What changes with the new Machinery Regulation, before committing resources
Manufacturer of automation cells for sheet-metal processing·Manufacturing SME·CRA + IEC 62443 pre-analysis in the context of the Machinery Regulation
SERVICES — CYBERSECURITY AXIS
NIS2 changes management's responsibilities for plant security. The CRA imposes continuous obligations on those who manufacture connected machinery or devices. IEC 62443 is the standard becoming the recognized path to demonstrate compliance with both. This page covers the full path: from team training to assessment, from CRA Reporting Ready to annual oversight.
THE CONTEXT
IEC 62443 is no longer just a set of best practices for industrial plant security. CEN/CENELEC is adopting it as a harmonized EN standard: for Italian manufacturers of machinery, embedded systems and connected components, it becomes the recognized path to demonstrate compliance with the Cyber Resilience Act.
Those who don't know IEC 62443 won't be able to document CRA compliance when the deadlines take effect. Those who train their team now arrive prepared — instead of playing catch-up.
The CRA vulnerability-reporting obligation kicks in from 11 September 2026 for products already on the market.
OEM customers already require compliance as a contractual condition in vendor qualification.
NIS2 makes management personally accountable for OT security governance.
THE METHOD
Each module lasts 4 hours, in person or remote, up to 12 participants. In the IEC 62443 domain the workshop deliverable is not a software tool but a process artifact — a map, a checklist, an analysis document — directly applicable to your plant or product.
IEC 62443 TRAINING — STARTING POINT
The 62443-01 module is the mandatory starting point for any IEC 62443 path. It's sellable on its own as an awareness session for management or mixed teams, and provides the conceptual framework that makes all subsequent modules effective.
62443-01 · 4 HOURS · NO TECHNICAL PREREQUISITES
Target: Mixed teams with different backgrounds — technical staff, managers, function heads. Great as an awareness session for management.
Workshop — what you build: A preliminary systems map of the organization — plants, connected products, components — with a first indication of the standard's scope of application.
IEC 62443 TRAINING — TRACKS BY TARGET
After the base module, the path specializes by function. The tracks aren't mutually exclusive: companies with OT plants and connected products often bring OT technicians and R&D teams into the room together, with modules calibrated for both.
MANAGEMENT TRACK · 62443-MGT
For whom: CEO, CTO, General Management. Those who must make decisions on investments, risks and regulatory obligations without needing to know the technical details of the standard.
Workshop: each participant builds an executive risk summary — a concise map of the main risks and the urgent decisions to bring to the board over the next 90 days.
OT / PLANT TRACK · 62443-OT
For whom: OT technicians, plant managers, maintenance managers.
How to conduct an IEC 62443 risk assessment on a real plant. Focus on the operational methodology: asset identification, zone definition, threat analysis and target security level definition.
Workshop: each participant builds a draft zone/conduit diagram and a first proposed target SL for a real plant or system of the organization.
How to move from risk analysis to countermeasure implementation. Focus on the technical and organizational measures defined by the standard and on how to verify their effectiveness.
Workshop: each participant builds a priority countermeasures checklist for their plant, ordered by urgency and estimated implementation cost.
PRODUCT / EMBEDDED TRACK · 62443-PRD
For whom: Designers, R&D managers, product managers of embedded systems and connected machinery.
How to integrate IEC 62443 security requirements into the design phases of a connected product or component. For those who must satisfy the CRA and don't know where to start in their development cycle.
Workshop: each participant builds a security requirements list for a real product or component — functional security requirements traceable to IEC 62443 clauses and CRA requirements.
How to structure the development process to produce components and systems compliant with IEC 62443-4-1 and the CRA process requirements. For R&D teams that must integrate security into their workflow without overturning existing processes.
Workshop: each participant builds a secure development checklist adapted to their development cycle — with the minimum IEC 62443-4-1 controls mapped onto the phases of the existing process.
IT SECURITY TRACK · 62443-SEC
For whom: CISOs, IT security managers, security architects who must extend their perimeter to OT environments.
For those coming from the IT security world who must understand how to manage OT environments with completely different logic, priorities and constraints.
Workshop: each participant builds an IT/OT gap analysis — a map of existing controls, main gaps and governance priorities for the next 12 months.
CROSS-CUTTING MODULE · 62443-CRA
The CRA isn't yet another standard to satisfy separately — it's a set of essential requirements for which IEC 62443 becomes the recognized compliance path. But the mapping between the two isn't automatic: this module shows exactly where the standard covers the CRA requirements and where gaps remain to be handled another way.
62443-CRA · 4 HOURS · CROSS-CUTTING TO OT AND PRD TRACKS
Target: R&D teams, product managers, compliance managers of connected industrial products.
Workshop — what you build: A preliminary compliance map between the CRA requirements applicable to your product and the corresponding IEC 62443 clauses — identifying gaps and priority actions.
