Solutions · By Industry · Industrial Ot

Industrial & OT

CRA Important Class II and NIS2 essential entity compliance for industrial and OT.

Pain

Class II requires a notified body — no self-certification — and notified body capacity is limited with 6-month lead times.

What you want

Start notified body engagement early, backed by an evidence package that's actually ready.

What you get

CRA class determination, IEC 62443-to-Annex-I mapping, NIS2 Article 21 for OT environments, SBOM legacy-component handling.

The industrial OT compliance challenge

Industrial control systems, SCADA, PLCs, industrial IoT, and connected OT equipment face the most demanding CRA classification: Important Class II — which requires third-party notified body assessment rather than self-certification.

Many industrial OT operators are also NIS2 essential entities in the energy, water, transport, or manufacturing sectors — adding Article 21 security obligations with management personal liability.

The combination requires: IEC 62443 alignment, notified body engagement, NIS2 security programme, and a unified evidence approach that satisfies both regulatory regimes.


CRA classification for industrial products

Important Class II products include (CRA Annex III):

  • Industrial automation and control systems (IACS) — specifically those intended for use in critical infrastructure
  • Firewalls, IDS/IPS, SIEM for industrial environments
  • Industrial routers and switches used in OT networks
  • Safety-critical controllers with network interfaces

Conformity assessment: Important Class II requires assessment by an accredited notified body (EU conformity assessment body). Self-certification is not available.

Timeline: Start notified body engagement early. Notified body capacity is limited and audit lead times can exceed 6 months.


IEC 62443 and CRA Annex I alignment

IEC 62443 (Industrial Automation and Control Systems Security) is the primary international standard for OT cybersecurity. Many CRA Annex I requirements align with IEC 62443 controls:

| CRA Annex I | IEC 62443 equivalent | |---|---| | §2(1) No known exploitable vulnerabilities | IEC 62443-2-3 patch management | | §2(3) Unauthorised access prevention | IEC 62443-3-3 SR 1.1–1.3 access control | | §2(5) Minimal attack surface | IEC 62443-3-3 SR 7.7 least privilege | | §2(7) Security monitoring | IEC 62443-3-3 SR 6.1–6.2 audit logging | | §2(8) Secure updates | IEC 62443-2-3 software maintenance | | §2(9) Security by default | IEC 62443-4-2 component requirements |

Strategy: If you are already IEC 62443 certified or pursuing certification, map your IEC 62443 documentation to CRA Annex I requirements. The notified body assessment under CRA can partially leverage IEC 62443 audit evidence — confirm this with your specific notified body.


NIS2 — essential entity obligations for OT operators

OT operators in energy, water, transport, digital infrastructure, and manufacturing may be classified as NIS2 essential entities. Obligations under Article 21:

  1. Risk analysis and IS policies for OT/ICS environments
  2. Incident handling — including OT-specific incident classification
  3. Business continuity for critical OT functions
  4. Supply chain security — ICS vendor assessment
  5. Network security — OT/IT network segmentation
  6. Access control — privileged access to OT systems
  7. Cryptography — where applicable in OT context
  8. Training for OT staff on cybersecurity hygiene
  9. MFA for remote access to OT systems
  10. Vulnerability management for ICS/SCADA components

Management liability (Art. 20): Management body must approve and oversee the Article 21 measures. Personal liability for failures.

NIS2 implementation guide


SBOM for industrial products

CRA Annex I Part II §1 requires a machine-readable SBOM. For industrial OT products this includes:

  • Firmware components (including RTOS, communication stacks)
  • Third-party libraries embedded in controllers
  • Open-source components in HMI software
  • OTA update packages

Format: SPDX 2.3/3.0 or CycloneDX 1.5. Transitive depth recommended.

OT-specific challenge: legacy components with no PURL or CPE identifiers. Use available identifiers (CPE where PURL unavailable). Document gaps in the SBOM with rationale.


What NexCyber provides for industrial/OT

  • CRA scope and class determination: Default vs. Important Class I vs. Important Class II
  • Notified body preparation: evidence package aligned to CRA Annex I + IEC 62443
  • NIS2 Article 21 mapping: 10 security measures for OT environments
  • SBOM completeness tracking: including legacy component handling guidance
  • Evidence layer: 10-year retention for technical file, vulnerability log, CVD policy

Tools


Related answers


NexCyber — EU Market Access Compliance Platform

Versus what you do today

Big4 consulting · In-house spreadsheet · NexCyber.

DimensionBig4 / ConsultingIn-house spreadsheetNexCyber
First assessment delay
4–8 weeks
2–6 weeks
5 minutes
Cost per regulation cycle
€90k–170k
€30k+ hidden
Included
Reproducibility
Slide deck of the day
Depends on editor
Deterministic, identical re-runs
Article-level traceability
Footnote
Often missing
Live link to EUR-Lex
Update when law changes
Re-billed mission
Restart from scratch
Automatic, MRCC re-signed
Deliverable format
Static PDF
XLSX/Word
PDF + MRCC machine-verifiable
Auditor verification
Email + chase
Not verifiable
sha256 verified in seconds
Multi-regulation simultaneous
1 mission per regulation
Duplicates & conflicts
5 regulations, 1 source of truth
New product line evolution
Re-billed mission
Full re-entry
Clone + delta
Run free assessment