Priority sector
Industrial groups and manufacturers face cybersecurity, product, supply-chain and sustainability obligations at the same time.
Key obligations
Manufacturers of medical devices, electronics, electrical equipment, machinery and vehicles are covered by Annex II of NIS2, as are producers of chemicals and food.
Regulation (EU) 2024/2847 sets cybersecurity requirements for products with digital elements, with reporting obligations from September 2026 and full application from December 2027.
AI systems used as safety components of products such as machinery can be classified as high-risk under the AI Act.
Customers, NIS2 and the CSDDD all push due-diligence requirements down the supply chain.
Manufacturers are regulated as operators, as producers of products and as links in other companies' supply chains. Connected machinery and products bring cybersecurity obligations into product design, while large customers demand evidence on security, data protection, human rights and the environment. Industrial groups must apply all of this consistently across plants and countries.
information security: NIS2 measures across IT and production systems, with incident response;
product compliance: readiness for the Cyber Resilience Act and AI Act requirements for products;
supply chain: supplier due diligence and answers to customer questionnaires;
integrity programmes: whistleblowing channels and, in Portugal, RGPC programmes for groups with 50 or more workers.
A free Compliance Assessment maps the obligations that apply to each plant and entity.
Related domains: Cybersecurity (NIS2) · Third-Party & Supply Chain · Sustainability (CSRD/CSDDD) · Artificial Intelligence · Corporate Governance
Regulated functions: Information Security Officer · Compliance Officer · Whistleblowing Officer · All sectors
General information as at October 2026; it does not constitute legal advice.
Request a free assessment designed for industrial groups.