UPDATE · AUGUST 2026
The AI Act timeline originally described in this article has been amended by the AI Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July. From 2 August 2026, the transparency obligations under Article 50 apply, and governance and enforcement are fully operational. The obligations for high-risk systems, however, have been postponed to 2 December 2027 (Annex III) and 2 August 2028 (systems integrated into products covered by Annex I, machinery included). The text below has been updated accordingly.
In an increasingly unstable and fast‑evolving geopolitical landscape, the data confirms a clear trend: the European Union is becoming an ever more frequent target of cyberattacks. In 2025, DDoS attacks across Europe increased by 75%, highlighting persistent and critical pressure on essential infrastructures. (source: here)
In parallel, a record average of 443 data‑breach notifications per day was reported, marking a 22% increase compared to the previous year. (source: here)
This trend is not new, and it is no coincidence that in recent years the European Union has developed a series of regulations and directives that will become fully applicable between 2026 and 2028. This new regulatory framework stems from the need to ensure strategic internal security, to protect European citizens and to strengthen the resilience of European‑made products. It is a real and necessary objective — yet navigating this regulatory and certification maze can be complex and challenging. The main risk is losing orientation. Companies risk becoming blinded to the opportunities ahead of them: improved security (and therefore reduced economic losses due to cyberattacks) or the potential competitive advantage inherent in achieving CE conformity — a mark that signals a level of quality and maturity that is almost unmatched globally when it comes to safety and data protection.
The challenges to overcome in this maze are the NIS2 Directive, the Cyber Resilience Act, the AI Act and the new Machinery Regulation. In this article, we will untangle their complexity and provide a practical map and an immediate, usable interpretation framework.
Table of contents
The Path Forward
In recent years we have witnessed an exponential acceleration in industrial digitalisation, driven by Europe’s Industry 4.0 paradigm — a transformation that can be summarised through three interconnected pillars: Information, Security and Quality. As a direct consequence, automation and industrial products have progressively shifted toward deeper OT/IT convergence, moving away from the long‑standing best practice of strict OT network segregation in production and packaging lines, and entering a new era of open, interconnected OT devices.
This openness has brought significant benefits — better control thanks to higher‑quality data collection, increased efficiency in development, and improvements in product quality — but it has also created an entry point for targeted cyberattacks against the supply chain. These attacks have evolved from traditional ransomware focused on extortion, into attempts to alter or degrade the performance and characteristics of the final product.
The European Union, often criticised for bureaucratic slowness, has not remained passive. It has responded with a coordinated regulatory package addressing cybersecurity, physical safety, supply chain resilience and the most recent evolution of artificial intelligence. The strategic objective is clear: strengthen the resilience of the internal market, reduce critical dependencies, and safeguard citizens, companies and Member States.
To achieve this, the EU has expanded the original NIS Directive — broadening the number of critical and important sectors and introducing far stricter governance and supervisory requirements. It has also embedded the concept of security‑by‑design into all products with digital elements, effectively bridging the traditional divide between safety and security. Notably, the security dimension has been extended to explicitly include the cybersecurity of hardware components.
At the same time, the explosive rise of generative and non‑deterministic AI has made it necessary to assess this technology through a risk‑based approach, introducing obligations connected to the use of a tool that is reshaping — and accelerating — the way work processes are conceived and executed.
Context Note: Digital Sovereignty
This regulatory package emerged in a geopolitical environment in which the United States was traditionally considered a reliable and secure technological partner. Over the past year, however, several events have overturned this assumption. It is no coincidence that the topic of digital sovereignty — meaning the independence from extra‑European technological services (particularly U.S.‑based ones) for the state’s critical functions — has become central to European discussions.
France was the first country to take concrete steps in this direction. In June 2025 (source: here), the Chief Legal Officer of Microsoft France admitted under oath before the French Senate that Microsoft cannot guarantee that European data will remain protected from requests by U.S. authorities, even when physically hosted in Europe — a structural conflict between the U.S. CLOUD Act and the EU’s GDPR.
The French response was immediate and practical: by 2027, Microsoft Teams and Zoom will be replaced by Visio (source: here), a videoconferencing platform developed internally by DINUM (Direction Interministérielle du Numérique). Furthermore, France has formally tied public‑sector digital procurement to French and European providers (source: here), reinforcing the strategic shift toward sovereign technological infrastructures.
