Shape

Regulatory guides for industry

Practical guides to the regulations reshaping industrial cybersecurity in 2026-2027, and where to start.

Regulatory calendar

The regulatory calendar industrial companies face

The 2026-2027 deadlines to prepare for now

  1. Since 11 Sept 2026

    Cyber Resilience Act: reporting obligations

    Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours.

    Read the guide
  2. 7 Oct 2026

    French Resilience Act (NIS2 transposition)

    Debated in plenary session at the French National Assembly. Obligations will apply once the law, its decrees and orders are published.

    Read the guide
  3. 20 Jan 2027

    Machinery Regulation applies

    New requirements on protecting control systems against corruption and on machinery with evolving behaviour.

    Read the guide
  4. 11 Dec 2027

    Cyber Resilience Act: full requirements

    All essential cybersecurity requirements apply to products placed on the EU market.

    Read the guide

A regulatory deadline is coming up?

Let’s talk about your site or product. One call is enough to know where to start.

Shape