Legal counsel for manufacturing & logistics enterprises in Hyderabad — where the plant floor and the boardroom carry the same legal exposure.
From supply chain contracts and OSH Code transition compliance to industrial dispute resolution and IP protection — SIRI Law LLP delivers integrated legal advisory for India's manufacturing sector, backed by attorneys who track the Factories Act repeal alongside cybersecurity advisory for Industry 4.0 and connected OT/ICS environments.
The transition most manufacturers haven't tracked closely enough
The Factories Act is technically repealed. Most compliance still runs on it.
Here's a detail that surprises a lot of manufacturing operators: the Factories Act 1948, the statute that has governed Indian factory floors for nearly eighty years, was formally repealed on 21 November 2025 — the day the four Labour Codes were notified. Section 143 of the Occupational Safety, Health and Working Conditions Code says so explicitly. And yet, for most manufacturers, day-to-day compliance in 2026 still runs substantially on the old framework, because the OSH Code's savings provisions keep existing factory licences and state Factories Rules operative until each state notifies its own OSH Code Rules. Some states have already done this; others remain in draft.
That means your actual compliance obligations depend on where your facility sits, not on a single national effective date — a nuance that's easy to miss if you're reading only the headline that "the Factories Act has been replaced." The Central OSH Code Rules, finalised on 8 May 2026, do set out several provisions that already apply nationally regardless of state transition status: mandatory appointment letters for all workers within three months, consolidated single-licence registration, and new inter-state migrant worker protections including journey allowance after 180 days of continuous work.
Layered on top of this transition is the operational reality of Industry 4.0: connected PLCs, SCADA systems, and IIoT sensors on the plant floor create a genuine OT/ICS cybersecurity exposure that most manufacturing legal counsel simply doesn't address. CERT-In's mandatory 6-hour breach notification window applies to OT incidents affecting critical systems exactly as it applies to conventional IT breaches — and without OT-aware monitoring, many manufacturers don't even detect an intrusion into their control systems until days after it started, which makes meeting that six-hour clock effectively impossible without the right technical visibility in place beforehand.
The OT/IT boundary is where attackers pivot
Without OT-aware monitoring, detection of a control-system intrusion can lag by days, not hours.
Where manufacturing legal risk actually builds
Manufacturing enterprises face a unique intersection of labour law, environmental regulation, product liability, and cybersecurity exposure
These are the recurring patterns behind the compliance gaps and disputes manufacturing clients bring to us most often.
OSH Code transition status assumed, not verified
Treating the Factories Act repeal as a single national event rather than a state-by-state transition leaves compliance gaps — some obligations already changed nationally, others depend entirely on your state's rule-notification status.
Vendor and logistics contracts leave liability exposed
Standard purchase orders and logistics agreements often contain ambiguous force majeure provisions and unallocated liability for delay, defect, or non-conformance — gaps that surface expensively during a supply chain disruption.
Connected plant floors carry undocumented cyber exposure
Industry 4.0 sensors, PLCs, and SCADA systems expand the attack surface, but most manufacturers have no OT-specific incident response plan or CERT-In notification protocol ready before an incident occurs.
PLI claims built on incomplete compliance architecture
PLI incentive claims require BIS certification, ISO compliance, and auditable production documentation as prerequisites — claims filed without this foundation risk clawback and scrutiny well after the incentive has been paid.
What we cover
Manufacturing and logistics legal services across the full operational lifecycle
From supply chain contracts and factory compliance through IP protection, cross-border trade, and OT/ICS cybersecurity legal advisory.
Supply Chain Agreements
Vendor contracts, purchase orders, logistics agreements, and force majeure clauses for complex supply chains, with liability allocation calibrated to the actual risk of delay, defect, or disruption.
- Vendor and purchase order drafting
- Logistics and distribution agreements
- Force majeure and liability allocation
- Supply chain dispute resolution
Factory & OSH Code Compliance
OSH Code and Factories Act transition advisory, hazardous process compliance, ESIC, EPFO, and occupational health regulatory advisory calibrated to your state's specific transition status.
