Regulations / Industrial and OT
Regulations by jurisdiction
Industrial and OT: what binds a connected product
Industrial buyers regulate their suppliers through procurement. The standard they cite is IEC 62443; the law that makes them cite it, in Europe, is NIS2.
| Framework | Applies when | Who demands it | In force | Penalties |
|---|---|---|---|---|
| IEC 62443-4-2 | Components deployed in industrial automation and control systems | Operator procurement and tenders | 2019 edition current | None; failing it loses the tender |
| EU NIS2 Directive | Operators in essential and important sectors in the EU; obligations flow down to their suppliers | Operator obligations, passed to component suppliers by contract | Transposition deadline 17 Oct 2024 | Essential entities up to EUR 10M or 2%; important entities up to EUR 7M or 1.4% |
IEC 62443-4-2
Component-level security requirements at four security levels: identification, use control, integrity, confidentiality, data flow, timely response, availability.
EU NIS2 Directive
Risk management, supply-chain security, incident reporting within 24 hours (early warning) and 72 hours (notification) for operators.
Comparisons
- IEC 62443-4-2 vs NIS2 — IEC 62443-4-2 is how an industrial buyer specifies component security in a tender; NIS2 is why the buyer has to.
Check your own product
The IoT security scorecard and the requirements generator resolve these frameworks for your product archetype and markets. Educational reference, not legal advice.
← All jurisdictions