In brief
- Regulations concerned: NIS2, Data Act, CRA, AI Act, GDPR.
- The manufacturer wears two distinct hats.
- Cumulative caps: CRA up to €15M or 2.5%, AI Act up to €35M or 7%, NIS2 up to €10M or 2% (important entities: €7M or 1.4%), GDPR up to €20M or 4%.
- For an industrial operator, security is the common thread: NIS2 measures (IT/OT), CRA requirements (product) and GDPR security share a common foundation.
Regulatory deadlines
The key dates of the regulations applicable to your sector.
May 2018
RGPDEntry into application
In forceJanuary 2023
NIS2Entry into force (EU directive)
In forceJanuary 2024
Data ActEntry into force
In forceAugust 2024
AI ActEntry into force
In forceOctober 2024
NIS2Transposition deadline (EU)
In forceDecember 2024
CRAEntry into force
In forceFebruary 2025
AI ActBan on prohibited practices
In forceAugust 2025
AI ActGeneral-purpose AI models (GPAI) & governance
In forceSeptember 2025
Data ActApplication
In force2026
NIS2French transposition (Resilience Act)
In forceAugust 2026
AI ActHigh-risk system obligations (Annex III)
In forceSeptember 2026
CRANotification obligation (vulnerabilities & incidents)
UpcomingAugust 2027
AI ActHigh-risk embedded in products (Annex I)
UpcomingDecember 2027
CRAFull application
UpcomingWhy the 'Industry' sector is concerned
The industrial operator wears two distinct hats. As a site operator, it manages an industrial information system (OT) increasingly connected to IT infrastructure, exposing it to the cyber risks that NIS2 seeks to reduce. As a manufacturer placing a product on the market, it becomes responsible for the security and data of that product under the CRA and the Data Act.
IT/OT convergence is the critical point: a poorly secured sensor or programmable controller becomes an entry point into the production line, with physical consequences (shutdown, sabotage). This is precisely the perimeter that NIS2 and the CRA aim to harden.
Finally, as soon as an industrial product embeds an AI function playing a safety role (for example, the control of a machine), the AI Act may classify it as high-risk, in addition to sector-specific legislation on machinery and product safety.
NIS2 — manufacturing and critical sites
NIS2 covers the manufacture of certain products (medical devices, electronic and computer products, machinery and equipment, vehicles) among important entities, above the applicable size threshold. Manufacturers must implement the risk management measures under Article 21, secure IT/OT convergence, and notify incidents.
Supply chain security — component suppliers, integrators, industrial software publishers — is a central issue.
Key obligations
- Risk management measures (Art. 21) covering IT and OT.
- Securing IT/OT convergence.
- Notification of significant incidents.
- Industrial supply chain security.
Data Act — data from connected products
The Data Act requires manufacturers of connected products to make the data generated by the product accessible to the user and to allow its sharing with third parties of the user's choosing. For industry, this covers data from machines, equipment and sensors.
Manufacturers must design their products for data access 'by design' and review their associated service contracts.
Key obligations
- User access to data generated by the product.
- Data sharing with third parties designated by the user.
- 'Data access by design' architecture.
- Review of associated data service contracts.
CRA — products with digital elements
The Cyber Resilience Act classifies as a manufacturer any industrial operator placing on the market a product with digital elements (connected machinery, equipment embedding software). It mandates security by design, vulnerability management, an SBOM, patches throughout the support period, and notification of actively exploited vulnerabilities, culminating in CE cybersecurity marking.
Key obligations
- Security 'by design' for products with digital elements.
- Vulnerability management and disclosure + SBOM.
- Patches over the support period.
- CE cybersecurity marking for market placement.
AI Act — AI as a safety component
When an industrial product incorporates an AI system acting as a safety component subject to harmonisation legislation (machinery, equipment), that AI may be classified as high-risk under the AI Act. This is in addition to internal uses (quality control, predictive maintenance), which are most often of limited risk.
Key obligations
- Qualifying AI as a security component (often high-risk).
- Risk management and data quality.
- Human oversight and technical documentation.
- Articulation with machinery legislation.
GDPR — employees, maintenance and clients
Industrial companies process personal data: employees, access badges and video surveillance of sites, maintenance data linked to technicians, and sometimes customer data. They act as data controllers and must maintain a record, implement security measures and govern these processing activities.
Key obligations
- Processing register (HR, site security, maintenance).
- Legal basis and information notice (video surveillance, access badges).
- Security and retention periods.
Comparative overview of regulations
| Regulation | Role of the manufacturer | Flagship obligation | Max. Penalty |
|---|---|---|---|
| NIS2 | Operator / manufacturer | IT/OT risk management | €10 M / 2 % |
| Data Act | Product manufacturer | Access to generated data | By State |
| CRA | Manufacturer | Security by design + vulnerabilities | 15 M€ / 2.5 % |
| AI Act | Provider/deployer | High risk (safety component) | 35 M€ / 7 % |
| GDPR | Accountable | Register + security | 20 M€ / 4 % |
How these regulations interact
For a manufacturer, security is the common thread: NIS2 measures (IT/OT), CRA requirements (product), and GDPR security share a common foundation. Building a security policy that covers both the factory (OT) and the products sold, then breaking it down by regulation, is the most effective approach.
The operator/manufacturer distinction structures everything: NIS2 primarily targets the operator (site security), while CRA and the Data Act target the manufacturer (product security and data). A single industrial group may be both and must address both scopes.
Application timeline
- 1GDPR. In force since May 2018.
- 2Data Act. Majority of obligations applicable from 12 September 2025.
- 3AI Act. Prohibitions since February 2025; high risk (safety components) according to the product timeline, from 2026–2027.
- 4CRA. Entered into force at end of 2024; full obligations by 2027.
- 5NIS2. French transposition in progress; act in anticipation now.
Applicable penalties
Cumulative caps: CRA up to €15M or 2.5%, AI Act up to €35M or 7%, NIS2 up to €10M or 2% (important entities: €7M or 1.4%), GDPR up to €20M or 4%. The Data Act refers to national sanctions.
Industrial risk has a physical dimension: a cyber incident on OT can halt a production line, damage equipment or compromise operator safety — well beyond regulatory sanctions alone.
Compliance roadmap
- 1Map IT and OT. Inventory management systems, industrial systems, connected products sold, and AI components.
- 2Building an IT/OT security foundation. Security policy covering operations and products, vulnerability management, SBOM — serving NIS2, CRA, and GDPR.
- 3Processing products (CRA / Data Act). Security by design and data access for connected products placed on the market.
- 4Qualify AI. Identify AI components classified as security components and produce the required documentation.
- 5Steer. Involve senior management, appoint a DPO and CISO, and establish periodic reviews.
How Data Comply One supports the sector
Data Comply One brings together GDPR, AI Act, NIS2 and DORA on a single platform, with outsourced DPO and CISO — and supports industrial players on the NIS2 (site) / CRA (product) articulation and the Data Act layer.
DCO provides tailored templates (register, NIS2 IT/OT measures, AI Act documentation, CRA/SBOM mapping) to avoid treating each regulation in isolation.
Frequently asked questions
If you manufacture in-scope products (medical devices, electronics, machinery, vehicles) beyond the size threshold, yes, as an important entity. IT/OT security is at the heart of the matter.
Detailed guides by regulation
Where does your compliance stand?
Take stock in a few minutes or talk to an expert dedicated to your sector.
They already trust us
See how organisations in the industry sector secured their compliance with DCO.