# How do OT security vendors sell to manufacturers?

> **The short answer:** OT security vendors sell to manufacturers through the CISO, but plant operations and controls engineering can each veto, and budgets are often split between IT and the plant. Product cybersecurity vendors sell to machine builders’ product security teams. NIS2 and the Cyber Resilience Act create dated reasons to buy. Multi-site OT programmes take an estimated 3–18 months.

- Page: https://panelhop.com/industries/manufacturing/ot-security-product-cybersecurity
- Section: Home › Industries › Manufacturing › OT security, compliance and product cybersecurity software
- Updated 5 October 2026 · Based on Panelhop research, October 2026
- Written for: Vendors of OT security, compliance and product cybersecurity software selling to manufacturers
- Publisher: Panelhop (https://panelhop.com/)

**NIS2 opens the deal. The plant can still stop it.** You sell OT visibility, monitoring and vulnerability management to manufacturing plants, or SBOM and vulnerability-reporting tools to machine builders and device makers under the Cyber Resilience Act. Germany counted 4,095 manufacturing registrations under NIS2 by mid-2026, so the CISO has a reason to buy. Then the plant manager and the controls engineer raise downtime fears, and IT and the plant each expect the other to pay.

- Annual deal: €12–100k for 1–3 sites (Illustrative)
- Sales cycle: 3–18 months, multi-site (Illustrative)
- Buying panel: 5–13 people (Illustrative)

## OT security, compliance and product cybersecurity software · How a deal really moves

**Your deal stalls between IT and the plant. It waits on controls engineers, evidence and who pays.** (Illustrative)

With Panelhop: The same deal, with every veto mapped. Evidence asked at qualification, and each site’s payer named.

One manufacturer, 5–13 people across IT and the plant, and an estimated 3–18 months for a multi-site programme.

What opens a deal:

- **NIS2 duties in Germany** (Regulation · DE)
- **Cyber Resilience Act reporting** (Deadline · EU)
- **Ransomware at a peer** (Security)
- **OEM or prime flow-down** (Contract)
- **New plant or greenfield site** (Funding)
- **New CISO or OT security lead** (Leadership)

The buyer: **A manufacturer in NIS2 scope**. Plant networks, or products under the CRA. 4,095 NIS2 registrations in German manufacturing.

Who decides:

| Seat | What worries them | Can veto |
|---|---|---|
| CISO | NIS2 findings that leave the board liable. | Yes |
| Executive board | A plant shutdown after an attack, and personal liability. | Yes |
| Finance | Paying twice for overlapping tools. | Yes |
| Legal and export control | Data leaving an approved region. | Yes |
| Plant manager | Monitoring or remote access that stops the line. | Yes |
| Controls engineering | Unsupported legacy HMIs and unvetted vendor access. | Yes |
| OT security manager | IT tools that don’t understand industrial protocols. | Yes |
| Product security officer | Missing a reporting duty that already applies. | Yes |

How the deal moves:

| Stage | Typical time | Where it stalls today | With Panelhop | Service |
|---|---|---|---|---|
| Targeting | – | The deadline moved. So did the deal | Weekly signals beyond one date: OT hiring, a peer incident, a new CISO | Signal Desk (In-market accounts, weekly): https://panelhop.com/services#signal |
| Evaluation | – | The CISO said yes. Then the plant objected | CISO, plant manager and controls engineer engaged to exit evaluation | Leak Fix (We build the fixes): https://panelhop.com/services#build |
| Site pilot | – | – | – | – |
| Architecture review | 4–12 weeks | Procurement asks for IEC 62443. Months pass | Required certificates, labels and hosting become qualification fields | Leak Fix (We build the fixes): https://panelhop.com/services#build |
| Budget approval | – | IT and the plant each think the other pays | Who funds which sites, and the fiscal year-end, recorded on the deal | Leak Fix (We build the fixes): https://panelhop.com/services#build |
| Multi-site rollout | – | – | – | – |
| Renewal | – | – | – | – |

With Panelhop across the deal: Signal Desk · weekly on what opens a deal (in-market accounts, scored and mapped); Panel Check on the buyer (coverage baselined); Panel Ops · monthly from the last stage back to the next trigger (scores and plays tuned against the baseline).

