential cybersecurity requirements. CE marking required.
EU-wide supply-chain due diligence for large companies. Phased application from 2027.
Industrial control systems integrated with corporate IT. ICS networks must now meet cybersecurity standards under NIS2.
Connected products need CE marking with cybersecurity essential requirements. Vulnerability handling and 5-year support obligation.
Tier 1, Tier 2 and beyond. Risk analysis, supplier code, remediation, annual report. Documentation is the deliverable.
New regulation applies from January 2027. Digital documentation, cybersecurity essential requirements, AI for safety functions.
Substance registration, SVHC notifications, SCIP database for articles, authorisation lists growing.
Machine vision quality control, predictive maintenance with safety impact, robotics decision-making all caught by Annex III.
Essential-requirements gap, secure-by-design review, vulnerability handling process, conformity route, technical documentation.
Entity classification, ISMS aligned with ISO 27001 and IEC 62443, OT segmentation, incident reporting playbook.
Risk analysis methodology, supplier code, preventive and remedial measures, annual report.
Essential-requirements assessment, cybersecurity for safety functions, digital documentation, notified-body submissions.
Annex III classification for safety-critical AI, machine vision and predictive maintenance. Technical file, human oversight.
Substance registration support, SVHC notifications, SCIP database submissions, restriction list monitoring.
IEC 62443 framework, ICS network segmentation, asset inventory for OT, secure remote access.
Employee monitoring lawful basis, ERP/CRM governance, dealer network data, transfers to non-EU plants.
Senior advisor with industrial experience, regulator and notified-body liaison, board reporting.
Eight questions about your products, processes and supply base. Get an indicative obligations map across CRA, NIS2, AI Act, CSDDD, Machinery and REACH.
Run obligations mapper~ 4 MINManufacturing sub-sectors listed in NIS2 Annex II as important entities include automotive, machinery and electronics manufacturing above thresholds (50 staff or €10M turnover). Critical manufacturing (medical devices, computers, electronic optical products) can be essential under Annex I.
Cyber Resilience Act applies from 11 December 2027. Vulnerability reporting from 11 September 2026. Connected products placed on the EU market after the date need CE marking with cybersecurity essential requirements.
Machinery Regulation 2023 already requires cybersecurity essential requirements for safety functions. CRA layers on top for the full product lifecycle. Our team builds combined technical documentation that satisfies both regimes.
Companies with 1,000 employees in Germany are in scope from January 2024. Smaller companies are not directly in scope but are typically required by larger customers to participate in supplier code and risk analysis.
CSDDD applies EU-wide from 2027 with phased thresholds. Companies above 1,000 employees and €450M EU turnover are in scope first, with smaller thresholds following. Non-EU companies meeting the EU turnover threshold are also in scope.
Yes if the AI affects safety functions or has high-risk outcomes (employment, safety-critical applications). Annex III lists AI in safety components of products subject to harmonised legislation. Most industrial safety AI is caught.
Substances of Concern in articles, as such or in complex objects (Products). Notification required for articles placed on the EU market containing SVHCs above 0.1%. Database is operated by ECHA, accessible to consumers and authorities.
Yes. We prepare technical documentation, coordinate with the notified body, manage queries and run dry-run interviews before submission. We have completed conformity files for machinery, medical devices and connected products.
ISMS, ISO 27001, IEC 62443 and OT cybersecurity programmes.
Open practice →Scoping, ISMS and supervisory readiness for manufacturers.
Open practice →AI Act for industrial AI, machine vision and predictive maintenance.
Open practice →Typical outcomes: NIS2 status determined, OT/IT segmentation plan, resilience measures.