What changes with the new Machinery Regulation, before committing resources
Manufacturer of automation cells for sheet-metal processing·Manufacturing SME·CRA + IEC 62443 pre-analysis in the context of the Machinery Regulation
SERVICES — CYBERSECURITY AXIS
NIS2 changes management's responsibilities for plant security. The CRA imposes continuous obligations on those who manufacture connected machinery or devices. IEC 62443 is the standard becoming the recognized path to demonstrate compliance with both. This page covers the full path: from team training to assessment, from CRA Reporting Ready to annual oversight.
THE CONTEXT
IEC 62443 is no longer just a set of best practices for industrial plant security. CEN/CENELEC is adopting it as a harmonized EN standard: for Italian manufacturers of machinery, embedded systems and connected components, it becomes the recognized path to demonstrate compliance with the Cyber Resilience Act.
Those who don't know IEC 62443 won't be able to document CRA compliance when the deadlines take effect. Those who train their team now arrive prepared — instead of playing catch-up.
The CRA vulnerability-reporting obligation kicks in from 11 September 2026 for products already on the market.
OEM customers already require compliance as a contractual condition in vendor qualification.
NIS2 makes management personally accountable for OT security governance.
THE METHOD
Each module lasts 4 hours, in person or remote, up to 12 participants. In the IEC 62443 domain the workshop deliverable is not a software tool but a process artifact — a map, a checklist, an analysis document — directly applicable to your plant or product.
IEC 62443 TRAINING — STARTING POINT
The 62443-01 module is the mandatory starting point for any IEC 62443 path. It's sellable on its own as an awareness session for management or mixed teams, and provides the conceptual framework that makes all subsequent modules effective.
62443-01 · 4 HOURS · NO TECHNICAL PREREQUISITES
Target: Mixed teams with different backgrounds — technical staff, managers, function heads. Great as an awareness session for management.
Workshop — what you build: A preliminary systems map of the organization — plants, connected products, components — with a first indication of the standard's scope of application.
IEC 62443 TRAINING — TRACKS BY TARGET
After the base module, the path specializes by function. The tracks aren't mutually exclusive: companies with OT plants and connected products often bring OT technicians and R&D teams into the room together, with modules calibrated for both.
MANAGEMENT TRACK · 62443-MGT
For whom: CEO, CTO, General Management. Those who must make decisions on investments, risks and regulatory obligations without needing to know the technical details of the standard.
Workshop: each participant builds an executive risk summary — a concise map of the main risks and the urgent decisions to bring to the board over the next 90 days.
OT / PLANT TRACK · 62443-OT
For whom: OT technicians, plant managers, maintenance managers.
How to conduct an IEC 62443 risk assessment on a real plant. Focus on the operational methodology: asset identification, zone definition, threat analysis and target security level definition.
Workshop: each participant builds a draft zone/conduit diagram and a first proposed target SL for a real plant or system of the organization.
How to move from risk analysis to countermeasure implementation. Focus on the technical and organizational measures defined by the standard and on how to verify their effectiveness.
Workshop: each participant builds a priority countermeasures checklist for their plant, ordered by urgency and estimated implementation cost.
PRODUCT / EMBEDDED TRACK · 62443-PRD
For whom: Designers, R&D managers, product managers of embedded systems and connected machinery.
How to integrate IEC 62443 security requirements into the design phases of a connected product or component. For those who must satisfy the CRA and don't know where to start in their development cycle.
Workshop: each participant builds a security requirements list for a real product or component — functional security requirements traceable to IEC 62443 clauses and CRA requirements.
How to structure the development process to produce components and systems compliant with IEC 62443-4-1 and the CRA process requirements. For R&D teams that must integrate security into their workflow without overturning existing processes.
Workshop: each participant builds a secure development checklist adapted to their development cycle — with the minimum IEC 62443-4-1 controls mapped onto the phases of the existing process.
IT SECURITY TRACK · 62443-SEC
For whom: CISOs, IT security managers, security architects who must extend their perimeter to OT environments.
