
- Digitalization
Categories:
OT cybersecurity is evolving from a purely technical concern into a key factor in operational continuity, market access and corporate trust.
In sectors such as energy, mobility and data centers, complying with NIS2 and the Cyber Resilience Act (CRA) is not simply about avoiding penalties. It means demonstrating that digital services, systems and products can withstand, respond to and recover from increasingly complex threats.
NIS2 strengthens the resilience of organizations and their critical services.
The CRA embeds security by design into products with digital elements placed on the European Union market.
The Directive explicitly covers sectors such as energy, transport, digital infrastructure, cloud service providers and data centers. For manufacturers and industrial integrators, this regulatory convergence requires governance, engineering, operations, the supply chain and the product lifecycle to be interconnected.
Dcode helps turn these obligations into tangible capabilities and business outcomes.
A timeline that demands action

The 2026–2027 period will be decisive:
- September 11, 2026: The CRA’s reporting obligations begin to apply. Manufacturers will be required to report certain actively exploited vulnerabilities and severe incidents affecting the security of their products. The deadlines include an early warning within 24 hours and a main notification within 72 hours.
- December 11, 2027: Most CRA obligations will become applicable, including lifecycle security requirements, vulnerability management, technical documentation and conformity assessment procedures.
- NIS2: Although the Directive was due to be transposed by October 17, 2024, Spain is still finalizing its national implementation framework. This situation should not delay preparations by affected organizations, particularly those operating in critical sectors.
For manufacturers and integrators, the direct consequence of this timeline is that vulnerability management, incident response, product update and evidence-gathering processes must be operational before the full application date.
The impact on OT manufacturers and integrators
In industrial environments, a product cannot be assessed in isolation. A control system, connected device, monitoring platform, industrial gateway or remote-access solution may form part of an essential service and become a critical element in the supply chain.
NIS2 requires organizations to manage risks associated with their suppliers, services and systems. It also requires prevention, detection, response, continuity and recovery capabilities, as well as mechanisms for reporting significant incidents within 24 and 72 hours, followed by a final report.
The CRA, for its part, primarily affects manufacturers and other parties that place products with digital elements on the European market. Industrial integrators play an essential role because they must incorporate security requirements into solution design, component selection, configuration, commissioning and maintenance.
The specific responsibilities will depend on each company’s business model and position in the value chain. An integrator that markets a solution under its own brand or makes substantial modifications may assume obligations similar to those of a manufacturer.
In both cases, organizations must have demonstrable capabilities in:
- Risk management and security policies.
- Security by design and by default.
- Incident-response capabilities.
- Business continuity and disaster recovery.
- Supplier and supply-chain management.
- Vulnerability and update management, encryption and access control.
- Incident prevention, detection and response.
- Crisis exercises and assessments of the effectiveness of security measures.
- OT threat and risk analysis.
- Network segmentation and communications control.
- Employee training and awareness.
- Technical documentation and verifiable evidence.
Aligning NIS2, the CRA and IEC 62443
The most effective strategy is not to create three separate compliance programs. It is to use IEC 62443 as a technical reference for structuring OT security and connecting it to NIS2’s organizational obligations and the CRA’s product-related obligations.
The ISA/IEC 62443 series provides requirements and processes for implementing and maintaining secure industrial automation and control systems throughout their lifecycle. It covers system-, component-, process- and organization-related aspects.
A practical alignment can be structured as follows:
| Need | Primary Framework | Application in OT |
| Governance, risks and incidents | NIS2 | Policies, roles, CSIRT, continuity and reporting |
| Product security | CRA | Security by design, vulnerabilities, updates and conformity |
| Industrial architecture and controls | IEC 62443 | Zones and conduits, security levels, and system and component requirements |
| Supply chain | NIS2 + CRA | Supplier assessment, contracts, dependencies and evidence |
| Secure development and integration | CRA + IEC 62443 | Requirements, testing, hardening, configuration and maintenance |
IEC 62443 does not, by itself, replace NIS2 or the CRA. Its value lies in providing a recognized technical foundation for translating regulatory requirements into specific architecture, engineering, operational and maintenance requirements.
Dcode, Sener’s digital division, supports organizations throughout this journey, from interpreting the regulatory scope and conducting the initial assessment to implementing controls, preparing evidence and driving continuous improvement.
From compliance to trust
Aligning these frameworks can become a competitive commercial advantage. Manufacturers and integrators that demonstrate cybersecurity maturity are better positioned to respond to tenders, qualification processes and supplier assessments.
Value is generated in four areas:
- Continuity: A lower likelihood of downtime and stronger recovery capabilities.
- Efficiency: Requirements and evidence that can be reused across projects, customers and audits.
- Market access: Greater readiness to operate in regulated sectors and supply chains.
- Trust: The ability to demonstrate how products and services are designed, integrated, updated and protected.
Dcode helps turn this regulatory requirement into a competitive capability through scope analysis, gap assessments, secure OT architecture, alignment with IEC 62443, vulnerability management, product security, supplier assessments and evidence preparation.
The objective is not to address an audit as an isolated exercise. It is to build demonstrable cyber resilience that protects operations, improves products and strengthens relationships with customers, partners and authorities.
In energy, mobility and data centers, the question is no longer whether cybersecurity affects the business. The question is whether the organization will be able to demonstrate it before its competitors do.
- cybersecurity