History snippets
The term Industrie 4.0 was coined in Germany and used for the first time in 2011 at the Hannover Messe, one of the world’s leading industrial trade fairs.
Two years later, in 2013, again in Hannover, Siegfried Dais and Henning Kagermann — chairs of the Industry 4.0 working group — presented the final report that established the founding principles of the paradigm.
In the following five years, organisations around the world published studies on the impact of Industry 4.0 in terms of costs, investments and employment, while major global companies created dedicated research units focused on its implementation.
Italy did not stand by and watch. On 21 September 2016, the Minister of Economic Development, Carlo Calenda, officially launched the National Industry 4.0 Plan, developed on the basis of the findings of the parliamentary inquiry conducted by the Tenth Commission of the Chamber of Deputies. The plan envisaged €23 billion of public investment over four years, including incentives such as 250% hyper‑depreciation and R&D tax credits, specifically designed to support Italy’s industrial landscape — composed largely of small and medium‑sized enterprises and a widespread manufacturing base — in its digital transformation.
In 2017, the plan was updated and rebranded as Impresa 4.0, extending its scope beyond manufacturing to include the services sector.
The main challenge quickly emerged: the misalignment between the rapidly accelerating pace of information technology and the much longer development, validation and industrial adoption cycles typical of mechanical and automation technologies.The Guardians of the Maze
The moment to enter the maze has arrived. As anticipated, this European labyrinth does not have a single gatekeeper. Four distinct regulations guard four different dimensions of digital and industrial security. Anyone operating within this perimeter must contend not with a single rule, but with a coordinated system of overlapping and interwoven obligations.
Understanding what each guardian oversees — and where its jurisdiction ends — is the essential first step to navigating the maze without losing your way.
Network and Information Systems 2 (NIS 2)
NIS2 is the guardian that oversees the inside of organisations: it does not assess the products a company sells or the services it provides to end‑customers, but rather how that company manages its internal processes, systems and cybersecurity risks. This distinction is important to establish from the outset, as it is also the most common source of misunderstanding: the directive does not certify anything — it imposes governance.
Adopted by the European Parliament and the Council on 14 December 2022, NIS2 replaces the previous 2016 NIS Directive, significantly expanding its scope. In Italy, it was transposed through Legislative Decree No. 138 of 4 September 2024, published in the Official Gazette on 1 October 2024 and entering into force on 16 October 2024.
The national competent authority is the Agenzia per la Cybersicurezza Nazionale (ACN), which manages the register of obligated entities and coordinates the implementation of the directive with the support of nine Ministries acting as sectoral authorities.
The Operational Deadlines in Italy:
- 15 January 2026: the full obligation to notify significant incidents to CSIRT Italia enters into force, in accordance with ACN Determination No. 379907/2025. The procedure consists of three mandatory phases: pre‑notification within 24 hours, formal notification within 72 hours, final report within one month.
- October 2026: deadline for the complete implementation of the mandatory security measures. From this date, ACN will begin inspection activities, moving from the support phase to the verification phase.
Who Is Affected? The directive identifies two categories of entities, defined on the basis of the criticality of their sector and the size of the organisation:
- Essential Entities (EES): operate in sectors of high criticality for society and the economy. These sectors include energy, transport, healthcare, water, banking, critical digital infrastructure, the space sector, and financial markets.
- Important Entities (IES): operate in strategic sectors with a lower systemic impact. These include non‑critical digital service providers, lower‑tier telecommunications, non‑primary manufacturing industries, postal services, and waste management.
In practice, the directive introduces the obligation to manage cybersecurity risk in a structured manner: identify it, assess it, and apply documented mitigation measures. This translates into an internal governance model that requires the appointment of dedicated roles and coordinators, the drafting and periodic updating of policies, and — this is the major shift from NIS1 — the direct accountability of the management body.
The Board of Directors can no longer delegate cybersecurity entirely to the IT department; it must approve the measures, oversee their implementation, and receive adequate training.
The directive also brings the concept of supply‑chain control into scope: obligated entities must assess the risks introduced by third‑party suppliers and adopt preventive measures accordingly.
