The EU Cyber Resilience Act, active since December 2024 with full obligations from December 2027, requires manufacturers to integrate security into product design or face fines up to €15 million and EU market exclusion. NIS2 adds supply-chain mandates with fines up to €10 million. Compliance is now a condition of market access, not an optional checklist.
What Are the New Cybersecurity Rules for Manufacturers?
Three regulatory frameworks now define the minimum security standard for manufacturers selling into major markets. The EU Cyber Resilience Act, NIS2 Directive, and ISO/SAE 21434 require security to be built into products and processes from the start, with penalties including fines up to €15 million and exclusion from the EU market for non-compliance.
From 2027 onward, manufacturers will be required to demonstrate that their digital systems are secure by design and by default, or risk exclusion from the EU market.
- NIS2, active since October 2024, classifies many industrial companies as “critical entities,” mandating stronger supply-chain security, improved network protection, and formalized threat management. Non-compliance can result in fines of up to €10 million, plus administrative penalties.
- The Cyber Resilience Act, effective since December 2024, with full obligations taking effect from December 2027, requires manufacturers to integrate security into their design process, conduct regular risk assessments, and provide updates throughout a product’s lifespan. Violations can result in fines of up to €15 million or market exclusion.
- ISO/SAE 21434, governing automotive cybersecurity, mandates a “security-by-design” approach across the entire vehicle lifecycle, including Cybersecurity Management Systems (CSMS) and secure supplier oversight.
These frameworks collectively set a new baseline: digital products must be designed, built, and maintained with cybersecurity in mind — not bolted on after the fact.
How Does Compliance Become a Competitive Advantage?
Secure-by-design practices reduce rework, accelerate certification, and build customer trust. Manufacturers that can demonstrate compliance and prove product integrity gain a measurable advantage in high-stakes markets, especially as manufacturing has become the top target for ransomware groups exploiting connected systems.
Secure-by-design practices reduce rework, accelerate certification, and strengthen trust in high-stakes markets. Customers increasingly prefer partners who can demonstrate compliance and prove product integrity under scrutiny.
This is especially critical as manufacturing becomes the top target for cyberattacks. Ransomware groups exploit the same connected systems that enable smart factories and servitized products. What used to be an operational risk now carries financial, reputational, and regulatory consequences.
The implication is clear: security must move left — into the earliest stages of product and process design. Threat modelling, vulnerability testing, and secure coding should be embedded alongside quality and safety practices.
How Do Manufacturers Implement Secure-by-Design?
Secure-by-design implementation requires alignment across three layers: architecture, lifecycle management, and organizational culture. Products must include secure update pipelines, software bills of materials (SBOMs), and encrypted data flows. Security teams, product owners, and compliance officers must treat protection as a shared responsibility, not a final gate before release.
- Architecture: Products and systems must be built with secure update pipelines, traceable software bills of materials (SBOMs), and encrypted data flows.
- Lifecycle management: Continuous monitoring, incident reporting, and compliance tracking ensure long-term protection and readiness for audits.
- Culture and accountability: Security teams, product owners, and compliance officers must work as one — treating protection not as a gate but as a shared responsibility.
The same architecture that enables data-driven services can also enable resilience. For connected products, that means ensuring every data stream, update, and API call is traceable and compliant by design.
What Does Regulatory Readiness Look Like in Practice?
Manufacturers that meet Cyber Resilience Act and NIS2 requirements can enter regulated markets faster, integrate more cleanly with customer IT environments, and demonstrate resilience during audits. In sectors such as defense, energy, and automotive, where safety and security overlap, compliance is not paperwork; it is permission to operate.
In sectors like defense, energy, and automotive, where safety and security overlap, compliance isn’t paperwork — it’s permission to operate.
What Is the Future of Secure Manufacturing?
The future of manufacturing requires three capabilities working together: connected products, intelligent operations, and secure foundations. The first two create agility and efficiency. The third preserves market access, customer trust, and business continuity. Security and compliance are not obstacles to innovation; they are the foundation that allows it to scale.
Security and compliance are not the brakes on innovation — they are the seatbelts that allow it to scale safely.
By embedding security into every design and deployment decision, manufacturers can turn regulation into a growth enabler, earning renewals faster, avoiding costly incidents, and keeping doors open in the world’s most demanding markets.
This article was written by Natalya Zheltukhina, Partner Network Manager at Sigma Software Group, DACH Region. Natalya is responsible for growing Sigma Software Group’s business on the DACH market, with a dedicated focus on the Automotive, Logistics, and Industrial Manufacturing Sectors.
FAQ
1. What is the EU Cyber Resilience Act and who does it affect?
The EU Cyber Resilience Act is a regulation, effective since December 2024 with full obligations from December 2027, that requires manufacturers to integrate cybersecurity into product design, conduct regular risk assessments, and provide security updates throughout a product’s lifespan. Non-compliance can result in fines up to €15 million or exclusion from the EU market. It applies to manufacturers of digital products sold in the EU.
2. What are the NIS2 Directive penalties for industrial manufacturers?
The NIS2 Directive, active since October 2024, classifies many industrial companies as critical entities and mandates stronger supply-chain security, improved network protection, and formalized threat management. Non-compliance can result in fines of up to €10 million, plus administrative penalties. Manufacturers affected by NIS2 must implement continuous monitoring and incident reporting programs.
3. What is secure-by-design vs. bolted-on security in manufacturing?
Secure-by-design means cybersecurity is built into a product or system from the earliest design stage, including threat modelling, vulnerability testing, and secure coding alongside quality and safety practices. Bolted-on security is added after development is complete. The EU Cyber Resilience Act and ISO/SAE 21434 both require the secure-by-design approach; bolted-on security does not meet their compliance standards.
4. What is an SBOM and why do manufacturers need one?
A software bill of materials (SBOM) is a traceable inventory of all software components in a product or system. Under secure-by-design frameworks including the EU Cyber Resilience Act, manufacturers must maintain SBOMs alongside secure update pipelines and encrypted data flows. SBOMs allow manufacturers to identify and respond to vulnerabilities across a product’s full lifecycle, which is required for compliance and audit readiness.