- State-specific OSH transition verification
- Factory licence and single-licence consolidation
- Hazardous process compliance
- ESIC and EPFO regulatory advisory
Labour & Industrial Law
Industrial Relations Code compliance, contract labour compliance, retrenchment, strikes, and labour court representation across the consolidated Labour Codes framework.
- Industrial Relations Code compliance
- Contract Labour Act obligations
- Retrenchment and standing orders
- Labour court and tribunal representation
IP for Manufacturing
Process patents, design protection, trade secrets, and anti-counterfeiting enforcement for manufactured goods and proprietary production methods.
- Process patent filing and prosecution
- Design registration for products
- Trade secret programmes for proprietary processes
- Anti-counterfeiting enforcement
Cross-Border Trade
FEMA compliance, import-export licensing, customs disputes, and international trade agreement advisory for manufacturers with global supply chains or export operations.
- Import-export licensing
- Customs dispute representation
- FEMA cross-border compliance
- International trade agreement advisory
OT/ICS Cybersecurity Legal Advisory
Legal advisory for OT cyber incidents, CERT-In notifications, and ICS security compliance under the IT Act, run jointly with SIRI's cybersecurity team for connected plant environments.
- OT/ICS incident response planning
- CERT-In notification protocol design
- ICS security compliance under IT Act
- Joint legal + technical OT risk assessment
Evidence, not guesswork
Factories Act 1948 vs. the OSH Code — what's changed and what's still transitioning
The repeal is real. So is the savings-provision gap. Here's what actually applies today.
| Provision | Factories Act 1948 (legacy) | OSH Code 2020 (current) |
|---|---|---|
| Legal status | Formally repealed 21 Nov 2025 | In force nationally; state rules still transitioning |
| Fine for death-causing safety breach | Minimum ₹25,000 | Up to ₹5 lakh, with non-compoundable repeat offences |
| Appointment letters | Not uniformly mandated | Mandatory for all workers within 3 months, nationally |
| Working hours structure | Standard 6-day, 8-hour pattern | Optional 4-day (12-hr) or 5-day (9.6-hr) structures, capped at 48 hrs/week |
| Migrant worker provisions | Separate Inter-State Migrant Workers Act | Consolidated into OSH Code — journey allowance after 180 days |
| Which framework actually applies to you | Depends on your state's OSH Code Rules notification status — verify before relying on either column alone | |
Sources: Occupational Safety, Health and Working Conditions Code 2020, Section 143; OSH Code Central Rules, notified 8 May 2026; state-level OSH Code Rules notification tracking. State rules vary materially — this table is a general national reference, not a substitute for confirming your specific state's transition status.
What the numbers actually mean
Four figures that frame manufacturing legal risk today
Non-compoundable on repeat offence — meaning no negotiated settlement is available once a company has a prior conviction within the statutory window.
Applies to control-system incidents exactly as it applies to IT breaches — detection latency is often the harder constraint than the deadline itself.
Of incremental sales, depending on sector and investment scale — contingent on BIS certification and auditable production documentation.
In-country retention requirement for OT security logs — infrastructure most manufacturing plants don't yet have configured correctly.
How we engage
Four stages from instruction to operational confidence
A structured engagement that maps your specific compliance exposure before building the framework that closes it.
Regulatory transition assessment
Review of your facility's state-specific OSH Code transition status, existing factory licences, PLI compliance architecture, and OT/ICS incident readiness.
Week 1Framework design
Updated supply chain contract templates, OSH compliance calendar, labour framework alignment, and OT incident response protocol design.
Weeks 2–5Ongoing compliance
Regulatory monitoring across state OSH rule notifications, PLI claim documentation support, environmental clearance tracking, and annual compliance review.
OngoingDispute & incident response
Labour tribunal representation, product liability defence, and joint legal-technical OT incident response when it's needed.
As neededWhy SIRI
Manufacturing law backed by OT/ICS technical capability
Manufacturing enterprises face a unique intersection of labour law, environmental regulation, product liability, and increasingly, cybersecurity exposure in connected OT/ICS environments. SIRI Law LLP provides integrated legal-technical advisory that no standalone law firm or cybersecurity consultancy can replicate.
