NIS2 · CRA · RED
Manufacturing and products
Manufacturing is an important entity under NIS2, and anything you place on the EU market with a radio or a network port now carries RED and CRA duties of its own.
WHAT MAKES THIS SECTOR DIFFERENT
Where the pressure actually comes from
The plant and the product are two different problems that arrive together. On the factory side it is OT segmentation and an estate nobody has mapped since the last line was installed; on the product side it is default credentials, exposed debug interfaces and the duty to handle vulnerability reports for the supported lifetime of the thing you sold.
WHICH RULES CATCH YOU
Start here, in this order
NIS2 / ZInfV-1
Slovenia's Information Security Act, in force since 19 June 2025, took the number of obliged organisations from roughly 100 to roughly 1,000. Risk measures, incident reporting, supply-chain security and training, supervised by URSIV.
Read more 453 days leftCyber Resilience Act
Anyone placing hardware or software with digital elements on the EU market: secure by design, secure defaults, signed updates, and reporting of actively exploited vulnerabilities. Reporting duties start first; full compliance follows on 11 December 2027.
Read more In force nowRED / EN 18031
Since 1 August 2025 every internet-connectable radio product placed on the EU market must meet the cybersecurity essential requirements of the Radio Equipment Directive's delegated act. EN 18031 is the harmonised standard, in three parts: network protection, personal data, and protection from fraud. It already applies to the devices the CRA covers in full from December 2027.
Read moreWHAT WE DO ABOUT IT
The three that matter most here
Penetration testing
A real attack, run by people who have done it for a living, ending in a report your engineers can act on and your auditor will accept.
Read more VMVulnerability management
Continuous discovery, prioritised by what is actually reachable and actually exploited — not by a scanner dumping ten thousand findings on your team.
Read more IoT / OTIoT and OT security
Cameras, controllers and machines that shipped with no security and cannot be patched. We segment them, watch them and stop them talking to strangers.
Read more