Digital shield with keyhole symbolizing cybersecurity and data protection.

CRA & Machinery Regulation

Cybersecurity Compliance for Machine Builders

The Cyber Resilience Act (CRA) and Machinery Regulation (MR) introduce new cybersecurity and safety requirements that will significantly impact machine manufacturers across Europe.

What is the Cyber Resilience Act (CRA)?

The Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for products with digital elements sold within the European Union.

Its objective is to ensure that products are designed, developed, and maintained with cybersecurity in mind throughout their lifecycle.

What is the Machinery Regulation (MR)?

The new EU Machinery Regulation (2023/1230) replaces the previous Machinery Directive (2006/42/EC) and reflects the realities of increasingly digitalized industrial equipment.
Since it is now a regulation, it applies directly in all EU member states, ensuring a more uniform legal framework.

 

Need guidance on your CRA or MV compliance journey?

Get expert feedback on your CRA readiness at no cost!

 
TopicCyber Resilience Act (CRA)Machinery Regulations
FocusCybersecurityFunctional Safety
ScopeProducts with digital elementsMachinery
GoalProtect data & systemsProtect people
CybersecurityCore requirementSafety-relevant only
EnforcementEU-wideEU-wide
Industrial production line with robotic arms and a glowing green shield symbolizing cybersecurity.

Who is affected and what manufacturers must do?

All manufacturers and EU importers of products with digital elements are affected. This includes machines with electronic controls, robots and other industrial equipment.

Manufacturers must ensure an appropriate level of cybersecurity throughout the entire product lifecycle. This includes designing secure products, addressing vulnerabilities, and providing security updates and support for as long as the product is intended to be used.

Hand holding a digital shield with checkmark in an automated industrial environment.

How does KEBA support CRA & MR compliance?

KEBA is committed to helping customers navigate the evolving cybersecurity and safety landscape. Our products will comply with the Machinery Regulation (MR) and the Cyber Resilience Act (CRA) when these regulations fully apply in 2027.

We implement the upcoming harmonized standards EN 50742 and EN 40000, complemented by selected IEC 62443 measures, and offer consulting services to support compliance for machines and other solutions built with KEBA technology.

Myth busters

Icon mit grünen Puzzleteilen, die zusammenpassen, wobei ein Teil leicht angehoben ist, was Problemlösung oder Teamarbeit symbolisiert.

Myth: Every vulnerability must be fixed immediately

Fact: The CRA requires risk-based management of exploitable vulnerabilities, not the elimination of all vulnerabilities.

Icon mit grünen Puzzleteilen, die zusammenpassen, wobei ein Teil leicht angehoben ist, was Problemlösung oder Teamarbeit symbolisiert.

Myth: CRA compliance = IEC 62443 compliance

Fact: IEC 62443 is not fully harmonized with the CRA. It can support compliance but does not automatically guarantee it.

Icon mit grünen Puzzleteilen, die zusammenpassen, wobei ein Teil leicht angehoben ist, was Problemlösung oder Teamarbeit symbolisiert.

Myth: Machine manufacturers are not affected by the CRA

Fact: Machine manufacturers are affected if their products include digital components or software that fall under the CRA scope.

Icon mit grünen Puzzleteilen, die zusammenpassen, wobei ein Teil leicht angehoben ist, was Problemlösung oder Teamarbeit symbolisiert.

Myth: The CRA only applies to software products.

Fact: The CRA applies to all products with digital elements, including hardware devices with embedded software used in industrial automation.

Icon mit grünen Puzzleteilen, die zusammenpassen, wobei ein Teil leicht angehoben ist, was Problemlösung oder Teamarbeit symbolisiert.

Myth: The CRA doesn't affect existing products.

Fact: Manufacturers must ensure that products placed on the market after the CRA applies meet its cybersecurity and support requirements.

Icon mit grünen Puzzleteilen, die zusammenpassen, wobei ein Teil leicht angehoben ist, was Problemlösung oder Teamarbeit symbolisiert.

Myth: Cybersecurity is only an IT issue.

Fact: Cybersecurity can affect machine safety. Both the CRA and the MR require cybersecurity risks to be considered throughout the product lifecycle.

Icon mit grünen Puzzleteilen, die zusammenpassen, wobei ein Teil leicht angehoben ist, was Problemlösung oder Teamarbeit symbolisiert.

Myth: CRA compliance requires product certification.

Fact: Most products can be self assessed and conformity can be self-declared. Third-party certification is needed only for specific CRA product categories.

Icon mit grünen Puzzleteilen, die zusammenpassen, wobei ein Teil leicht angehoben ist, was Problemlösung oder Teamarbeit symbolisiert.

Myth: Cybersecurity activities are completed after delivery

Fact: The CRA requires manufacturers to manage vulnerabilities and provide security support throughout the defined support period of the product.

Icon mit grünen Puzzleteilen, die zusammenpassen, wobei ein Teil leicht angehoben ist, was Problemlösung oder Teamarbeit symbolisiert.

Myth: Open-source software can't be used in CRA-compliant products.

Fact: Open-source software is allowed, but manufacturers remain responsible for managing cybersecurity risks.

Frequently Asked Questions

Do you have questions about CRA or MR? We have compiled answers to the most frequently asked questions for you here.

 

Need guidance on your CRA or MV compliance journey?

Get expert feedback on your CRA readiness at no cost!

 
Please select your preferred language
Your browser is out of date
Internet Explorer is no longer supported. Please switch to a current browser to use keba.com to its fullest extent.

Edge

Chrome

Safari

Firefox