The industrial OT compliance challenge
Industrial control systems, SCADA, PLCs, industrial IoT, and connected OT equipment face the most demanding CRA classification: Important Class II — which requires third-party notified body assessment rather than self-certification.
Many industrial OT operators are also NIS2 essential entities in the energy, water, transport, or manufacturing sectors — adding Article 21 security obligations with management personal liability.
The combination requires: IEC 62443 alignment, notified body engagement, NIS2 security programme, and a unified evidence approach that satisfies both regulatory regimes.
CRA classification for industrial products
Important Class II products include (CRA Annex III):
- Industrial automation and control systems (IACS) — specifically those intended for use in critical infrastructure
- Firewalls, IDS/IPS, SIEM for industrial environments
- Industrial routers and switches used in OT networks
- Safety-critical controllers with network interfaces
Conformity assessment: Important Class II requires assessment by an accredited notified body (EU conformity assessment body). Self-certification is not available.
Timeline: Start notified body engagement early. Notified body capacity is limited and audit lead times can exceed 6 months.
IEC 62443 and CRA Annex I alignment
IEC 62443 (Industrial Automation and Control Systems Security) is the primary international standard for OT cybersecurity. Many CRA Annex I requirements align with IEC 62443 controls:
| CRA Annex I | IEC 62443 equivalent | |---|---| | §2(1) No known exploitable vulnerabilities | IEC 62443-2-3 patch management | | §2(3) Unauthorised access prevention | IEC 62443-3-3 SR 1.1–1.3 access control | | §2(5) Minimal attack surface | IEC 62443-3-3 SR 7.7 least privilege | | §2(7) Security monitoring | IEC 62443-3-3 SR 6.1–6.2 audit logging | | §2(8) Secure updates | IEC 62443-2-3 software maintenance | | §2(9) Security by default | IEC 62443-4-2 component requirements |
Strategy: If you are already IEC 62443 certified or pursuing certification, map your IEC 62443 documentation to CRA Annex I requirements. The notified body assessment under CRA can partially leverage IEC 62443 audit evidence — confirm this with your specific notified body.
NIS2 — essential entity obligations for OT operators
OT operators in energy, water, transport, digital infrastructure, and manufacturing may be classified as NIS2 essential entities. Obligations under Article 21:
- Risk analysis and IS policies for OT/ICS environments
- Incident handling — including OT-specific incident classification
- Business continuity for critical OT functions
- Supply chain security — ICS vendor assessment
- Network security — OT/IT network segmentation
- Access control — privileged access to OT systems
- Cryptography — where applicable in OT context
- Training for OT staff on cybersecurity hygiene
- MFA for remote access to OT systems
- Vulnerability management for ICS/SCADA components
Management liability (Art. 20): Management body must approve and oversee the Article 21 measures. Personal liability for failures.
SBOM for industrial products
CRA Annex I Part II §1 requires a machine-readable SBOM. For industrial OT products this includes:
- Firmware components (including RTOS, communication stacks)
- Third-party libraries embedded in controllers
- Open-source components in HMI software
- OTA update packages
Format: SPDX 2.3/3.0 or CycloneDX 1.5. Transitive depth recommended.
OT-specific challenge: legacy components with no PURL or CPE identifiers. Use available identifiers (CPE where PURL unavailable). Document gaps in the SBOM with rationale.
What NexCyber provides for industrial/OT
- CRA scope and class determination: Default vs. Important Class I vs. Important Class II
- Notified body preparation: evidence package aligned to CRA Annex I + IEC 62443
- NIS2 Article 21 mapping: 10 security measures for OT environments
- SBOM completeness tracking: including legacy component handling guidance
- Evidence layer: 10-year retention for technical file, vulnerability log, CVD policy
Tools
- CRA Scope Checker — product class determination (Default/Class I/Class II)
- NIS2 Applicability Checker — essential entity check
- SBOM Readiness Checker — Annex I Part II completeness
- Penalty Calculator — CRA + NIS2 exposure
Related answers
- Audit-ready evidence for CRA
- SBOM under CRA
- NIS2 × CRA overlap
- CRA Article 14 vulnerability reporting
NexCyber — EU Market Access Compliance Platform