Penalties for non-compliance are calibrated according to the category involved: up to 10 million euros or 2% of the global annual turnover for Essential Entities, and up to 7 million euros or 1.4% of the turnover for Important Entities. Starting from October 2026, the inspection activities of the ACN will also become fully operational.
Cyber Resilience Act (CRA)
If NIS2 looks inside organisations, the Cyber Resilience Act looks outside: at the products that leave the factory and enter the European market.
The two guardians stand on opposite sides of the same doorway, and together they cover the entire perimeter.
There is a structural difference worth clarifying immediately: the CRA is not a directive — it is a regulation. This means it is directly applicable in all Member States without any need for national transposition, no legislative decree, and no room for local adaptation. It enters into force, and it applies.
Published in the Official Journal of the European Union on 20 November 2024 and entering into force on 10 December 2024, Regulation (EU) 2024/2847 introduces, for the first time, mandatory horizontal cybersecurity requirements for all products with digital elements (PDE) placed on the European market.
It covers both hardware and software components and establishes binding obligations across the entire supply chain.
What is a product with digital elements? The definition is broader than one might expect. The following categories fall within its scope:
- Electronic devices with embedded software. Examples include smartphones, computers, routers, printers, IoT devices and smart appliances.
- Hardware components whose correct functioning depends on software (firmware). This includes chips, electronic modules, sensors and programmed boards.
- Products that interact with networks or digital systems and may be exposed to cybersecurity vulnerabilities — even if they are not directly connected to the Internet.
This last point is particularly relevant for the industrial world: an embedded device (e.g., sensors) that does not have direct network access but interacts with digital control systems still falls within the scope of the CRA.
Who is involved? The Regulation distributes responsibility across three distinct actors, each with active obligations.
This is not a linear chain in which passing the product to the next party frees the previous one from responsibility.
The three key actors are:
- Manufacturer: designs or has the PDE assembled on its behalf. They are the primary responsible party, accountable for secure design, patch management, technical documentation, and CE marking. This includes both those who physically manufacture the hardware and those who develop its embedded software.
- Importer: places on the EU market a product manufactured outside the Union. They cannot simply “bring the product in”; they must actively verify CRA compliance and ensure that the manufacturer provides all required documentation and adequate update mechanisms.
- Distributor: markets the product without modifying it. They must ensure that compliance is maintained throughout distribution, that update instructions are accessible to users, and that any risks reported by manufacturers are correctly communicated.
The main obligations revolve around three pillars:
- Vulnerability management: identification, assessment and mitigation of cybersecurity risks throughout the product’s lifecycle.
- Mandatory security updates: timely release of patches for known vulnerabilities, with a minimum guaranteed support period of five years from market placement, unless a shorter, documented and justified useful life applies. Updates must be accessible to users or, where possible, applied automatically.
- CE marking: the product must demonstrate conformity with CRA requirements before being placed on the market. The CE mark becomes, in effect, a signal of cyber‑resilience.
Operational deadlines:
- 11 September 2026: the reporting obligation under Article 14 comes into effect. Manufacturers must notify national authorities and ENISA of actively exploited vulnerabilities affecting their products.
- 11 December 2027: full application of the Regulation. From that date, no product with digital elements may be placed on the EU market unless it complies with the CRA requirements and bears a valid CE marking.
An important clarification for the OT and industrial world: not all software falls under the scope of the CRA.
The key criterion is functional necessity.
The firmware of a machine — essential to its functioning — is included within the regulation’s perimeter.
Supervisory software running on a separate PC and not integrated into the product is not included, or at least not directly.
Everything that is functionally necessary for the automated operation of the product is subject to the Regulation; optional or management‑level applications that live outside the product follow different rules.
This distinction should be clarified with precision during the design phase, as it has significant implications for technical documentation and CE marking.
The penalties for failing to meet CRA requirements are more severe than those of NIS2 in the cybersecurity domain: up to €15 million or 2.5% of the company’s worldwide annual turnover for the most serious violations.
This threshold is higher than that established under NIS2 and reflects the priority the EU assigns to product security as a prerequisite for trust in the digital single market.
