Industries · Manufacturing and robotics

Manufacturing cybersecurity: the plant, the machines and the robots

A medium-sized or large machinery maker is an important entity under NIS2 in Poland (KSC), and from 20 January 2027 its new machines must also meet the cybersecurity requirements of the EU Machinery Regulation. We work on both sides: the plant where you build, and the product you ship.

// In short

Two regimes: one for the plant, one for the product

The KSC Act covers makers of medical devices, electronics, electrical equipment, machinery, motor vehicles and other transport equipment (NACE divisions 26 to 30), plus chemicals and food. Medium and large companies in these sectors are important entities. Separately, the Machinery Regulation and the Cyber Resilience Act (CRA) set requirements for the products themselves.

As of 24 September 2026. Sources: Dz.U. 2026 item 252, Annex 2 (in Polish), Regulation (EU) 2023/1230.

The plant: when the KSC Act covers you

Manufacturing under the KSC Act, as of 24 September 2026
What you makeWhere in the actCategory
Machinery and equipment (NACE division 28), electrical equipment (27), computers and electronics (26), motor vehicles (29), other transport equipment (30)Annex 2, manufacturing sectorImportant entity, if at least medium-sized
Medical devices and in vitro diagnostic devicesAnnex 2, manufacturing sectorImportant entity
Chemical substances and mixtures (REACH), including their distributionAnnex 2, chemicals sectorImportant entity
Food: industrial production and processing, wholesale distributionAnnex 2, food sectorImportant entity
Basic pharmaceutical products and preparations (NACE division 21)Annex 1, health sectorEssential entity if large, important if medium-sized
  • Any activity counts, not just the main one. For divisions 26 to 30, the annex covers companies carrying out any of those activities.
  • Group subsidiaries. The size thresholds count the whole group. Exception: your information systems are independent of the group's systems, or you do not provide services jointly with the other group companies (Article 5(6) and (7)).
  • No periodic audit for important entities. The authority can order one by decision after a serious incident or another breach of the act (Article 15(1b)). Chapter 3 obligations apply from 3 April 2027.
  • Supervision. The competent authority for manufacturing is the minister responsible for the economy, and for medical devices the minister of health (Article 41(9f) and (9g)).

Source: Dz.U. 2026 item 252 (in Polish). The full list of obligations is on NIS2 compliance in Poland (KSC).

// Deadlines

Three dates for manufacturers

  1. Machinery

    The Machinery Regulation applies

    It covers machinery placed on the market from this date. Machinery placed on the market earlier in line with Directive 2006/42/EC can still be made available (Article 52(1)).

    Regulation (EU) 2023/1230 (opens in a new tab)
  2. KSC

    Chapter 3 of the KSC Act

    ISMS, risk, incidents, business continuity, supply chain, assets and yearly management training. The scope includes the OT that production depends on.

    Act text (Dz.U. 2026 item 252) (opens in a new tab)
  3. CRA

    Full application of the Cyber Resilience Act

    Covers products with digital elements that connect to a device or network. Reporting of actively exploited vulnerabilities and severe incidents has applied since 11 September 2026.

    European Commission (opens in a new tab)

As of . Sources: Regulation (EU) 2023/1230 with its corrigendum, Dz.U. 2026 item 252 (in Polish), ENISA.

The product: what the Machinery Regulation requires

  1. Connecting a device creates no hazard (Annex III, 1.1.9)

    Connecting another device to the machine, including a remote one, must not lead to a hazardous situation.

  2. Safety-critical software and data are protected

    They must be identified and protected against accidental or intentional corruption. At any time, the machine can tell you which software it needs to operate safely.

  3. The machine records evidence of interventions

    It collects evidence of legitimate and illegitimate interventions in its software, its configuration and the relevant hardware components. That is the evidence a customer will ask for after an incident.

  4. Control systems withstand attack attempts (1.2.1)

    Where the circumstances and risks call for it, the control system has to withstand reasonably foreseeable malicious attempts by third parties that could lead to a hazardous situation.

  5. A five-year log of safety software changes

    A tracing log of interventions and of safety software versions uploaded after the machine was placed on the market stays available for five years after each upload (1.2.1, point (f)).

An integrator can become the manufacturer

A substantial modification to a machine, including one made by digital means, that the manufacturer did not foresee and that affects safety makes whoever carried it out the manufacturer, with all the obligations (Article 3(16) and Article 18). If the machine has networked digital elements, the CRA adds vulnerability handling and reporting through the ENISA platform. Medical devices and vehicles covered by their own regulations are outside the CRA (Article 2(2)). More on the CRA: compliance and audit.

// Risks

Where plants most often lack evidence

A control you cannot show in the system won't pass an audit, or a security questionnaire from an automotive or medical customer.

