Skip to main content
FromNine
Menu

Manufacturing & Industry

From shop-floor signal to business decision.

What we build for manufacturers: IT/OT integration that respects the control layer, operational data for quality and maintenance, service knowledge where the technician stands, and the product data new EU rules require.

For manufacturers running plants in several European countries, with different languages on the shop floor and one group-wide view to keep.

Close-up of machined metal with fine toolpath lines
  1. 1 January 2026

    CBAM definitive period starts

    Importers of covered goods move from transitional reporting to the definitive regime.

    SourceRegulation (EU) 2023/956 (opens external site)

  2. 12 September 2026

    Data access by design for connected products

    New connected products must make the data they generate accessible to users.

    SourceRegulation (EU) 2023/2854 (opens external site)

  3. 11 December 2027

    Cyber Resilience Act fully applies

    Products with digital elements need secure design and vulnerability handling to carry the CE mark.

    SourceRegulation (EU) 2024/2847 (opens external site)

What is changing on the shop floor

  1. Products now carry data obligations

    The Data Act, the Cyber Resilience Act, the Ecodesign Regulation and the battery passport all reach into product design. Data access, security updates and product passports become part of what you ship.

    SourceRegulation (EU) 2024/2847

  2. IT and OT are converging

    Plant data is needed in the cloud, while control systems must stay safe and available. NIS2 brings several manufacturing sectors into scope, and IEC 62443 sets the vocabulary for zones and conduits.

    SourceDirective (EU) 2022/2555

  3. Expertise is retiring

    Experienced technicians and process engineers carry knowledge no manual holds. Capturing it in searchable, multilingual form is now an operational priority.

  4. Reporting reaches the plant

    CBAM and sustainability reporting need energy, emissions and material data at site and product level, collected once and reused across reports.

    SourceRegulation (EU) 2023/956

Challenges and what we build

  1. The challenge

    Every MES-to-ERP link is a point-to-point project.

    Our response

    A unified namespace on MQTT and OPC UA with an ISA-95 information model, so machines, MES and ERP publish and subscribe instead of being wired together one by one.

  2. The challenge

    Quality and maintenance data sits in separate silos.

    Our response

    An operational data platform that joins process, quality and maintenance data with context, for analysis that engineers trust. Predictions come with measured accuracy, or not at all.

  3. The challenge

    Technicians lose time searching manuals and service history.

    Our response

    A service knowledge assistant over manuals, work instructions and past interventions, in the technician's language, citing the document and revision it used.

  4. The challenge

    Connected products must meet the Cyber Resilience Act and the Data Act.

    Our response

    Secure update pipelines, software bills of materials, vulnerability handling and documented data-access APIs, engineered into the product platform.

  5. The challenge

    Product compliance data is scattered across suppliers.

    Our response

    Supplier data integration over EDI and APIs into one product data model that can feed Digital Product Passports, battery passports and CBAM reports.

  6. The challenge

    Orders, delivery notes and certificates are keyed in by hand.

    Our response

    Document intelligence that reads and validates trade documents and certificates of conformity, with staff confirming exceptions before ERP posting.

IT/OT reference landscape

The ISA-95 levels stay intact. A unified namespace makes plant data available above the zone boundary, where analytics, knowledge and compliance services use it.

Illustrative example
L4Business planning and logistics: ERP (SAP S/4HANA,Odoo)L3Manufacturing operations: MES, quality, maintenanceL2Supervisory control: SCADA and HMIL1Control: PLCs and drivesL0Process: sensors, machines and linesZONE BOUNDARY (IEC 62443)Unified namespace: MQTT, OPC UAOperational data platformQuality and maintenance analyticsService and engineering knowledgeassistantProduct compliance data and DigitalProduct Passport
ISA-95 levels, unified namespace and operational data platform

Plant data crosses the zone boundary once, through the namespace, and is reused by every service above it.

Read the diagram as text

The diagram shows the five ISA-95 levels from top to bottom: level 4 business planning and logistics in the ERP (SAP S/4HANA or Odoo), level 3 manufacturing operations with MES, quality and maintenance, level 2 supervisory control with SCADA and HMI, level 1 control with PLCs and drives, and level 0 the process with sensors, machines and lines.

A zone boundary based on IEC 62443 separates level 4 from the levels below.

Levels 1 to 4 publish data to a unified namespace using MQTT and OPC UA. The namespace feeds an operational data platform, which supports quality and maintenance analytics, a service and engineering knowledge assistant, and product compliance data including the Digital Product Passport.

  • Read first, write rarely

    Analytics and assistants read from the namespace. Anything that changes production goes through the MES with operator approval.

  • Zones and conduits

    Segmentation follows IEC 62443, with defined conduits between control and enterprise networks.

  • Predictions with measured accuracy

    Models report measured accuracy and uncertainty. When the data does not support a prediction, we say so.

  • One product data model

    The same product and material data feeds ERP, passports and reporting, instead of three spreadsheets.

The regulatory timeline for manufacturers

Product, data and reporting rules arrive in quick succession. Delegated acts under the Ecodesign Regulation will add product-specific dates.

  1. In application

    Ecodesign Regulation: Framework for Digital Product Passports in force

    Product requirements follow per delegated act.

  2. In application

    NIS2: National NIS2 rules apply

    Several manufacturing sectors are in scope, including machinery, electronics and vehicles.

  3. In application

    Data Act: Data Act applies

    Users gain rights to data generated by connected products.

  4. In application

    CBAM: Definitive period starts

  5. In application

    CSRD: Omnibus amendment narrows reporting scope

    Large companies previously in the second wave report from financial year 2027.

  6. In application

    Cyber Resilience Act: Vulnerability and incident reporting starts

    Actively exploited vulnerabilities and severe incidents must be reported.