AI Act
Continuing our metaphor, the first two guardians protect the physical boundaries of the maze: NIS2 oversees the internal processes of organisations, while the CRA oversees the products that leave the factory.
The third guardian operates on a different plane: it is not concerned with how organisations function or what they produce, but how they make decisions.
The AI Act brings responsibility inside the model itself, into the logic through which an automated system processes data and generates outputs that affect people, rights and safety.
Published in the Official Journal of the European Union on 12 July 2024 and entering into force on 1 August 2024, Regulation (EU) 2024/1689 is the world’s first comprehensive legal framework for artificial intelligence.
Like the CRA, it is a regulation, directly applicable in all Member States without national transposition. The text was amended for the first time by the AI Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, which rewrote its application timeline just days before the 2 August deadline.
Italy has nonetheless moved ahead on the institutional side: with Law 132/2025 it designated the national competent authorities, assigning AgID the functions of notification and accreditation of conformity assessment bodies, and ACN the tasks of supervision, enforcement and cybersecurity — the same agency that oversees the implementation of NIS2.
Risk classification is the architectural core of the regulation.
Unlike NIS2 and the CRA, which define obligations by categories of entities or products, the AI Act evaluates each system based on the impact it may have on individuals and fundamental rights, placing it within a four‑level scale:
- Unacceptable risk: systems prohibited and not allowed on the EU market. This category includes systems that pose a direct threat to fundamental rights, safety or human dignity: social scoring, subliminal behavioural manipulation, real‑time remote biometric identification in public spaces, and systems exploiting vulnerabilities of vulnerable groups. This is not a matter of compliance: these systems cannot exist on the European market. Exclusions: AI systems developed for military purposes or for research are excluded.
- High risk: systems that may cause serious harm to health, safety or fundamental rights if they fail or are misused. This category includes AI systems for medical diagnosis, management of critical infrastructures, recruitment, access to credit or public services, border control, and support to judicial activities. For these systems, the regulation requires: a conformity assessment, a risk‑management system covering the entire lifecycle, technical documentation including training data and bias‑mitigation measures, human oversight, registration in a public European database. The obligations themselves remain unchanged, but the Digital Omnibus has postponed their application (2 December 2027 for Annex III systems, 2 August 2028 for those integrated into products).
- Limited risk: systems that do not present serious risks but may significantly influence users’ experience or decisions. For these, the regulation imposes transparency obligations, applicable from 2 August 2026 (Article 50): informing users that they are interacting with AI, indicating when content is generated by a model, and clearly labelling deepfakes and synthetic content.
- Minimal risk: systems with negligible impact on rights and safety, such as spam filters, AI in video games and non‑critical functions. No specific obligations apply under the AI Act, beyond the general requirements of the EU market. Operators may adopt voluntary codes of conduct.
Who is involved? The AI Act also distributes responsibility along the supply chain, identifying three main actors:
- Provider / Developer: Those who design, develop or produce the AI system. They are the primary party responsible for compliance before market placement, required to produce technical documentation, risk assessments, bias‑mitigation measures, security safeguards and transparency measures.
- Importer / Distributor: Those who introduce the AI system into the EU market or distribute it. They must verify compliance and ensure that instructions, warnings and updates are available to the end‑user.
- User / Deployer: Those who use the AI system for operational or commercial purposes. For high‑risk systems, the deployer is often the least aware of the obligations that apply to them, which include human oversight, incident management and use in accordance with the provider’s instructions. It is worth emphasising: purchasing a high‑risk AI system from an external provider does not transfer all responsibility — part of the obligations remains with the organisation deploying it.
The obligations under the AI Act have extraterritorial reach: they also apply to companies established outside the EU if their systems are used within the European Union or produce effects on individuals located in the EU.
This creates another point of friction with U.S. — and increasingly Chinese — big tech, where the broader topic of digital sovereignty comes back into play.
The implementation timeline follows a series of progressive waves. The original calendar was, however, amended by the AI Digital Omnibus (Regulation (EU) 2026/1744) just days before the main deadline of 2 August 2026, so it is best read in its updated version:
- 2 February 2025: the prohibitions on unacceptable-risk practices and the obligations regarding staff AI literacy come into effect. Systems in this category cannot be placed on the EU market under any circumstance.