For those coming from the IT security world who must understand how to manage OT environments with completely different logic, priorities and constraints.
Workshop: each participant builds an IT/OT gap analysis — a map of existing controls, main gaps and governance priorities for the next 12 months.
CROSS-CUTTING MODULE · 62443-CRA
The CRA isn't yet another standard to satisfy separately — it's a set of essential requirements for which IEC 62443 becomes the recognized compliance path. But the mapping between the two isn't automatic: this module shows exactly where the standard covers the CRA requirements and where gaps remain to be handled another way.
62443-CRA · 4 HOURS · CROSS-CUTTING TO OT AND PRD TRACKS
Target: R&D teams, product managers, compliance managers of connected industrial products.
Workshop — what you build: A preliminary compliance map between the CRA requirements applicable to your product and the corresponding IEC 62443 clauses — identifying gaps and priority actions.
TRAINING PATHS
62443-01
For management, mixed teams, a first approach to the standard. Sellable on its own as a company awareness session.
62443-01 + 62443-OT-a + 62443-OT-b
For OT technicians, plant managers, maintenance teams. The team leaves with a draft zone diagram and a priority countermeasures checklist.
62443-01 + 62443-PRD-a + 62443-PRD-b
For embedded designers, R&D teams, product managers. The team leaves with a security requirements list and a secure development checklist.
62443-01 + 62443-PRD-a + 62443-PRD-b + 62443-CRA
The most direct path for those who must start a CRA compliance journey. The team leaves with a compliance map, a security requirements list and a priority action roadmap.
62443-01 + 62443-OT-a + 62443-OT-b + 62443-PRD-a + 62443-CRA
Complete coverage for companies with OT plants and connected products.
Custom — from 2 modules. A free combination for specific needs.
GROUPS up to 12 participants·FORMAT in person or remote·LANGUAGE Italian or English·MATERIALS slides and checklists included·BRIEFING pre-course included
ASSESSMENT
An OT assessment captures where you're exposed — on NIS2, CRA and IEC 62443 — with a concrete, not theoretical, snapshot. The OT track: what I analyze and what you receive item by item, on the dedicated page.
OT Radar
1 day. A 4–6 page document with priority risks and 90-day actions.
OT Compass
2 days. A 15–20 page report with a compliance and mitigation roadmap.
OT track, NIS2 / CRA / IEC 62443 exposure. The Radar doesn't oblige you to the Compass.
Dig into Radar and Compass →ANNUAL OVERSIGHT — CRA COMPLIANCE MANAGER
ANNUAL RENEWAL · SCOPE REVIEWED AT EACH RENEWAL
TRIGGER → PRODUCTS WITH DIGITAL ELEMENTS SUBJECT TO THE CYBER RESILIENCE ACT
The CRA imposes continuous obligations on manufacturers: monitoring product vulnerabilities, managing disclosure, updating technical documentation, maintaining the SBOM. Those who don't oversee these obligations over time risk sanctions of up to 2.5% of annual global turnover and product withdrawal from the European market.
MEMBER ETSI TC CYBER — CYBERSECURITY · ISA IEC 62443 EXPERT PATH
Those who have completed an OT Compass access with no additional onboarding cost. Those arriving without an assessment start with a half-day of initial alignment that includes analysis of the in-scope product.
ANNUAL OVERSIGHT — OT SECURITY ADVISOR
ANNUAL RENEWAL · FORMAL LETTER OF ENGAGEMENT
TRIGGER → CRITICAL OT PLANTS OR CONNECTED INDUSTRIAL PRODUCTS TO KEEP COMPLIANT WITH IEC 62443 AND NIS2
Plants change, vendors change, threats evolve, regulations update. Maintaining compliance and security posture over time isn't manageable with sporadic interventions. This service oversees OT security in a structured way — without having to hire an internal CISO.
ISA IEC 62443 EXPERT PATH · MEMBER ETSI TC CYBER — CYBERSECURITY
The organization must have completed an OT Compass. The service requires continuous access to plant documentation and the IT/OT structure. Formal letter of engagement.
RELATED WORK