OSH Code transition fluency
We track each state's OSH Code Rules notification status individually, so your compliance calendar reflects what actually applies to your specific facility, not a generic national assumption.
Joint legal + technical OT advisory
Our cybersecurity team can assess your OT/ICS environment's actual technical exposure while our attorneys build the CERT-In notification protocol and legal response framework around it, under one privilege.
PLI-aware compliance architecture
We build the underlying BIS, ISO, and documentation foundation your PLI claims actually depend on, rather than treating incentive filing as a paperwork exercise separate from operational compliance.
Legal, cybersecurity, and GRC under one retainer
Attorney-client privilege covers all technical findings from a joint engagement — a structural advantage no standalone law firm or cybersecurity consultancy can replicate on its own.
Who we work with
Manufacturers and logistics operators across sectors
From electronics and pharma manufacturing to third-party logistics — the regulatory shape differs by sector, the underlying compliance discipline doesn't.
Frequently asked
Manufacturing and logistics law, answered directly
Has the Factories Act 1948 been fully replaced?
Formally, yes — Section 143 of the Occupational Safety, Health and Working Conditions Code 2020 repealed the Factories Act 1948 from 21 November 2025, when the four Labour Codes were notified. In practice, the Code's savings provisions keep existing factory licences and state Factories Rules operative until each state notifies its own OSH Code Rules, so most day-to-day compliance in 2026 still runs on the old framework depending on your state's transition status. This needs verifying state by state, not assumed nationally.
What are the penalty stakes under the new OSH Code compared to the old Factories Act?
Higher, not lower. Under the Factories Act, a breach of the safety provisions causing death carried a minimum fine of ₹25,000; the OSH Code carries this forward with stiffer amounts, including fines that can reach ₹5 lakh for contraventions causing death. Repeat convictions within the statutory window attract enhanced punishment that cannot be compounded, meaning no discounted settlement is available. Both the occupier, typically a director, and the factory manager carry personal legal liability.
Does CERT-In's 6-hour breach notification apply to OT and ICS incidents, not just IT systems?
Yes. CERT-In's direction on 6-hour breach reporting applies to any incident impacting critical systems, which includes OT and ICS environments in a connected manufacturing plant, not only conventional IT infrastructure. A ransomware or intrusion event affecting a production line's control systems triggers the same notification clock as a data breach, and without OT-aware monitoring, detection itself can lag by days, which is often the harder problem to solve than the notification deadline itself.
What legal risks come with claiming PLI scheme incentives?
PLI incentives are conditioned on meeting minimum investment thresholds and incremental sales targets over a five-year window, and claims require detailed annual documentation and certification. BIS certification, ISO compliance, and a documented quality management system are prerequisites for most schemes, not optional extras. Getting the underlying compliance architecture wrong doesn't just risk losing the incentive — it can expose the company to clawback and scrutiny on claims already paid.
What supply chain contract provisions carry the highest risk?
Force majeure definitions, delay and non-conformance liability allocation, and payment terms tied to milestone conditions are the highest-risk provisions in most manufacturing supply chain agreements. Generic templates rarely address what happens when a supplier disruption cascades through a multi-tier supply chain, which is exactly when these clauses matter most.
Can SIRI assess our OT/ICS cybersecurity exposure alongside legal compliance?
Yes. Our cybersecurity team can assess the technical exposure of your connected plant floor — PLCs, SCADA, IIoT sensors — while our attorneys build the CERT-In notification protocol, incident response plan, and legal framework around the findings, all under one attorney-client privilege rather than a separate, uncoordinated technical engagement.
Ready when you are
Ready to engage?
Schedule a confidential consultation with our legal team. We will assess your OSH Code transition status, supply chain exposure, and OT/ICS readiness — no obligation, no pressure.
Related services
Other ways SIRI Law LLP supports industrial enterprises
Employment & labour law
Labour Codes compliance, retrenchment, and industrial dispute resolution.
Cybersecurity testing services
OT/ICS-aware penetration testing for connected manufacturing environments.
Corporate & commercial law
M&A due diligence and contracts for manufacturing and logistics transactions.
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