- 2 August 2025: governance provisions, obligations for General-Purpose AI (GPAI) models and the sanctioning regime become operational.
- 2 August 2026: the regulation enters its general application phase. The transparency obligations under Article 50 apply (chatbots, deepfakes, emotion recognition), and governance and enforcement become fully operational, with national authorities holding full powers and the Commission able to fine GPAI model providers.
- 2 December 2026: machine-readable labelling of AI-generated content becomes mandatory for systems already on the market, together with two new prohibitions introduced by the Omnibus (generation of non-consensual intimate imagery and of child sexual abuse material).
- 2 December 2027: requirements for high-risk systems under Annex III, those used in areas such as recruitment, credit scoring, biometrics, education and justice. In the original calendar this date was 2 August 2026.
- 2 August 2028: requirements for high-risk systems integrated into products already covered by sectoral legislation (Annex I), including medical devices, machinery and transport systems. In the original calendar this date was 2 August 2027.
This is not a suspension. The postponement stems from the fact that harmonised standards and conformity tools were not ready, and imposing obligations without the means to meet them would have produced uncertainty rather than protection. The time gained, however, should be put to use: mapping the AI systems in operation and classifying them by risk may take months rather than weeks.
The penalties are the most severe in the entire European digital regulatory package, structured on two levels:
- up to €15 million or 3% of turnover for violations of general obligations applicable to providers, deployers, importers and distributors.
- up to €35 million or 7% of worldwide annual turnover for violations involving prohibited unacceptable‑risk practices.
New Machinery Regulation
We have reached the fourth guardian — the one that closes the circle and brings everything back to the physical world. The Machinery Regulation oversees the machines themselves, and it does so at a time when the distinction between physical safety and cybersecurity has, in practice, become impossible to maintain.
A ransomware attack that blocks a motion axis is no longer an IT problem: it is a safety problem.
Published in the Official Journal of the European Union on 29 June 2023 and entering into force on 19 July 2023, Regulation (EU) 2023/1230 replaces the Machinery Directive 2006/42/EC, which had governed the sector since 2009.
Like the CRA and the AI Act, it is a regulation, directly applicable in all Member States without national transposition, eliminating the interpretative discrepancies that the previous directive had generated across national legal systems.
Full application is set for 20 January 2027: from that date, Directive 2006/42/EC is formally repealed, and any machine placed on the EU market must comply with the new Regulation.
What truly changes compared to the old directive? Three structural elements distinguish the new Regulation from the previous framework:
- Cybersecurity as an essential safety requirement: For the first time, cybersecurity explicitly enters the design and construction requirements for machinery (Annex III, points 1.1.9 and 1.2.1). Connected machines must be designed to withstand tampering and unauthorised external access. Cybersecurity is no longer a system‑level optional feature — it is now an integral part of CE conformity.
- Recognition of AI and self‑evolving systems: The definition of “machinery” is updated to include software with safety functions and systems with self‑evolving behaviour based on machine learning. These categories are subject to mandatory conformity‑assessment procedures. A machine that “learns” is a machine that must be certified for what it may become, not only for what it is at the moment it is placed on the market.
- Digital documentation: The Regulation introduces the possibility of providing the instruction manual and the declaration of conformity exclusively in digital format, via QR code, replacing the previous paper requirement.
The concept of substantial modification is probably the most critical — and least understood — aspect of the new Regulation, especially for those managing existing installations.
Any intervention that alters the machine’s safety performance, introduces new risks, or changes the intended use defined by the original manufacturer is considered a substantial modification.
When this occurs, the original CE marking completely lapses, and the party who performed the modification becomes, by law, the new manufacturer, with all the resulting obligations: a new conformity assessment, an update of the technical documentation, and the issuance of a new CE declaration.
Three examples help make the concept concrete:
- Updating supervisory software in a way that introduces new automation functions constitutes a substantial modification and requires a new conformity assessment.
- Replacing a sensor or actuator with an equivalent component that does not affect safety is considered ordinary maintenance and does not require a new conformity process.
- Integrating a new robot into an existing installation is a substantial modification and triggers a mandatory re‑assessment of conformity.
