August 26, 2026

For most UK manufacturers, cybersecurity regulation has historically felt like something that applied to critical national infrastructure rather than to a mid-sized factory in the Midlands or a precision engineering firm in London.
That's changing. The Cyber Security and Resilience Bill proposes to extend the scope of UK cybersecurity regulation significantly. Managed service providers, digital service providers and a wider range of organisations operating essential services are all being brought into scope. And with the EU's Cyber Resilience Act introducing mandatory reporting obligations for manufacturers of connected products from late 2026, the regulatory landscape is shifting in ways that manufacturing businesses can no longer afford to treat as someone else's problem.
Make UK's Cyber Security in Manufacturing report, puts it plainly: cyber resilience is no longer just about protecting data, it's about keeping factories running. The central message is that manufacturers are increasingly targeted precisely because operational downtime creates immediate pressure, and many are operating with IT and OT environments that weren't designed with today's threat landscape in mind.
This article covers what the incoming legislation actually requires, where it applies to manufacturing businesses, and what good cyber compliance looks like on the factory floor.
In this article, we’ll cover:
- What is the Cyber Security and Resilience Bill and does it affect manufacturers?
- What is the Cyber Resilience Act and what does it mean for connected products?
- What are the new cyber incident reporting requirements for UK businesses?
- What is OT security and why is it now a compliance issue?
- How does NIS2 affect UK manufacturers with EU operations?
- What does cybersecurity compliance actually look like on the factory floor?
- How do you know if your manufacturing business is ready?
What is the Cyber Security and Resilience Bill and does it affect manufacturers?
The Cyber Security and Resilience Bill is the UK government's primary legislative response to the growing cyber threat to essential services and digital infrastructure. It reforms and extends the existing Network and Information Systems (NIS) Regulations 2018, which currently apply to operators of essential services and relevant digital service providers.
The Bill's key changes include expanding the scope of regulated entities to include managed service providers; strengthening incident reporting requirements to make them more consistent and timely; and introducing proportionate but enforceable obligations around risk management and security controls.
For manufacturers, the direct applicability depends on whether they fall within the expanded scope, which is still being defined as the Bill progresses through Parliament. However, several factors make this directly relevant to the sector:
Managed service providers are in scope
If your IT infrastructure is managed by an external provider, as is increasingly common in UK manufacturing, that provider's compliance posture directly affects your own security. Understanding what obligations your IT provider is under, and how they're meeting them, is now a legitimate due diligence question.
Supply chain pressure is growing
Even where manufacturers themselves are not directly regulated, their customers and contract partners increasingly are. Cyber Essentials certification (already a requirement for many government supply chain contracts) is likely to become more prevalent as a condition of doing business as the regulatory environment tightens. Our guide to what Cyber Essentials actually covers is a useful starting point if this is new territory.
The direction of travel is clear
The Bill signals that the UK government intends to raise the baseline of cybersecurity across the economy. Manufacturers that treat this as a future concern rather than a present one risk finding themselves behind the curve when obligations crystallise.
What is the Cyber Resilience Act and what does it mean for connected products?
The EU Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for manufacturers of products with digital elements: hardware and software that connect to networks or other devices. It entered into force in late 2024, with reporting obligations applying from late 2026 and the main product security obligations from late 2027.
For UK manufacturers, the key question is whether they sell connected products into the EU market, or produce components that end up in products sold there. If the answer is yes, the CRA applies regardless of where the manufacturer is based.
Under the CRA's reporting obligations, manufacturers must notify the relevant national Computer Security Incident Response Team (CSIRT) within 24 hours of becoming aware of an actively exploited vulnerability, with a more detailed report within 72 hours. This is a demanding timeline that assumes the manufacturer has monitoring infrastructure capable of detecting incidents promptly, and the internal processes to escalate and report them quickly.
For many UK manufacturers, particularly those supplying connected industrial equipment, sensors or control components into EU supply chains, this is a significant gap from where they currently operate. According to Make UK's Cyber Security in Manufacturing report, 31% of manufacturers affected by supplier cyber attacks reported delays to customer deliveries: a reminder that the impact of a cyber incident travels well beyond the organisation where it originates.
What are the new cyber incident reporting requirements for UK businesses?
Under the Cyber Security and Resilience Bill, incident reporting will become more structured, more consistent and subject to clearer timelines. The existing NIS Regulations require operators of essential services to notify the relevant competent authority of significant incidents, but in practice, reporting has been inconsistent, and the definition of what constitutes a reportable incident has been applied unevenly.
The Bill proposes to tighten this up. More organisations will be required to report. Reports will need to be made more promptly. And the information required will be more standardised, giving regulators a clearer picture of the threat landscape across the economy.
For manufacturers, the practical implication is that incident reporting can no longer be treated as an afterthought. It requires preparation, specifically, a documented incident response plan that defines what a reportable incident looks like, who assesses it, who makes the notification decision, and what information needs to be captured. Make UK's research found that only around half of manufacturers have such a plan in place. That's the gap this legislation is designed to close.
The ICO's guidance on personal data breaches is a useful parallel: the 72-hour notification window for personal data breaches under UK GDPR gives a sense of the timelines regulators consider reasonable. The Cyber Security and Resilience Bill is moving the broader incident reporting landscape in the same direction. Our article on what patch management involves and why it matters covers one of the key controls that both reduces incident frequency and supports compliance, since unpatched vulnerabilities are one of the most common routes into manufacturing systems.