TRAINING PATHS
62443-01
For management, mixed teams, a first approach to the standard. Sellable on its own as a company awareness session.
62443-01 + 62443-OT-a + 62443-OT-b
For OT technicians, plant managers, maintenance teams. The team leaves with a draft zone diagram and a priority countermeasures checklist.
62443-01 + 62443-PRD-a + 62443-PRD-b
For embedded designers, R&D teams, product managers. The team leaves with a security requirements list and a secure development checklist.
62443-01 + 62443-PRD-a + 62443-PRD-b + 62443-CRA
The most direct path for those who must start a CRA compliance journey. The team leaves with a compliance map, a security requirements list and a priority action roadmap.
62443-01 + 62443-OT-a + 62443-OT-b + 62443-PRD-a + 62443-CRA
Complete coverage for companies with OT plants and connected products.
Custom — from 2 modules. A free combination for specific needs.
GROUPS up to 12 participants·FORMAT in person or remote·LANGUAGE Italian or English·MATERIALS slides and checklists included·BRIEFING pre-course included
DEADLINE 11 SEPTEMBER 2026
From 11 September 2026, every manufacturer of products with digital elements sold in the European market is obliged to report actively exploited vulnerabilities and severe incidents to ENISA's Single Reporting Platform — on tight timelines: early warning within 24 hours of becoming aware of the event, full notification within 72 hours. The obligation applies to products already on the market. Those without a tested process find out at the worst moment — during an incident.
PHASE 1 — SNAPSHOT · half day
Census of products in CRA scope, of the channels through which the company currently learns of vulnerabilities and incidents, of the people involved. Verification of what already exists.
PHASE 2 — PROCESS BUILD · 1–2 weeks
Design of a vulnerability handling and incident reporting process sized for the company: who receives the report, who assesses, who decides, who notifies. Definition of roles and responsibilities. Preparation of operational templates.
PHASE 3 — TEST AND HANDOVER · 1 day
Tabletop simulation: an exploited vulnerability handled by the team with the new process, against the 24/72-hour clock. Fixing what doesn't work. Handover session with CEO/CTO.
CLOSED SCOPE · 3 WEEKS · DECLARED OUTPUT
Dig into CRA Reporting Ready →ASSESSMENT — L2
An OT assessment exists to understand where you're exposed — on NIS2, CRA and IEC 62443 — with a concrete, not theoretical, snapshot. Those who do it before receiving a vendor qualification request or a letter from the supervisory authority handle the adjustment calmly instead of chasing it.
OT TRACK · 1 DAY · DECLARED OUTPUT
Plant architecture, connected products, vendors, past incidents, existing measures. Interviews with CEO/CTO, IT/OT and production or R&D.
OT TRACK · 2 DAYS · 15–20 PAGE REPORT · ROADMAP
OT/IT architecture, products, critical vendors, existing measures — assessed against IEC 62443, NIS2 and CRA. Extended interviews reaching procurement.
The Radar doesn't oblige you to the Compass. From the Compass, the recurring services open up with no additional onboarding cost — knowledge of the company is already acquired.
ANNUAL OVERSIGHT — CRA COMPLIANCE MANAGER
ANNUAL RENEWAL · SCOPE REVIEWED AT EACH RENEWAL
TRIGGER → PRODUCTS WITH DIGITAL ELEMENTS SUBJECT TO THE CYBER RESILIENCE ACT
The CRA imposes continuous obligations on manufacturers: monitoring product vulnerabilities, managing disclosure, updating technical documentation, maintaining the SBOM. Those who don't oversee these obligations over time risk sanctions of up to 2.5% of annual global turnover and product withdrawal from the European market.
MEMBER ETSI TC CYBER — CYBERSECURITY · ISA IEC 62443 EXPERT PATH
Those who have completed an OT Compass access with no additional onboarding cost. Those arriving without an assessment start with a half-day of initial alignment that includes analysis of the in-scope product.
ANNUAL OVERSIGHT — OT SECURITY ADVISOR
ANNUAL RENEWAL · FORMAL LETTER OF ENGAGEMENT
TRIGGER → CRITICAL OT PLANTS OR CONNECTED INDUSTRIAL PRODUCTS TO KEEP COMPLIANT WITH IEC 62443 AND NIS2
Plants change, vendors change, threats evolve, regulations update. Maintaining compliance and security posture over time isn't manageable with sporadic interventions. This service oversees OT security in a structured way — without having to hire an internal CISO.
ISA IEC 62443 EXPERT PATH · MEMBER ETSI TC CYBER — CYBERSECURITY
The organization must have completed an OT Compass. The service requires continuous access to plant documentation and the IT/OT structure. Formal letter of engagement.
RELATED WORK
If you're not sure of the right starting point — training, CRA Reporting Ready or a direct assessment — the Regulatory Spark is for this: 45 free minutes to understand your real exposure and choose the next step on concrete ground. If you already have a clear idea, write to me directly.
Book the Regulatory Spark