This concept will have significant implications for retrofit and revamping projects on existing installations — a topic we will explore in the next section.
The transition period is still open, but it is rapidly coming to an end.
Until 19 January 2027, it will still be possible to place machines compliant with the old Directive 2006/42/EC on the market, provided they have already been fully manufactured.
From 20 January 2027, this will no longer be permitted.
Machines that have been legitimately placed on the market before that date will retain their conformity unless they are subsequently modified in a substantial way, in which case they fall entirely under the new regulatory regime.
The consequences of non‑compliance follow a different logic compared to the other three regulations: the Machinery Regulation does not establish direct EU‑level financial penalties (these are delegated to national legal systems).
However, the operational consequence is just as clear: without compliance, CE marking cannot be obtained — and without CE marking, the product cannot be placed on the market or put into service within the European Union.
The European regulatory framework on security, digital products and artificial intelligence has become an interconnected ecosystem.
These four regulations do not occupy separate rooms within the maze: their walls touch, and understanding where and how they intersect is just as important as understanding what each individual regulation prescribes — to avoid getting lost and ending up at a dead end.
NIS2, through the adoption of organisational policies and controls, focuses on the protection of critical services and infrastructures, while the CRA safeguards the digital products used by those same infrastructures.
Those who manufacture a device and those who operate it in a critical context bear distinct but complementary obligations over the same object: together, they provide end‑to‑end coverage, from the machine or software all the way to the network and the connected services.
At the same time, AI‑based safety functions integrated into a machine fall under the high‑risk category of the AI Act, yet those same systems must also meet the essential health and safety requirements of the Machinery Regulation.
This creates a dual certification pathway: digital compliance and physical‑safety compliance running in parallel.
A single function must satisfy two regulators with different logics: one assessing AI risk, the other physical safety. Until July 2026 the two deadlines were almost aligned on 2027, which made the overlap manageable within a single compliance pathway. With the Digital Omnibus that alignment no longer holds, at least on paper: the Machinery Regulation applies from 20 January 2027, while the AI Act requirements for high-risk systems integrated into products arrive only on 2 August 2028. That leaves more than eighteen months in which a machine with AI-based safety functions must comply with the Machinery Regulation while the corresponding AI Act obligations are not yet applicable.
That gap, however, is not a regulatory vacuum. The same Digital Omnibus also amends the Machinery Regulation, with a structural change worth noting: the reference to the old Directive 2006/42/EC moves from Section A to Section B of Annex I of the AI Act, updated to refer to Regulation (EU) 2023/1230. It is a shift to a sectoral approach, under which the requirements for high-risk AI systems used as safety components in machinery (or that are themselves machinery) will not remain in the AI Act, but will be incorporated into the Machinery Regulation.
The transfer takes place through delegated acts that the Commission is required to adopt in order to insert into Annex III of the Machinery Regulation the requirements set out in Chapter III, Section 2, and in Articles 17, 19, 72 and 73 of the AI Act. The delegation runs for five years from 27 July 2026.
For anyone designing machinery, this changes how those eighteen months should be read: they are not a window in which AI in machinery falls outside the scope, they are the interval in which the requirements move from one text to another, and they point to where to look right now. Chapter III, Section 2 of the AI Act (risk management system, data and data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity) is a reasonable preview of what will end up in Annex III of the Machinery Regulation. Anyone setting up the safety architecture and the technical file of a machine with AI functions today can align with those requirements before they formally become part of machinery legislation. A margin of uncertainty remains, and it is fair to state it: until the delegated acts are published, the exact wording is not known.
Finally, connected machines equipped with IoT components fall under NIS2 when used by operators of critical infrastructure.
In this context, cybersecurity becomes an integral component of the machine’s physical safety, requiring cyber and mechanical protection measures to be assessed and implemented in a coordinated way.
This overlap is not a flaw in the European regulatory system — it is a structural feature.
Those who read it as a map, rather than an obstacle, can build an integrated compliance pathway instead of four separate ones — and this is exactly what we will explore in the next section.
The Thread of Ariadne: The IEC 62443 Standard
In Greek mythology, Ariadne’s thread did not tear down the walls of the labyrinth — it simply made them navigable.