*Source: Stages, seats, triggers and stalls from Panelhop research, October 2026; [BSI – Bundesamt für Sicherheit in der Informationstechnik](https://www.bsi.bund.de/DE/Themen/Regulierte-Wirtschaft/NIS-2-regulierte-Unternehmen/NIS-2-in-Zahlen/nis-2-in-zahlen.html); the services as described on the Services page.*
*Note: Durations, panel sizes and cycle lengths are Panelhop estimates from our research, not measurements.*

## At a glance

| Fact | Value |
|---|---|
| Annual deal | €12–100k for 1–3 sites (Illustrative) |
| Sales cycle | 3–18 months, multi-site (Illustrative) |
| Buying panel | 5–13 people (Illustrative) |
| How deals start | A peer incident, a NIS2 audit, a CRA duty or a customer’s flow-down requirement |

*Source: Panelhop research, October 2026.*
*Note: Values marked Illustrative are Panelhop estimates from our research, not measurements.*

## Where do OT security deals with manufacturers leak?

**OT security pipeline leaks at ownership and evidence.**

OT security deals with manufacturers leak where outreach reaches only the CISO, pipeline rests on one deadline, security evidence appears late and nobody owns the budget. Each leak is a gap in the sales system, not in demand.

**Exhibit 1: Where the pipeline leaks: 4 points across 7 stages.**

1. **One deadline moves, and the pipeline goes with it** (stage: Targeting). What you see: Deals tagged to a rule stall when the date moves or buyers decide they are out of scope. Why it happens: Nobody adds a second reason to buy, such as an OEM, prime or retailer requirement. Almost none of the vendors in Panelhop’s analysis ties its offer to a specific obligation.
2. **Outreach reaches the CISO and nobody else** (stage: Evaluation). What you see: The CISO says yes, and controls engineers appear months later with a veto. Why it happens: Plays are built for one persona, while the plant manager and the controls engineer hold vetoes. Panelhop’s research rates this IT and OT ownership gap as very common, because OT security budgets are often split between IT and the plant.
3. **Procurement asks for evidence you never prepared** (stage: Architecture review). What you see: A long questionnaire sits with no owner, and an IEC 62443 line is answered with a white paper. Why it happens: Certifications are not planned against target segments. In Panelhop’s analysis, 15 of 20 vendors publish no vendor-security evidence, and none shows a TISAX label.
4. **Multi-site scope shrinks to one pilot site** (stage: Budget approval). What you see: A programme scoped for many sites becomes one pilot and slips into next year’s plan. Why it happens: Neither IT nor the plant owns the budget, and the deal plan never names who pays for which sites.

*Source: Panelhop research, October 2026.*

## What makes a manufacturer buy OT security or product cybersecurity software?

**Rules, incidents and customers set the security calendar.**

Manufacturers buy OT security and product cybersecurity software after NIS2 duties, Cyber Resilience Act deadlines, a peer incident, a customer’s flow-down requirement, a new plant or a new CISO. Several of these are dated, but dates can move, so stack more than one reason on every account.