  • A flat network between office and shop floor

    The engineering workstation reaches both the internet and the PLCs. There are no zones and no controlled conduits between them, and the only current map of IT and OT connections is in one person's head.

    Missing evidence: a zone and conduit map with firewall rules and a review date.

  • Remote service access for machine vendors

    Integrators and machine builders connect through their own modems or remote desktop tools. Nobody knows how many entry points exist, and sessions are not logged.

    Missing evidence: a list of remote access paths with an owner, session approval and a log.

  • An OT asset list kept in a spreadsheet

    PLCs, HMI panels, firmware versions and who may change them. The KSC Act requires asset management (Article 8(1)(2)(m)), and last year's spreadsheet does not show today's state.

    Missing evidence: an inventory built from passive network monitoring, with vendor and version.

  • PLC programs and recipes backed up, never restored

    Backups of PLC programs exist, but nobody has measured how long it takes to bring a line back after a failure or a ransomware attack on the shop floor servers.

    Missing evidence: a restore test result with a date and duration.

// How we help

Services that fit the plant and the product

  1. 01Plant

    OT security based on IEC 62443

    Network zones and conduits, a review of vendor remote access and a passive device inventory. Active tests only in a test environment, never on a running line.

    First step, 6 weeks

    One production hall, from network to PLC

    • Zone and conduit map
    • Remote access list with owners
    • 90-day remediation plan

    Key deliverable: vendor remote access under control: named account, session approval and log

    IEC 62443 and OT
  2. 02Product

    Machines ready for the Machinery Regulation and the CRA

    Gap analysis against points 1.1.9 and 1.2.1 of Annex III and the CRA requirements, security testing of the controller, the service app and remote access, and a vulnerability handling process.

    • List of safety-critical software
    • Intervention records and version log
    • An SBOM for every software release
    Cyber Resilience Act
  3. 03Compliance

    KSC for an important entity

    An ISMS that includes OT, an asset register fed from systems, management training (Article 8e) and evidence-backed answers to customer questionnaires.

    NIS2 compliance in Poland
  4. 04Data

    Production data with an owner

    Data from MES, ERP and quality systems with documented lineage. One OEE definition instead of three reports that don't match.

    Data governance

// Scope

What we do, and what we don't

We agree the scope and date in writing before we start.

We do

  • Passive inventory and traffic analysis on the OT network
  • IT and OT architecture reviews based on IEC 62443
  • Penetration tests of IT, service apps and OT test environments
  • Gap analysis against the KSC Act, the Machinery Regulation and the CRA

We don't

  • Active scans or tests on a running production line
  • Conformity assessment or CE marking of a machine: that is the manufacturer's obligation
  • IEC 62443 certification
  • Reselling OT tool licenses

We designed FutureCode Evidence Box for manufacturing and robotics, among other industries: it works inside your network without internet access and never runs active tests on OT.

// FAQ

Questions from manufacturers

We build machines and robots. Does the KSC Act apply to us?

If you carry out an activity in NACE division 28 (machinery and equipment) or in divisions 26, 27, 29 or 30 and you are at least a medium-sized company, yes: as an important entity under Annex 2. At least medium-sized means 50 or more staff, or annual turnover over EUR 10 million and a balance sheet total over EUR 10 million. As of 24 September 2026.

We are a subsidiary of a large group. Does our size count, or the group's?

As a rule, the group's, because the figures of linked and partner enterprises are added up. If your information systems are independent of the group's systems, or you do not provide services jointly with the other group companies, the act will not treat you as an entity just because of the group's size (Article 5(6) and (7)). Document it.

Does the Machinery Regulation cover machines we already run?

It applies to machinery placed on the market from 20 January 2027. Machinery placed on the market earlier under the Machinery Directive can still be made available. Watch out for retrofits: a substantial modification that affects safety, including a software change, makes whoever carried it out the manufacturer of that machine (Article 18).

Do you test PLCs and the OT network?

On a running line, only passively: we observe traffic and configuration. Active tests happen in a test environment or on spare hardware, after the rules of engagement are signed. We test IT systems, service apps and remote access the usual way.

Is IEC 62443 mandatory?

It is a series of standards, not a law. Neither the KSC Act nor the Machinery Regulation requires it by name. Its zones and conduits and its security levels are still a practical way to meet the network, access and supplier requirements in OT.

From the blog: security and data

Let's start with one production hall

In 30 minutes we work out whether the KSC Act covers you, which machines will fall under the new regulation, and where to start in OT.

Book a 30-minute call

Prefer the scope in writing?

Describe the plant and the line you want to start with. We will send back the scope and date of the first step. We reply within one business day.

Request the first step