Theseus did not need to understand the structure of the maze to escape it; he only needed to hold on to the thread.
IEC 62443 works in exactly the same way within the regulatory landscape we have just explored.
It does not replace NIS2, the CRA, the AI Act or the Machinery Regulation, but provides a common technical language for navigating all of them without getting lost — the map we need.
IEC 62443 is the international reference standard for the cybersecurity of industrial OT systems, designed to protect devices, integrated systems and networks from digital threats throughout their entire lifecycle.
It plays a unifying role. Widely recommended in NIS2 compliance documentation as the technical framework for protecting critical infrastructures and services, it can concretely demonstrate the security of digital products under the CRA, and provides the criteria for integrating cybersecurity correctly into machinery systems as required by the Machinery Regulation.
Adopting it is not a formality; it means harmonising IT and OT security requirements into a single coherent, verifiable and continuous framework that spans the entire lifecycle of a plant or a product with digital elements.
The structure of the standard is organised into four fundamental layers, each with a clearly defined scope of application:
- Component layer: covers individual devices and modules, including requirements for authentication, secure credential management, protection against misconfigurations and resilience to known vulnerabilities.
- System layer: concerns the integration of components into a system, internal segmentation, user and role management, and the protection of communication channels.
- Zone & conduit layer: focused on segmenting OT networks into security zones and protected conduits, using industrial firewalls and continuous monitoring to prevent compromises from spreading across different areas of the plant.
- Lifecycle / organizational layer: covers the management of organisational processes, vulnerability management, patching, periodic audits and documentation throughout the entire lifecycle.
Two parts of the standard deserve particular attention for those who need to demonstrate regulatory compliance.
IEC 62443-4-1
It defines the requirements of the Secure Product Development Lifecycle (SDL): security requirements management, vulnerability traceability, configuration control, security testing and verification throughout the development process.
IEC 62443-4-2
It defines the technical security requirements for components, known as Component Security Requirements (CSR), including authentication, communication protection, secure credential and log management, resistance to known vulnerabilities, and configuration controls.
The IEC 62443‑4 certification attests that both the development process and the components meet these requirements, providing verifiable and standardised security that regulators recognise.
To achieve compliance, an organisation must implement both technical and procedural controls across all layers, document all security measures, conduct periodic testing, manage vulnerabilities and updates, and ensure clear accountability among manufacturers, integrators and operators.
This approach mirrors the distributed responsibility model we have seen across all four regulations: no actor is exempt — every role in the supply chain carries its own obligations.
Those who adopt IEC 62443 do not walk through four separate mazes: they walk through a single one, guided by a thread that crosses all four regulatory boundaries at once.
Retrofit or Revamping: They Are Not the Same Thing
Retrofit involves replacing or upgrading components of an existing installation while preserving its original function: a new drive replacing an obsolete one, a more accurate sensor in place of a worn‑out one, an updated interface without modifying the control logic.
The installation performs the same function as before — just more efficiently or with more modern components.
In general, a well‑executed retrofit does not alter the safe behaviour of the machine and does not require a new CE certification, provided it does not introduce new risks.
Revamping is something entirely different.
It involves a substantial modification of the function, control logic, automation or safety of the installation.
New capabilities are added, the way the machine makes decisions is changed, systems that did not previously exist are integrated.
Here, the regulatory perimeter reopens.
In practice, the distinction is not always clear — which is exactly why it is worth understanding it before approving an intervention.
The case of plant extension
One of the most common and ambiguous scenarios is the extension of an existing installation: a new cell, a new line, a new robotic arm.
The intervention may appear limited, but the regulatory criterion is not the physical size of the extension — it is who controls the extension.
If the new section has its own independent safety and control systems, it can be certified as a new autonomous machine.
The intervention is limited: the new section receives its own CE marking, and the existing installation remains under the previous regime.
If, however, the new section ties into the existing control systems, sharing safety logic, PLCs, emergency functions, and interlock circuits, then the intervention is no longer limited.
The modification becomes system‑wide and triggers a re‑assessment of the entire installation.
In this case, the party performing the modification becomes, by law, the new manufacturer of the whole system, with all related obligations.
The practical question to ask is not “How big is the extension?”
but “Does the new section share the safety logic with the existing installation?”