**Exhibit 2: The 6 events that open or close the window for a deal.**

- **NIS2 duties in Germany** (Regulation). What happens: Germany’s NIS2 law covers manufacturers in listed sectors with at least 50 staff, or more than €10M in both turnover and balance sheet. Where to spot it: BSI registration statistics, it-sa in Nuremberg each October and job posts for ISMS and OT security roles. Window: Incident reporting, supply-chain duties, management liability and audits keep purchases open through 2026 and 2027. Registration was due within 3 months of the law taking effect in December 2025.
- **Cyber Resilience Act reporting** (Regulation). What happens: Manufacturers of products with digital elements must report actively exploited vulnerabilities from 11 September 2026, and the main obligations apply from 11 December 2027. Where to spot it: Job posts for product security officer and PSIRT roles, and new vulnerability disclosure pages at machine builders. Window: Open now for reporting tools; SBOM and vulnerability handling must be in place before the main obligations apply.
- **Cyber incident at a peer** (Security). What happens: Ransomware or an intrusion halts production at a manufacturer in the same industry. Where to spot it: Material-incident disclosures to the SEC, and security and trade press. Window: Weeks for the victim; peers fund visibility and segmentation in the following months.
- **Customer flow-down requirements** (Contract). What happens: OEMs, primes and in-scope customers pass security duties to suppliers: a TISAX label for automotive data, NIS2 supply-chain clauses or NIST self-assessments for US defence work. Where to spot it: Supplier portals, RFQ requirements and customer security schedules. Window: Every new contract or renewal with that customer.
- **US defence cyber rules (DFARS, NIST)** (Regulation). What happens: US defence suppliers must still self-assess against NIST rules and meet DFARS incident-reporting duties, while CMMC Phase II has been suspended since 13 July 2026. Where to spot it: Prime flow-down clauses, federal solicitations and Department of War memoranda. Window: Every new defence contract or prime requirement; do not anchor pipeline on a CMMC date until the review’s findings are published.
- **New CISO or OT security lead** (Leadership). What happens: A new CISO or OT security manager reviews tools and the split between IT and the plant. Where to spot it: Company announcements and job changes at target manufacturers. Window: The first months in the role.

*Source: Panelhop research, October 2026; [Bundesministerium der Justiz (gesetze-im-internet.de)](https://www.gesetze-im-internet.de/bsig_2025/__28.html); [European Commission](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act); [U.S. Department of War, Under Secretary of War for Acquisition and Sustainment](https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf).*

## Who decides on OT security at a manufacturer?

**Plant managers and controls engineers can stop the deal.**

At a manufacturer, the CISO increasingly owns OT security risk, but the control network, uptime and often part of the budget sit with operations and controls engineering. Under NIS2, management carries liability for security measures, so the board joins larger decisions. When the buyer is a machine builder’s product security incident response team (PSIRT), the panel is product security, engineering and PLM, with no plant veto.

**Exhibit 3: At a multi-site manufacturer in NIS2 scope, 5–13 people sit on the panel and 8 seats can stop the deal.** (Illustrative)

At a multi-site manufacturer in NIS2 scope: 5–13 people.

| Seat | Typical titles | Cares about | Worries about | Can veto |
|---|---|---|---|---|
| CISO | CISO / CSO, Informationssicherheitsbeauftragter | Asset inventory, monitoring and evidence for NIS2, TISAX or customer audits. | NIS2 findings that leave the board liable, and an IT compromise spreading into OT. | Yes |
| OT security manager | OT Security Manager | Segmentation, secure remote access and patch windows the plant accepts. | Tools built for IT that do not understand industrial protocols. | Yes |
| Plant manager | Plant Manager, Werkleiter, VP Operations | Uptime and output. | Monitoring or remote access that stops the line. | Yes |
| Controls engineering | Head of Automation / Controls Engineering, Process Control Manager, Electrical and Instrumentation Lead | Protocol compatibility and no impact on the control network. | Unsupported legacy HMIs and unvetted vendor access. | Yes |
| Product security officer (when the deal covers products) | Product Security Officer | SBOM, vulnerability handling and CRA reporting for products sold in the EU. | Missing a reporting duty that already applies. | Yes |
| Finance | CFO, Plant Controller | Where the cost sits between IT and plant budgets, including sensor hardware per site. | Paying twice for overlapping tools. | Yes |
| Legal and export control | General Counsel, Data Protection Officer, Export Control Officer | Data location, subprocessors and controlled technical data. | Data leaving an approved region. | Yes |
| Executive board | CEO, Vorstand / Geschäftsführung | Cyber resilience and the NIS2 duties that sit with management. | A plant shutdown after an attack, and personal liability. | Yes |

*Source: Panelhop research, October 2026.*
*Note: The panel size is a Panelhop estimate from our research, not a measurement.*

## What do OT security and product cybersecurity vendors sell, and to whom?

**You sell evidence that plants and products are secure.**

OT security vendors sell asset visibility, monitoring, segmentation and vulnerability management to manufacturers for their plant networks, often with sensor hardware per site. Product cybersecurity vendors sell SBOM, vulnerability handling and reporting to manufacturers whose own products contain software. Both position a rule or a standard as the reason to act.