  7. In application

    Data Act: Data access by design for new connected products

  8. Status as of 2 October 2026

  9. Upcoming

    Machinery Regulation: Machinery Regulation applies

    Including requirements for safety functions that rely on software and connectivity.

  10. Upcoming

    Batteries Regulation: Battery passport required

    For industrial, electric-vehicle and light-means-of-transport batteries in scope.

  11. Upcoming

    Cyber Resilience Act: Main obligations apply

Regulation and standards reference

The instruments that most often shape product, plant and data programmes, and what they mean for engineering.

This overview supports planning conversations. It is not legal advice, and product-specific obligations depend on delegated acts and harmonised standards. Dates reviewed on 2 October 2026.

Cyber Resilience ActScopeEU-wide

Products with digital elements placed on the EU market must be designed securely, ship with security updates for their support period and come with vulnerability handling. Reporting duties apply from 11 September 2026 and the main obligations from 11 December 2027.

What it means for your programme

Secure development, software bills of materials and update pipelines become part of the product. We build them into your platform and release process.

SourceRegulation (EU) 2024/2847, EUR-Lex (opens external site)

Data ActScopeEU-wide

Users of connected products and related services have a right to access and share the data those products generate. Connected products placed on the market from 12 September 2026 must make that data accessible by design.

What it means for your programme

Product platforms need documented data-access interfaces and contract terms for data sharing. We design both.

SourceRegulation (EU) 2023/2854, EUR-Lex (opens external site)

Ecodesign Regulation and Digital Product PassportScopeEU-wide

The Ecodesign for Sustainable Products Regulation sets the framework for product requirements and the Digital Product Passport. Concrete obligations arrive per product group through delegated acts.

What it means for your programme

A product data model that already holds material, origin and repair information turns each new delegated act into a data mapping, not a new system.

SourceRegulation (EU) 2024/1781, EUR-Lex (opens external site)

Machinery RegulationScopeEU-wide

Replaces the Machinery Directive from 20 January 2027, with requirements that cover software-based safety functions, connected machinery and protection against corruption of safety-relevant software.

What it means for your programme

Software that touches safety functions needs traceable requirements and change control. We separate it clearly from analytics and assistance.

SourceRegulation (EU) 2023/1230, EUR-Lex (opens external site)

NIS2 for manufacturingScopeEU-wide

Manufacturers of medical devices, computers and electronics, electrical equipment, machinery and vehicles are among the sectors in scope, with duties for risk management, incident reporting and supply-chain security.

What it means for your programme

OT security, segmentation and incident processes become board-level topics. We design IT/OT integration with them in place.

SourceDirective (EU) 2022/2555, EUR-Lex (opens external site)

CBAM and sustainability reportingScopeEU-wide

The Carbon Border Adjustment Mechanism entered its definitive period on 1 January 2026 for imports of covered goods. Sustainability reporting under the CSRD was narrowed by the 2026 Omnibus to the largest companies, with later first reporting years.

What it means for your programme

Emissions, energy and material data should be captured once, at the source, with lineage that an auditor can follow.

SourceRegulation (EU) 2023/956, EUR-Lex (opens external site)

Illustrative use cases

Illustrative example
  1. Maintenance knowledge at the machine

    Technicians ask in their own language and get the relevant manual section, work instruction and past fixes, with sources.

  2. Supplier certificate intake

    Certificates of conformity and material declarations read, checked against the order and stored with the batch.

  3. Order and delivery note processing

    Customer orders and delivery notes extracted and validated before posting; staff confirm every exception.

  4. MES modernisation behind APIs

    A legacy MES wrapped in documented APIs and replaced function by function, without stopping a line.

  5. Spare-parts service assistance

    Customers and dealers identify parts and check availability; the assistant hands over to service staff for technical judgement.

Platforms in manufacturing

  • SAP

    Gold Partner

    SAP S/4HANA for manufacturing and supply chain at group level, integrated with MES and plant data through the namespace.

  • Odoo

    Gold Partner

    Odoo manufacturing for mid-sized plants and subsidiaries, often in a two-tier set-up with SAP at group level.

  • Salesforce

    Summit Partner

    Sales agreements, dealer networks and field service, connected to installed-base and service history.

Partner levels are those held by FromNine. Product names are trademarks of their respective owners.

International

Plants across Europe, one data model

Many manufacturers run plants and subsidiaries in several Member States, each with its own MES, ERP instance and working language. EU product rules such as the Cyber Resilience Act, the Data Act and the Ecodesign Regulation apply to all of them in the same way.

We design one information model and integration pattern that every site can adopt at its own pace, with multilingual service content for the people on the floor.

Frequently asked questions

Will you write to our control systems?

By default, no. Analytics and assistants read plant data through the namespace. Any change to production runs through the MES or the control engineers, with operator approval and change control.

Can you predict machine failures?

Sometimes. It depends on the failure modes, the sensors and the history available. We test first, report measured accuracy and uncertainty, and recommend condition-based rules where a model would not be reliable.

Which protocols and standards do you work with?

OPC UA and MQTT for plant data, ISA-95 for the information model, IEC 62443 for zones and conduits, and EDI or APIs for supplier and customer integration.

How do you help with the Cyber Resilience Act?

We engineer the product platform for it: secure development practices, software bills of materials, vulnerability intake and update pipelines. Conformity assessment and legal interpretation stay with you and your notified body where one is needed.

Can SAP at group level and Odoo at plant level work together?

Yes, a two-tier ERP set-up is common. We define which master data and transactions live where and integrate the two so group reporting stays consistent.

Discuss your plant or product programme

Connecting plant data, preparing connected products for the CRA or bringing service knowledge to technicians? Start with one line, one product or one site.