When to look up: warning signs
We introduced this when discussing the new Machinery Regulation, but it is worth expanding.
Not every intervention requires a deep regulatory review, but certain signals indicate that it is worth stopping to reflect before proceeding:
- You introduce or replace software with control or safety functions — even an update that adds new automation features.
- You add connected digital components: IoT sensors, communication modules, remote‑access capabilities. If the component interacts with digital systems, it may activate the CRA perimeter.
- You integrate an AI module or modify the automation logic so the system makes decisions autonomously that it did not previously make.
- The machine operates in a context subject to NIS2: the operator is a critical‑infrastructure entity, and the system’s supply chain falls under security obligations.
- You change the supplier of a critical component — not only the physical component, but also its documentation, firmware, and update lifecycle.
None of these points is automatically a problem: they are simply the moments where a preliminary assessment costs far less than discovering a non‑compliance downstream.
Operational recommendations
Before starting a revamping project, several concrete actions significantly reduce regulatory risk:
- Cross‑regulation preliminary analysis: map which regulations may be triggered by the intervention (Machinery Regulation, CRA, NIS2, AI Act) before defining the technical scope of the project.
- Clarify roles in the supply chain: who designs, who integrates, who provides digital components, who operates the installation. Each role has specific obligations, and unclear overlaps are the main source of documentation gaps.
- Involve a Notified Body when needed: for high‑risk machine categories or when the intervention affects primary safety functions, the assessment of a Notified Body is not just an obligation — it is protection.
- Prepare SBOM and traceability: maintaining an updated Software Bill of Materials for the digital components introduced is the first tool for vulnerability management and CRA compliance.
- Use IEC 62443 as a documentation framework: map zones and conduits of the modified installation, define the target security level of the new configuration, document minimum controls, and manage the integration between legacy systems and modern components. This is the most effective way to make compliance verifiable and communicable across the supply chain.
A revamping carried out methodically is not just a technical upgrade: it is an opportunity to bring a legacy installation into the regulatory perimeter in a structured way, turning an obligation into a solid documentary foundation for the years to come.
Conclusions
In this article, we have walked through a real, articulated and constantly evolving labyrinth. The regulations we have examined — NIS2, the CRA, the AI Act and the new Machinery Regulation — are current obligations, with dates, sanctions and supervisory authorities already in place.
These four guardians oversee different and complementary dimensions: the internal processes of organisations, the digital products placed on the market, the logic of AI systems, and the physical and digital safety of machinery.
Responsibility is distributed across the entire supply chain, and no actor is exempt — from the manufacturer to the final operator.
Their jurisdictions overlap, and these overlaps are not a flaw in the European regulatory system; they are an expression of a strategic intent that must be understood in order to be managed.
There is a thread that helps you avoid getting lost in this labyrinth.
IEC 62443 does not eliminate regulatory complexity, but it provides a common technical language, a verifiable documentation structure and a control framework that cuts across NIS2, the CRA and the Machinery Regulation.
Those who adopt it do not follow four separate compliance paths, but a single one — more solid, more coherent and easier to communicate to customers, auditors and supervisory authorities.
The treasure at the centre of this maze is not the absence of obligations: it is compliance as a competitive advantage.
A company that demonstrates cybersecurity throughout the supply chain, correctly documents its digital products, and maintains a traceable and up‑to‑date cybersecurity governance framework is not simply avoiding penalties — it is building an asset.
In an increasingly demanding European market, CE conformity extended to cyber‑resilience requirements becomes a sales argument, a qualification criterion in public tenders and a differentiation element against extra‑EU competitors who operate without these constraints.
Companies capable of demonstrating security, traceability and solid governance will gain a durable competitive advantage.
At noname.solutions, we support our clients along this entire journey: from the design of secure systems to technical documentation, from the secure development lifecycle to the management of the digital supply chain.
For us, applying the principles behind these regulations is not merely about meeting legal requirements — it is about designing products and services that remain reliable over time.
“Every new technology deserves enthusiasm, but also silence and reflection. Before we ask a machine to decide for us, we should pause and consider what we are no longer deciding together.”
— original quotation created at noname.solutions
👉🏻 Contact us to assess your starting point together.

