Manufacturing Digital October 2026 | Page 105

TECH & AI

JANUARY

2027 the date the EU Machinery Regulation’ s main obligations kick in

industrial machinery must meet, with the main obligations due from January 2027. Compliance, Sheetal says, is becoming“ a design principle for how organisations will need to operate and compete rather than just a legal safeguard.”
Shared ownership of risk Closing the gap, Sheetal argues, is as much organisational as it is technical.“ Cyber risk should be a shared responsibility, anchored in the business and not delegated to the CISO office alone,” he says. Procurement, operations and production leaders should set the risk appetite and decide which assets matter most, while the Chief Information Security Officer function owns the assessment frameworks, segmentation architecture and monitoring that inform those decisions.
That means vendor security requirements belong in procurement contracts, not afterthoughts added once equipment is already running production lines. It means incoming assessments for any new system before it touches the factory floor and continuous monitoring of supplier relationships that already exist. The perimeter manufacturers need to defend now runs the length of the supply chain, and is only as strong as its most connected link.
manufacturingdigtial. com 105