NIS2 Data Act CRA AI Act GDPR

Industrial sector compliance: GDPR, AI Act, NIS2, Data Act & CRA

Industry 4.0 has brought factories within the scope of several European digital regulations. Connected machines, IoT sensors, digital twins, AI for quality control and predictive maintenance: these are all building blocks that expose manufacturers to GDPR, the AI Act, NIS2 (manufacture of critical products), the Data Act (data generated by connected products) and the CRA (products with digital elements placed on the market). This guide covers these texts as applied to the manufacturing industry, distinguishes the role of operator (factory) from that of manufacturer (product sold), and points to in-depth guides.

DPO / CISO team — Data Comply One Updated on 15 June 2026

In brief

  • Regulations concerned: NIS2, Data Act, CRA, AI Act, GDPR.
  • The manufacturer wears two distinct hats.
  • Cumulative caps: CRA up to €15M or 2.5%, AI Act up to €35M or 7%, NIS2 up to €10M or 2% (important entities: €7M or 1.4%), GDPR up to €20M or 4%.
  • For an industrial operator, security is the common thread: NIS2 measures (IT/OT), CRA requirements (product) and GDPR security share a common foundation.

Regulatory deadlines

The key dates of the regulations applicable to your sector.

May 2018

RGPD

Entry into application

In force

January 2023

NIS2

Entry into force (EU directive)

In force

January 2024

Data Act

Entry into force

In force

August 2024

AI Act

Entry into force

In force

October 2024

NIS2

Transposition deadline (EU)

In force

December 2024

CRA

Entry into force

In force

February 2025

AI Act

Ban on prohibited practices

In force

August 2025

AI Act

General-purpose AI models (GPAI) & governance

In force

September 2025

Data Act

Application

In force

2026

NIS2

French transposition (Resilience Act)

In force

August 2026

AI Act

High-risk system obligations (Annex III)

In force

September 2026

CRA

Notification obligation (vulnerabilities & incidents)

Upcoming

August 2027

AI Act

High-risk embedded in products (Annex I)

Upcoming

December 2027

CRA

Full application

Upcoming

Why the 'Industry' sector is concerned

The industrial operator wears two distinct hats. As a site operator, it manages an industrial information system (OT) increasingly connected to IT infrastructure, exposing it to the cyber risks that NIS2 seeks to reduce. As a manufacturer placing a product on the market, it becomes responsible for the security and data of that product under the CRA and the Data Act.

IT/OT convergence is the critical point: a poorly secured sensor or programmable controller becomes an entry point into the production line, with physical consequences (shutdown, sabotage). This is precisely the perimeter that NIS2 and the CRA aim to harden.

Finally, as soon as an industrial product embeds an AI function playing a safety role (for example, the control of a machine), the AI Act may classify it as high-risk, in addition to sector-specific legislation on machinery and product safety.

NIS2 — manufacturing and critical sites

NIS2 covers the manufacture of certain products (medical devices, electronic and computer products, machinery and equipment, vehicles) among important entities, above the applicable size threshold. Manufacturers must implement the risk management measures under Article 21, secure IT/OT convergence, and notify incidents.

Supply chain security — component suppliers, integrators, industrial software publishers — is a central issue.

Key obligations

  • Risk management measures (Art. 21) covering IT and OT.
  • Securing IT/OT convergence.
  • Notification of significant incidents.
  • Industrial supply chain security.
Detailed guide: Industry & NIS2

Data Act — data from connected products

The Data Act requires manufacturers of connected products to make the data generated by the product accessible to the user and to allow its sharing with third parties of the user's choosing. For industry, this covers data from machines, equipment and sensors.

Manufacturers must design their products for data access 'by design' and review their associated service contracts.

Key obligations

  • User access to data generated by the product.
  • Data sharing with third parties designated by the user.
  • 'Data access by design' architecture.
  • Review of associated data service contracts.
Detailed guide: Industry & Data Act

CRA — products with digital elements

The Cyber Resilience Act classifies as a manufacturer any industrial operator placing on the market a product with digital elements (connected machinery, equipment embedding software). It mandates security by design, vulnerability management, an SBOM, patches throughout the support period, and notification of actively exploited vulnerabilities, culminating in CE cybersecurity marking.