**What vendors of this type sell**

- OT asset inventory and network monitoring
- Secure remote access and segmentation
- OT vulnerability management
- SBOM and product vulnerability handling
- CRA reporting and compliance readiness

**Which manufacturers buy it**

- Multi-site manufacturers newly in NIS2 scope
- Automotive suppliers under OEM and NIS2 supply-chain requirements
- US defence suppliers under DFARS and NIST rules
- Machine builders and electronics makers selling connected products in the EU

## How does an OT security deal move at a manufacturer?

**OT security deals stall between IT and the plant.**

An OT security deal at a manufacturer moves from a trigger through a CISO-led evaluation, a site pilot, architecture review and budget approval to a multi-site rollout. Product security tools sold to a machine builder’s PSIRT usually skip the site pilot and the plant veto, and move on CRA dates and customer requirements. Durations are Panelhop estimates of the manufacturer’s side.

**Exhibit 4: Stage by stage: what you do, what the manufacturer does, and what changes at the 4 stages where deals stall.** (Illustrative)

| Stage | Typical time | What you do | What the manufacturer does | Today | With Panelhop | Service |
|---|---|---|---|---|---|---|
| Targeting | – | Targets CISOs at large manufacturers with deadline messages. | A peer incident, a NIS2 audit, a CRA duty or a flow-down requirement from an OEM or prime puts OT security on the board agenda. | CISOs at large manufacturers, chased with deadline messages. Stalls: A single date as the only reason. Pipeline built on one regulatory date stalls when the date moves or is suspended, as CMMC Phase II was on 13 July 2026. | Each week, manufacturers with a live, dated signal arrive in your CRM, scored on fit and signal strength, with the signal that fired and a reviewed brief. Typical signals are OT security hiring, a peer incident or a new CISO. | Signal Desk (In-market accounts, weekly): https://panelhop.com/services#signal |
| Evaluation | – | Runs a demo and a questionnaire with the CISO’s team. | Security compares visibility, detection and integration with the SIEM and SOC. | The CISO is the only thread. Stalls: Won with the CISO, then silence. The CISO commits verbally, then plant leadership or controls engineering raise downtime and compatibility concerns months later. | A role map per tier puts the CISO, the plant manager and the controls engineer on every OT security opportunity. Coverage is tracked per account, and engaging each of those roles is an exit criterion for evaluation. | Leak Fix (We build the fixes): https://panelhop.com/services#build |
| Site pilot | – | Deploys sensors or a collector at one site. | OT engineering checks passive monitoring and protocol coverage with no impact on control traffic. | The pilot site is whichever site said yes. | The pilot becomes a stage with written success criteria, a multi-site scope and sign-off owners in security, operations and engineering. | Leak Fix (We build the fixes): https://panelhop.com/services#build |
| Architecture review | 4–12 weeks, often in parallel | Answers an IT-oriented questionnaire for an OT product. | Security, OT engineering and legal review segmentation, remote access, hosting and certificates such as IEC 62443 or ISO 27001. | Security evidence is found when procurement asks. Stalls: Evidence nobody prepared. IEC 62443 lines, TISAX labels or US-only hosting for controlled data surface at procurement, and an answer that should already exist takes months. | Required certificates, labels and hosting become qualification fields, and a deal cannot leave the stage while a requirement has no answer. | Leak Fix (We build the fixes): https://panelhop.com/services#build |
| Budget approval | – | Waits while IT and the plant decide who pays. | IT and plant budgets split the cost, and large programmes go to the board, often in the next planning cycle. | The close date assumes a single budget owner. Stalls: No single budget owner. Separate IT and OT budget lines mean nobody owns the funding, so the deal slips into next year’s plan. | Stage exit criteria record who funds which sites, the fiscal year-end and the planning cycle, with forecast accuracy tracked. | Leak Fix (We build the fixes): https://panelhop.com/services#build |
| Multi-site rollout | – | Plans sites one by one, with hardware per site. | Group security rolls out site by site, timed to each plant’s change windows. | Sites are added when someone asks. | With your team, Panel Ops operates the expansion triggers that Leak Fix builds, and retires plays that do not convert. It reports progress against the baseline every month. | Panel Ops (We run it monthly): https://panelhop.com/services#run |
| Renewal | – | Renews and adds sites or modules. | Renews where the tool fed the SOC and passed audits, and questions overlap with other tools. | Renewal is a date in the contract. | A health score built from the handoff brings overlap questions up early, and renewal tasks start well before the renewal date. | Leak Fix (We build the fixes): https://panelhop.com/services#build |

