CRA & Machinery Regulation
Cybersecurity Compliance for Machine Builders
The Cyber Resilience Act (CRA) and Machinery Regulation (MR) introduce new cybersecurity and safety requirements that will significantly impact machine manufacturers across Europe.
What is the Cyber Resilience Act (CRA)?
The Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for products with digital elements sold within the European Union.
Its objective is to ensure that products are designed, developed, and maintained with cybersecurity in mind throughout their lifecycle.
What is the Machinery Regulation (MR)?
The new EU Machinery Regulation (2023/1230) replaces the previous Machinery Directive (2006/42/EC) and reflects the realities of increasingly digitalized industrial equipment.
Since it is now a regulation, it applies directly in all EU member states, ensuring a more uniform legal framework.
Need guidance on your CRA or MV compliance journey?
Get expert feedback on your CRA readiness at no cost!
| Topic | Cyber Resilience Act (CRA) | Machinery Regulations |
|---|---|---|
| Focus | Cybersecurity | Functional Safety |
| Scope | Products with digital elements | Machinery |
| Goal | Protect data & systems | Protect people |
| Cybersecurity | Core requirement | Safety-relevant only |
| Enforcement | EU-wide | EU-wide |
Who is affected and what manufacturers must do?
All manufacturers and EU importers of products with digital elements are affected. This includes machines with electronic controls, robots and other industrial equipment.
Manufacturers must ensure an appropriate level of cybersecurity throughout the entire product lifecycle. This includes designing secure products, addressing vulnerabilities, and providing security updates and support for as long as the product is intended to be used.
How does KEBA support CRA & MR compliance?
KEBA is committed to helping customers navigate the evolving cybersecurity and safety landscape. Our products will comply with the Machinery Regulation (MR) and the Cyber Resilience Act (CRA) when these regulations fully apply in 2027.
We implement the upcoming harmonized standards EN 50742 and EN 40000, complemented by selected IEC 62443 measures, and offer consulting services to support compliance for machines and other solutions built with KEBA technology.
Timeline
Lorem ipsum dolor sit amet, consetetur
Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et dolore magna aliquyam erat, sed diam voluptua. At vero eos et accusam et justo duo dolores et ea rebum. Stet clita kasd gubergren, no sea takimata sanctus est Lorem ipsum dolor sit amet. Lorem ipsum dolor sit amet, consetetur sadipscing elitr, s
Myth busters
Myth: Every vulnerability must be fixed immediately
Fact: The CRA requires risk-based management of exploitable vulnerabilities, not the elimination of all vulnerabilities.
Myth: CRA compliance = IEC 62443 compliance
Fact: IEC 62443 is not fully harmonized with the CRA. It can support compliance but does not automatically guarantee it.
Myth: Machine manufacturers are not affected by the CRA
Fact: Machine manufacturers are affected if their products include digital components or software that fall under the CRA scope.
Myth: The CRA only applies to software products.
Fact: The CRA applies to all products with digital elements, including hardware devices with embedded software used in industrial automation.
Myth: The CRA doesn't affect existing products.
Fact: Manufacturers must ensure that products placed on the market after the CRA applies meet its cybersecurity and support requirements.
Myth: Cybersecurity is only an IT issue.
Fact: Cybersecurity can affect machine safety. Both the CRA and the MR require cybersecurity risks to be considered throughout the product lifecycle.
Myth: CRA compliance requires product certification.
Fact: Most products can be self assessed and conformity can be self-declared. Third-party certification is needed only for specific CRA product categories.
Myth: Cybersecurity activities are completed after delivery
Fact: The CRA requires manufacturers to manage vulnerabilities and provide security support throughout the defined support period of the product.
Myth: Open-source software can't be used in CRA-compliant products.
Fact: Open-source software is allowed, but manufacturers remain responsible for managing cybersecurity risks.
Frequently Asked Questions
Do you have questions about CRA or MR? We have compiled answers to the most frequently asked questions for you here.
The Cyber Resilience Act (CRA) focuses on cybersecurity for products with digital elements, while the Machinery Regulation (MR) focuses on machine safety. Both require manufacturers to address cybersecurity risks, but the MR specifically considers their impact on safety.
The CRA primarily applies to products placed on the EU market after the regulation becomes applicable. Existing machines are generally not affected unless substantial modifications result in a new product being placed on the market.
The manufacturer is primarily responsible for ensuring compliance with the CRA. Importers and distributors also have specific obligations to verify that only compliant products are placed on the EU market.
System integrators are generally not directly responsible for the compliance of products they integrate. However, they may become responsible if they substantially modify a product or place a new product on the market under their own name.
System integrators are also responsible for using products as intended, following the manufacturer's cybersecurity documentation, and configuring them appropriately. Compliance can be affected if products are used outside their specified operating conditions or intended purpose.
In most cases, manufacturers can assess compliance themselves and issue a Declaration of Conformity. Independent third-party involvement is only required for specific categories of products defined by the CRA.
These categories primarily include important and critical products that provide cybersecurity functions for other products or systems, such as operating systems, firewalls, identity management solutions, and password managers. Industrial machines and production equipment are generally not classified as important or critical products under the CRA. Therefore, self-assessment and self-declaration are typically sufficient.
The Cyber Resilience Act entered into force in December 2024. Most requirements become applicable on 11 December 2027. However, some obligations apply earlier. In particular, manufacturers must report actively exploited vulnerabilities and severe security incidents to the relevant authorities from 11 September 2026.
The Machinery Regulation (EU) 2023/1230 applies from 20 January 2027 and will replace the current Machinery Directive throughout the European Union.
Need guidance on your CRA or MV compliance journey?
Get expert feedback on your CRA readiness at no cost!
Locations
Business Areas
Newsroom
Edge
Chrome
Safari
Firefox