Key obligations

  • Security 'by design' for products with digital elements.
  • Vulnerability management and disclosure + SBOM.
  • Patches over the support period.
  • CE cybersecurity marking for market placement.
Detailed guide: Industry & CRA

AI Act — AI as a safety component

When an industrial product incorporates an AI system acting as a safety component subject to harmonisation legislation (machinery, equipment), that AI may be classified as high-risk under the AI Act. This is in addition to internal uses (quality control, predictive maintenance), which are most often of limited risk.

Key obligations

  • Qualifying AI as a security component (often high-risk).
  • Risk management and data quality.
  • Human oversight and technical documentation.
  • Articulation with machinery legislation.
Detailed guide: Industry & AI Act

GDPR — employees, maintenance and clients

Industrial companies process personal data: employees, access badges and video surveillance of sites, maintenance data linked to technicians, and sometimes customer data. They act as data controllers and must maintain a record, implement security measures and govern these processing activities.

Key obligations

  • Processing register (HR, site security, maintenance).
  • Legal basis and information notice (video surveillance, access badges).
  • Security and retention periods.
Detailed guide: Industry & GDPR

Comparative overview of regulations

RegulationRole of the manufacturerFlagship obligationMax. Penalty
NIS2Operator / manufacturerIT/OT risk management€10 M / 2 %
Data ActProduct manufacturerAccess to generated dataBy State
CRAManufacturerSecurity by design + vulnerabilities15 M€ / 2.5 %
AI ActProvider/deployerHigh risk (safety component)35 M€ / 7 %
GDPRAccountableRegister + security20 M€ / 4 %

How these regulations interact

For a manufacturer, security is the common thread: NIS2 measures (IT/OT), CRA requirements (product), and GDPR security share a common foundation. Building a security policy that covers both the factory (OT) and the products sold, then breaking it down by regulation, is the most effective approach.

The operator/manufacturer distinction structures everything: NIS2 primarily targets the operator (site security), while CRA and the Data Act target the manufacturer (product security and data). A single industrial group may be both and must address both scopes.

Application timeline

  • 1GDPR. In force since May 2018.
  • 2Data Act. Majority of obligations applicable from 12 September 2025.
  • 3AI Act. Prohibitions since February 2025; high risk (safety components) according to the product timeline, from 2026–2027.
  • 4CRA. Entered into force at end of 2024; full obligations by 2027.
  • 5NIS2. French transposition in progress; act in anticipation now.

Applicable penalties

Cumulative caps: CRA up to €15M or 2.5%, AI Act up to €35M or 7%, NIS2 up to €10M or 2% (important entities: €7M or 1.4%), GDPR up to €20M or 4%. The Data Act refers to national sanctions.

Industrial risk has a physical dimension: a cyber incident on OT can halt a production line, damage equipment or compromise operator safety — well beyond regulatory sanctions alone.

Compliance roadmap

  • 1Map IT and OT. Inventory management systems, industrial systems, connected products sold, and AI components.
  • 2Building an IT/OT security foundation. Security policy covering operations and products, vulnerability management, SBOM — serving NIS2, CRA, and GDPR.
  • 3Processing products (CRA / Data Act). Security by design and data access for connected products placed on the market.
  • 4Qualify AI. Identify AI components classified as security components and produce the required documentation.
  • 5Steer. Involve senior management, appoint a DPO and CISO, and establish periodic reviews.

How Data Comply One supports the sector

Data Comply One brings together GDPR, AI Act, NIS2 and DORA on a single platform, with outsourced DPO and CISO — and supports industrial players on the NIS2 (site) / CRA (product) articulation and the Data Act layer.

DCO provides tailored templates (register, NIS2 IT/OT measures, AI Act documentation, CRA/SBOM mapping) to avoid treating each regulation in isolation.

Frequently asked questions

If you manufacture in-scope products (medical devices, electronics, machinery, vehicles) beyond the size threshold, yes, as an important entity. IT/OT security is at the heart of the matter.

Detailed guides by regulation

Where does your compliance stand?

Take stock in a few minutes or talk to an expert dedicated to your sector.

They already trust us

See how organisations in the industry sector secured their compliance with DCO.

See testimonials