Manufacturing Cybersecurity: NIST CSF 2.0 & ISO 21434
Manufacturing Cybersecurity: How NIST CSF 2.0 and ISO 21434 Strengthen Production Resilience
Manufacturing cybersecurity has become a strategic business priority.
As factories become more connected, production environments increasingly rely on industrial control systems, engineering workstations, PLCs, SCADA platforms, testing stations and connected supply chains. While these technologies improve efficiency and automation, they also expand the attack surface.
For manufacturers, a cyber incident is not simply an IT issue. It can stop production lines, compromise calibration data, disrupt supply chains, damage equipment, affect product quality and potentially impact safety functions.
To stay resilient, organizations need cybersecurity frameworks that address both operational technology and production realities. This is where the NIST CSF 2.0 Manufacturing Profile and ISO 21434 become essential.
Why manufacturing environments are increasingly exposed
Industrial environments face a unique combination of cybersecurity challenges.
Many production sites still operate legacy equipment that was not originally designed with cybersecurity in mind. These systems may rely on outdated protocols, limited visibility, inconsistent security baselines and patching processes that are difficult to implement without affecting uptime.
At the same time, manufacturers increasingly depend on external vendors, remote access, global hardware suppliers, software providers and system integrators. Every third-party connection can introduce additional cyber risk.
This means attackers are no longer targeting only enterprise IT systems. They are also targeting the operational systems that keep production running.
A successful attack can lead to:
- Production downtime and missed delivery commitments
- Unauthorized changes to firmware, software or calibration data
- Disruption of engineering and testing environments
- Loss of visibility across OT assets
- Supply chain compromise
- Reputational and financial damage
Cybersecurity must therefore be integrated into manufacturing operations, not added as an afterthought.
NIST CSF 2.0 Manufacturing Profile: a framework built for operational resilience
The NIST Cybersecurity Framework 2.0 Manufacturing Profile provides a structured way for manufacturers to manage cybersecurity risk while maintaining production continuity.
The framework is built around six key functions:
- Govern
- Identify
- Protect
- Detect
- Respond
- Recover
Together, these functions help organizations create a cybersecurity program that connects governance, risk management, technology controls and operational resilience.
1. Govern: align cybersecurity with business and production priorities
Cybersecurity needs clear ownership.
The Govern function helps manufacturers define responsibilities, decision-making processes, risk thresholds and cybersecurity policies. This creates stronger alignment between cybersecurity teams, engineering, operations, maintenance and executive leadership.
A strong governance model helps ensure that cybersecurity decisions support both business objectives and production continuity.
For example, manufacturers can define how OT systems should be selected, configured, updated and maintained. This reduces inconsistencies across sites and strengthens change-control processes.
2. Identify: gain visibility across production systems
You cannot protect what you cannot see.
The Identify function focuses on creating a complete inventory of production assets, including machines, sensors, networks, applications, servers and connected systems.
This visibility is critical for understanding vulnerabilities, dependencies and operational impact. It also helps organizations identify hidden exposure created by external vendors, remote connections and supply chain partners.
A detailed asset inventory creates the foundation for meaningful risk assessments and stronger compliance with frameworks such as ISO 21434, IEC 62443 and NIST CSF 2.0.
3. Protect: prevent unauthorized access and tampering
The Protect function focuses on securing the systems, tools and data used across the production environment.
This includes controls such as:
- Role-based access control
- Multi-factor authentication
- Least-privilege access
- Network segmentation between IT and OT environments
- Secure firmware handling
- Encryption of sensitive provisioning data
- Hardened engineering workstations and production servers
- Secure update mechanisms
These controls reduce the risk of unauthorized changes, accidental misconfigurations and malicious manipulation of production systems.
In manufacturing, protecting access to critical systems is especially important because privileged actions can directly affect production lines, product configuration and safety-related processes.
4. Detect: identify abnormal activity before it becomes disruptive
Fast detection is essential in OT cybersecurity.
Manufacturers need visibility into network traffic, system logs, configuration changes and authentication events across both IT and OT environments.
Continuous monitoring can help identify anomalies such as unusual PLC commands, unexpected data flows, suspicious privileged access or integrity violations.
The goal is not only to detect threats, but also to detect them early enough to prevent wider operational disruption.
Why ISO 21434 matters in the production phase
ISO 21434 is often associated with vehicle cybersecurity during development. However, cybersecurity requirements must remain protected during production as well.
Production is the point where firmware, software, cryptographic credentials, calibration data and electronic components are configured, validated and finalized. If this phase is not properly secured, cybersecurity requirements defined during development can be compromised before the product even reaches the market.
This is why manufacturers need a rigorous Production Control Plan.
A Production Control Plan should define and secure every tool, process and cybersecurity control involved in manufacturing, including:
- Firmware flashing stations
- Hardware calibration equipment
- Credential provisioning systems
- Secure-boot configurators
- End-of-line testing stations
- Production servers
- Engineering workstations
The objective is to ensure that every interaction with hardware, software and cryptographic materials is controlled, traceable and protected from tampering.
Building an audit-ready production environment
To support ISO 21434 and UN-R155 requirements, manufacturers need both physical and logical protections.
Physical controls can include restricted-access areas, secured cabinets for provisioning devices, surveillance systems and badge-access monitoring.
Logical controls should include authentication, encryption, firmware signing, access control, network segmentation and detailed logging of privileged activities.
However, protection alone is not enough.
Manufacturers also need verification mechanisms to confirm that cybersecurity controls are functioning as intended. This can include manual inspection, automated integrity checks, calibration validation, diagnostic routines, cybersecurity test cases and systematic log reviews.
End-to-end traceability is equally important. Organizations should be able to demonstrate:
- Who performed each production step
- Which tools and versions were used
- Which verification checks were completed
- What results were obtained
- Who approved final production release
This creates a transparent and tamper-evident record that supports regulatory compliance and product trustworthiness.
Download the White Paper
How can your organization align NIST CSF 2.0, ISO 21434 and production cybersecurity without compromising uptime?
Our white paper explores how manufacturers can build stronger cyber resilience across production environments, from governance and OT asset visibility to secure production tools, incident response and recovery.
Inside the white paper, you will discover:
- The key updates in the NIST CSF 2.0 Manufacturing Profile
- How to secure OT environments and production assets
- How ISO 21434 applies during the production phase
- The role of Production Control Plans in preventing tampering
- Practical controls for firmware, calibration, provisioning and traceability
- How to improve incident response and operational resilience
Pour plus d'information
CS Canada
Vincent Besselat, Responsable des ventes
3333 boul. de la Côte-Vertu, Bureau 800, Saint-Laurent, QC, H4R 2N1, Canada
+ 1 (514) 677-8462 – vbesselat@cscanada.ca – www.cscanada.ca