*Source: Panelhop research, October 2026; [U.S. Department of War, Under Secretary of War for Acquisition and Sustainment](https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf).*
*Note: Typical times are Panelhop estimates from our research, not measurements.*

## How does Panelhop help OT security vendors sell to manufacturers?

**Map every veto before the first demo.**

Panelhop helps OT security vendors with a Panel Check (GTM audit) that baselines each stage and drafts tiers from closed-won data, testing site count and NIS2 scope as fit factors. Signal Desk (in-market accounts, weekly), Leak Fix (we build the fixes) and Panel Ops (we run it monthly) then work the stages that leak. AI drafts each brief, we review it and your rep owns every first touch.

What we baseline and report:

1. Opportunities with CISO, operations and engineering contacts at evaluation exit, against the baseline
2. Days from first meeting to the start of security review, against the baseline
3. Share of regulation-tagged pipeline that also carries a customer requirement, against the baseline

## What other vendors sell to manufacturers?

**Other vendor types in manufacturing.**

The same manufacturers buy from these vendor types too, through different panels and pipelines.

- [Enterprise manufacturing software: ERP, planning, PLM, QMS and CPQ](https://panelhop.com/industries/manufacturing/enterprise-manufacturing-software): ERP, supply chain planning, PLM, quality and CPQ software for multi-site manufacturers and engineer-to-order machine builders.
- [Plant-floor AI, sensing and connected worker platforms](https://panelhop.com/industries/manufacturing/plant-floor-ai-connected-worker): Machine monitoring, condition sensors, industrial AI and no-code shop-floor apps sold plant by plant, usually starting with a pilot.
- [Automation lines and engineered capital equipment](https://panelhop.com/industries/manufacturing/automation-systems-capital-equipment): Custom automation lines, special-purpose machines and turnkey production systems sold to manufacturers as capital projects.

[The whole manufacturing market: segments, panel and pipeline →](https://panelhop.com/industries/manufacturing/)

## What do terms like “OT security” and “IEC 62443” mean?

**The words your buyers use, defined.**

Plain definitions of the terms that come up when you sell OT security, compliance and product cybersecurity software to manufacturers.

- **OT security**: Protection of operational technology, the PLCs, SCADA, historians and networks that run production, where uptime and safety come before patching speed.
- **IEC 62443**: The international standard series for the security of industrial automation and control systems. Security reviews of OT products often ask for IEC 62443 evidence.
- **Cyber Resilience Act (CRA)**: The EU law that sets security duties for products with digital elements, connected machines included. Vulnerability reporting applies from 11 September 2026 and the main obligations from 11 December 2027.
- **SBOM**: Software bill of materials: a list of the components inside a product’s software. Machine and device makers use one to handle vulnerabilities under the Cyber Resilience Act.
- **Flow-down requirement**: A security or quality duty a customer passes to its suppliers by contract, such as a TISAX label, NIS2 supply-chain clauses or NIST self-assessments for US defence work.
- **NIS2**: The EU directive on network and information security. Germany’s implementing law puts registration, incident reporting, supply-chain duties and management liability on manufacturers in listed sectors above its size threshold.

