Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

BY INDUSTRY · MANUFACTURING

Plants, products and suppliers in one defensible risk picture.

The corporate CISO has no authority on the shop floor, the plant manager owns production, the group is an important entity under NIS2 and R&D ships products under the CRA. Mindlapse consolidates the picture without pretending to see the PLCs.

NIS2 important entity · CRA on shipped products · Plants as entities · Suppliers both ways

Consolidation · five plants, one group view Illustrative data
Entity Score Risk AnalysisThird partiesExceptionsBusiness ImpactRemediation
Lyon plant 82 4.4 4.1 3.9 4.3 4.0
Gdańsk plant 74 4.0 3.7 3.3 3.9 3.6
R&D centre 69 3.7 3.4 3.2 3.5 3.4
Monterrey plant 61 3.4 3.1 2.4 3.3 2.9
Recent acquisition 43 2.8 1.2 2.1 2.6 2.3
Group average · 3.73.13.03.53.2

Exceptions pile up on the plant with the oldest lines; the acquisition arrives with almost nothing in the third-party column.

THE SITUATION

The plant manager owns the line; the CISO owns the slide.

  1. The plant manager owns production

    The corporate CISO advises; the line stops when the plant manager says so, and not before.

  2. Patched at the next shutdown

    MES, SCADA and HMIs on unsupported systems, vendor-controlled, under exceptions that outlive everyone who signed them.

  3. The acquisition arrives with its own posture

    A plant bought last year, three tools, no register, and the group’s auditor next month.

  4. Security became a CE-marking topic

    Vulnerability handling, support periods and an SBOM that engineering has never produced.

WHO IS IN SCOPE

Who is in scope in manufacturing?

Manufacturers of medical devices, electronics, electrical equipment, machinery, vehicles and other transport equipment, chemicals and food are NIS2 Annex II sectors, mostly as important entities. Makers of products with digital elements fall under the CRA, whose reporting duties come first and whose full obligations follow; machine makers also meet the Machinery Regulation. Some French groups are operators of vital importance under the Code de la défense, a regime the platform does not enter. The CRA page carries the dates; the NIS2 page, the entity test.

Written for

  • Industrial groups with many plants NIS2 important entity, sometimes OIV
  • Automotive and aerospace tiers OEM questionnaires, TISAX as a customer requirement
  • Connected-equipment and machinery makers The CRA and the Machinery Regulation
  • Chemicals and process industries NIS2 Annex II

THE OBLIGATIONS MAP

What NIS2 and the CRA ask of a plant group, and what Mindlapse verifies.

EU rows first; every "verifies" cell is a product claim at ledger level, no cell carries a date, and the French sentence under the table is the site’s one dated source.

What NIS2 and the CRA ask of a plant group, and what Mindlapse verifies.
Regulation Obligation What Mindlapse verifies Surface
NIS2 Art. 21(2)(d) · supply-chain security Proportionate, context-aware supplier assessments, re-assessment on events, contradictions flagged with evidence Supplier Hub
NIS2 Art. 21(2)(e) · secure acquisition, development and vulnerability handling Security requirements attached to initiatives at design; advisories matched to declared systems every morning Security by Design
CRA Art. 13 and Annex I · product risk assessment and essential requirements Requirements carried into your control set with cross-framework mapping; the product risk assessment as living records Control Atlas
CRA Art. 14 · reporting duties Actively exploited vulnerabilities and severe incidents recorded as risks and actions with owners; the notification file drafted by the cascade and logged; you file it Risk Register
NIS2 Art. 20 · accountability across plants Consolidated posture by entity, plants as entities, the management body reading one picture Organization Map
Machinery Regulation Cybersecurity among the essential health and safety requirements The machine’s digital elements assessed in the same product risk assessment; evidence dated Risk Register

NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026.

A QUARTER, THEN THE DAY THE CUSTOMER ASKS

A quarter runs on expiries and events; the OEM’s questionnaire finds the atlas already answered.

Four moments of an ordinary quarter in a plant group, and what the platform had already done; then the day an OEM asks, in three steps.

A quarter in manufacturing, then the request Illustrative data

A normal quarter

  1. alert: WEEK 1

    The acquisition joins the group view.

    Its third-party maturity was flagged on the group view before anyone had opened its register.

    Surface: Organization Map

  2. WEEK 4

    A tier-one integrator’s remote-access derogation expired.

    The expiry reopened the decision with its compensating measures and its approver.

    Surface: Derogation lane

  3. WEEK 8

    The new controller’s CRA risk assessment is updated.

    As living records on the product, with the actions and their owners.

    Surface: Risk Register

  4. verified: WEEK 12

    The OEM answer goes out.

    The plant’s control narrative and the product record, sent from the atlas.

    Surface: Control Atlas

The day the customer asks

  1. THE REQUEST

    An OEM sends its supplier questionnaire and asks for the evidence behind three answers.

    The answers were read from the plant’s verified controls, not written for the occasion.

    Surface: Control Atlas

  2. WHAT OPENS

    The plant’s verified Control Atlas, its derogations, the product record.

    Each derogation with its compensating measures and its expiry; the product record with its risk assessment.

    Surface: Derogation lane

  3. WHAT IS EXPORTED

    The control set, the evidence, the product file.

    The plant’s control set with its evidence from Audit mode, and the CRA Article 13 file as living records.

    Surface: Audit mode

Illustrative quarter: the moments are fictional, the surfaces are the product’s.

FROM THE FIELD

Built with the people who run the lines.

CYBER COLLECTIVE LAB · Edition 2

Third-party risk assessment (TPRM) in the strategic chemicals sector

Third-party risk in strategic chemicals: the edition on assessing the suppliers a process plant cannot pause.

CYBER COLLECTIVE LAB · Edition 3

Field feedback on the Security by Design factory in automotive

The Security by Design factory in automotive: field feedback on securing products at design, inside the OEM’s cadence.

2–3×
risk visibility across the organization
−50–70%
time-to-risk-decision
15–30%
cyber-budget optimization

Measured with our design-partner CISOs, figures under continuous validation.

FAQ

Manufacturing asks

Does Mindlapse connect to our OT or ICS monitoring?

No OT connector today. Lines and the systems behind them are modelled as activities with their impact, and the built-in feeds match advisories to the systems you declare; nothing is read from the PLCs.

Is IEC 62443 in the framework catalog?

Yes. IEC 62443 is in the catalog and maps to the same control set as NIS2 and the CRA, and TISAX is there for the automotive tiers; a control implemented once answers each of them.

Who owns the CRA vulnerability-handling process in a plant group?

The product record does: it carries the risk assessment and its actions with owners, and R&D, the plant and the corporate CISO read the same record at their own altitude.

Can plants keep their own tools and methods?

Yes. Autonomy is a permission model: each plant runs its own register with scales per organization, inherited from the group where you decide, and the group reads the consolidated view without editing the plant’s records.

How do we answer an OEM questionnaire from the platform?

From the verified Control Atlas of the plant, with the evidence behind each answer, and, when the customer runs Mindlapse, through its portal, where answers and action plans synchronize on both sides.

PLANTS, CONSOLIDATED

Bring your plant list and one product. Leave with a consolidation model and a CRA record.

A live session on your structure: plants, tiers, derogations, the group view.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.