What is OT security and why is it now a compliance issue?
Operational Technology (OT) security is the discipline of securing the systems that control physical industrial processes, and it's increasingly where regulators and insurers are focusing attention. The reason is straightforward: as factories become more connected, the attack surface expands, and the consequences of a successful attack extend beyond data loss to production downtime, physical damage and safety risk.
The NCSC's operational technology guidance makes clear that OT environments cannot simply be secured using the same approaches as standard IT. Legacy industrial systems were often designed without cybersecurity in mind, operate on long refresh cycles, and frequently cannot be patched or updated without significant operational planning. These characteristics make them attractive targets and difficult to protect.
What does this mean from a compliance standpoint?
Both the Cyber Security and Resilience Bill and NIS2 treat OT security as in scope for regulated entities. Demonstrating compliance in an OT environment means being able to show (rather than just assert) that you have visibility of your OT architecture, that access to OT systems is controlled and monitored, and that you have processes in place to detect and respond to anomalous behaviour on production networks.
This is a harder bar to meet than many manufacturers realise, and it's one where working with an IT provider that understands the specific constraints of industrial environments makes a material difference. Our article on ransomware explained covers how attacks unfold in practice, useful context for understanding what OT security is actually trying to prevent.
How does NIS2 affect UK manufacturers with EU operations?
The EU's NIS2 Directive, which came into force in late 2024, significantly expanded the scope and requirements of the original NIS Directive. It now covers manufacturers of critical products, including machinery, vehicles, medical devices and certain electronic equipment, as well as digital infrastructure providers and a wider range of essential services.
NIS2 applies to medium and large enterprises operating in covered sectors within the EU. For UK manufacturers, the direct applicability depends on whether they have EU operations, subsidiaries or significant commercial activities in EU member states. Those that do need to understand their NIS2 obligations as a distinct set of requirements alongside the UK's Cyber Security and Resilience Bill.
The commercial impact extends further than direct legal applicability. NIS2 requires in-scope organisations to assess and manage the cybersecurity risks posed by their immediate suppliers, meaning that UK manufacturers supplying into regulated EU businesses may face contractual cybersecurity requirements as a condition of the relationship. This is the supply chain dimension of the legislation, and it's already influencing procurement conversations across manufacturing sectors.
Our guide to IT onboarding and offboarding is tangentially relevant here: one of the most common sources of supply chain cybersecurity risk is poor access management when staff or contractors change, and NIS2's supply chain requirements put a spotlight on exactly these kinds of hygiene issues. For a broader view of the cyber risk landscape facing UK manufacturers, our article on what malware is and how to stay protected covers the threat types that regulatory frameworks are designed to defend against.
What does cybersecurity compliance actually look like on the factory floor?
The key shift that both the Cyber Security and Resilience Bill and the Cyber Resilience Act demand is a move from passive security (having controls in place and hoping they work) to active, demonstrable compliance. That means being able to show that your security controls are effective, that incidents are detected and reported promptly, and that your posture is reviewed and maintained over time.
For a manufacturing business, this translates practically into a compliance programme rather than a compliance event. It involves regular risk assessments that cover both IT and OT environments; documented policies that are actually followed; access controls that are reviewed when staff join, move roles or leave; and monitoring that generates the evidence needed to demonstrate compliance to regulators, customers and insurers.
The Cyber Essentials framework provides a structured baseline covering the five controls most likely to prevent common attacks. It is increasingly expected by public sector customers and is a credible starting point for manufacturers building their compliance posture. The Benefits of Cyber Essentials Plus certification covers why the independently verified version carries more weight than the self-assessment alone.
Almost a third of UK manufacturers either don't have cyber insurance or don't know whether they're covered.
That's a meaningful commercial risk alongside the regulatory one, and insurers are increasingly using Cyber Essentials certification and documented incident response planning as conditions of coverage. Lyon Tech's cybersecurity services are designed to support manufacturers in building the kind of demonstrable, maintained compliance posture that satisfies both regulators and insurers.
How do you know if your manufacturing business is ready?
The honest answer for most manufacturers is: not fully. The combination of new UK legislation, EU regulatory requirements and growing supply chain pressure is creating a compliance environment that most manufacturing businesses haven't yet assessed themselves against.
A structured starting point is to ask four questions:
Do you know which regulations apply to your business, directly, through your IT providers, or through your customer relationships?
Do you have a documented, tested incident response plan that covers both your IT and OT environments?
Can you demonstrate your cybersecurity controls to a customer, insurer or regulator who asks?
And do you have the monitoring capability to detect an incident quickly enough to meet the reporting timelines the legislation requires?
If any of those produce an uncertain answer, the next step is an honest assessment of where the gaps are. Lyon Tech works with manufacturing businesses through exactly that process, from initial infrastructure audit to building the ongoing managed security and compliance support that keeps pace with a changing regulatory environment. Get in touch to start that conversation.
About Lyon Tech
Manufacturing businesses face a growing set of cybersecurity obligations, from the UK's Cyber Security and Resilience Bill to the EU Cyber Resilience Act and NIS2. Lyon Tech provides specialist managed IT services and cybersecurity services for manufacturing and industrial businesses, helping production environments meet their compliance requirements without disrupting operations. Explore our services.


.jpg)
.png)