## What do vendors of OT security, compliance and product cybersecurity software ask about selling to manufacturers?

**Answers before your next manufacturer deal.**

### Who owns the OT security budget at a manufacturer?

At a manufacturer, ownership of the OT security budget is split. The CISO increasingly owns OT security risk, but the control network, uptime targets and often part of the budget sit with plant operations and controls engineering. The plant manager may not hold the budget but can stop anything that risks the line. Vendors should map security, operations and engineering from the first touch and record who pays for which sites before forecasting a multi-site deal.

### Why do OT security deals with manufacturers take so long?

OT security deals with manufacturers take so long because security, plant operations and controls engineering each hold a veto and part of the budget. The CISO often commits first, and plant or engineering concerns about downtime arrive months later. IT-oriented questionnaires slow review of OT products, and large programmes wait for the next planning cycle. Multi-site programmes take 3–18 months, by Panelhop’s estimate.

### How does NIS2 affect selling OT security to German manufacturers?

NIS2 gives OT security vendors a dated reason to reach German manufacturers, because it makes management liable and pushes duties down to suppliers. Germany’s law covers manufacturers in listed sectors with at least 50 staff, or more than €10M in both turnover and balance sheet. The BSI counted 4,095 manufacturing registrations by mid-2026. Vendors should still pair NIS2 with a second reason, such as a peer incident or a customer requirement.

### Do software vendors need a TISAX label to sell to automotive suppliers?

Software vendors need a TISAX label to sell to automotive suppliers when their product or service handles automotive OEM data, such as prototype data. OEMs require labels from suppliers that handle their data, and those suppliers pass the requirement on to vendors that process it. A deal can wait months for an assessment the vendor has not started, so check the requirement at discovery and plan the label against your target segments.

### What does the Cyber Resilience Act mean for selling to machine builders?

For product security vendors, the Cyber Resilience Act turns machine builders and device makers into buyers with dated duties. Manufacturers must report actively exploited vulnerabilities from 11 September 2026, and the main obligations apply from 11 December 2027. These dates pull product security, SBOM and vulnerability handling into budgets now. The buyer is often a new product security officer or PSIRT lead, alongside engineering and PLM owners.

### Which job postings signal a manufacturer is about to buy OT security?

Job postings for ISMS, OT security and product security roles signal that a manufacturer is building or funding an OT security programme. Hiring for a product security officer or PSIRT lead points to Cyber Resilience Act work at machine builders and device makers. A newly hired CISO or OT security manager usually reviews tools and the split between IT and the plant in the first months in the role. OT security vendors should record each posting on the account with a date and an owner.

## Sources

**Where the numbers come from.**

Sourced figures link to their source below. Figures marked Illustrative, and figures given as estimates, are inferred from Panelhop research. Vendors appear only as types, never by name.

1. [BSI – Bundesamt für Sicherheit in der Informationstechnik, NIS-2 in Zahlen (2026)](https://www.bsi.bund.de/DE/Themen/Regulierte-Wirtschaft/NIS-2-regulierte-Unternehmen/NIS-2-in-Zahlen/nis-2-in-zahlen.html)
2. [Bundesministerium der Justiz (gesetze-im-internet.de), BSI-Gesetz (BSIG), Section 33: Registrierungspflicht (2026)](https://www.gesetze-im-internet.de/bsig_2025/__33.html)
3. [Bundesministerium der Justiz (gesetze-im-internet.de), BSI-Gesetz (BSIG), Section 28: Besonders wichtige Einrichtungen und wichtige Einrichtungen (2026)](https://www.gesetze-im-internet.de/bsig_2025/__28.html)
4. [European Commission, Cyber Resilience Act (2026)](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act)
5. [U.S. Department of War, Under Secretary of War for Acquisition and Sustainment, Implementing Department of War Chief Information Officer’s Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements (2026)](https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf)
- Panelhop research, October 2026: our analysis of the vendors, buying panels, pipelines and triggers for OT security, compliance and product cybersecurity software in manufacturing, from public sources. Vendor names are not published.

## Next step

Find where your pipeline to manufacturers leaks.

[Book a GTM audit](https://panelhop.com/book) · [What the Panel Check covers](https://panelhop.com/services#audit)
