New Dual Regulatory Demands for EU Industry

Author photo: Thomas Menze
By Thomas Menze

KEYWORDS: Industrial Cybersecurity Regulations, Cyber Resilience Act, CRA Security by Design, NIS2 Incident Reporting, CE Marking, NIS2 Risk Management, OT Cybersecurity Governance

Expert Discourse on Industrial Cybersecurity

From 2026 onward, operators of process-related industries classified as critical infrastructure in Europe—such as chemical production sites—will be operating under the combined regulatory pressure of the NIS2 Directive and the Cyber Resilience Act (CRA). While NIS2 directly applies to operators as essential or important entities, CRA primarily targets manufacturers and suppliers of products with digital elements, with significant downstream implications for plant owners and operators.

The CRA introduces mandatory security-by-design and security-by-default requirements across the full lifecycle of industrial automation and control system (IACS) products, including secure development practices, vulnerability handling, and conformity assessments. Automation vendors will be required to provide documented cybersecurity assurances, including risk analyses, software bills of materials (SBOMs), vulnerability disclosure processes, and post-market security support.

NIS2, in contrast, places explicit responsibility on operators to implement robust cybersecurity governance, encompassing risk management measures, incident detection and reporting, business continuity, and supply chain risk control. For chemical plant operators, this extends beyond IT systems to include operational technology (OT), safety-related systems, and outsourced engineering or maintenance services.

As a result, operators must maintain comprehensive and auditable documentation—such as cybersecurity risk assessments, incident response and recovery plans, supplier security evaluations, and evidence of regulatory compliance—to demonstrate due diligence to national authorities. Procurement and asset management processes will increasingly depend on demonstrable CRA compliance from automation suppliers, effectively linking product cybersecurity assurance with operational regulatory obligations under NIS2.

Together, CRA and NIS2 mark a structural shift in European industrial cybersecurity: from voluntary best practices to enforceable, lifecycle-oriented compliance, with direct accountability at both executive and supplier levels.

The Cyber Resilience Act (CRA) applies to all products with digital elements placed on the EU market, including hardware and software used in industrial automation and control systems (IACS) within process industries. Its primary regulatory focus is on manufacturers, importers, and distributors of such products, requiring cybersecurity to be built into products by design and by default.

CRA Makes Cybersecurity Mandatory for EU Market Access in Industrial Automation by 2026

For automation suppliers, the CRA establishes mandatory security-by-design and security-by-default principles across the entire product lifecycle. This includes secure development processes, documented cybersecurity risk assessments, protection against known classes of vulnerabilities, and the ability to provide timely security updates throughout the expected lifetime of the product. Manufacturers must implement structured vulnerability handling and disclosure processes and ensure that vulnerabilities are assessed, documented, and remediate without undue delay.

From 2026 onward, products with digital elements that do not comply with CRA requirements will no longer be eligible for CE marking and therefore cannot be legally placed on or made available within the EU market. For industrial automation suppliers, this effectively makes cybersecurity a market access requirement comparable to functional safety or electromagnetic compatibility.


ARC Advisory Group clients can view the complete report at the ARC Client Portal.

Contact Us if you would like to speak with the author.

Obtain more ARC In-depth Research Market Analysis.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients