The Cyber Resilience Act for Machinery: Obligations, Deadlines and Reporting

Legal references checked against the Official Journal

If your machine has a controller with an Ethernet port, a remote-service router or a wireless handheld, the EU Cyber Resilience Act almost certainly applies to it. Part of it already applies: since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents, even for machines delivered years ago. The design, vulnerability handling and documentation requirements follow on 11 December 2027. This guide explains scope, deadlines, classification and what to prepare, with the article references you need to check it yourself.

The key dates

20 Nov 2024

Published in the Official Journal

Regulation (EU) 2024/2847 of 23 October 2024, OJ L, 2024/2847. Corrected by OJ L, 2025/90555 of 2 July 2025 (Articles 13(8) and 64(10)) and OJ L, 2025/90828 of 17 October 2025 (Article 67).

10 Dec 2024

Entry into force

Twenty days after publication (Article 71(1)). No manufacturer obligations apply yet on this date.

11 Jun 2026

Notified bodies

Chapter IV (Articles 35 to 51) applies, so conformity assessment bodies can be notified under the CRA (Article 71(2)).

11 Sep 2026

Reporting obligations apply

Actively exploited vulnerabilities and severe incidents must be reported, including for products placed on the market before this date (Articles 71(2) and 69(3)). ENISA's Single Reporting Platform went live the same day in an initial version.

11 Dec 2027

Full application

Products placed on the market from this date must meet all requirements: Annex I, risk assessment, conformity assessment, declaration and CE marking (Article 71(2)). Products placed on the market earlier are only caught if they undergo a substantial modification after this date (Article 69(2)).

11 Jun 2028

End of transitional validity of certificates

EU-type examination certificates and approval decisions on cybersecurity requirements issued under other Union harmonisation legislation remain valid until this date, unless they expire earlier or that legislation provides otherwise (Article 69(1)).

What decides which obligations apply is therefore the date on which a product is placed on the EU market. For running product lines, the Commission's guidance C(2026) 5252 (content approved on 27 July 2026; no formal adoption found as of 15 September 2026) offers some relief: products designed before 11 December 2027 and placed on the market afterwards do not need to be redesigned if the risk assessment shows that appropriate measures are in place. Conformity assessment, the declaration and CE marking are still required.

Is your machine in scope?

Article 2(1) covers products with digital elements made available on the market "whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network". A product with digital elements is any software or hardware product together with its remote data processing solutions (Article 3(1)), and under Article 3(2) this includes remote data processing software designed by or under the responsibility of the manufacturer, such as a cloud application that a machine function depends on.

Typical triggers on machinery

  • Ethernet or fieldbus interface to the plant network or other machines
  • Remote service access via router, VPN or portal
  • USB port for loading programs or recipes
  • Wi-Fi, Bluetooth or cellular, including wireless handhelds
  • Connection to the manufacturer's cloud application

Exclusions in Article 2(2) to (7)

  • Medical devices and in vitro diagnostics (Regulations (EU) 2017/745 and 2017/746)
  • Vehicles under Regulation (EU) 2019/2144 and aviation products certified under Regulation (EU) 2018/1139
  • Marine equipment under Directive 2014/90/EU
  • Products excluded by delegated act, so far those under Regulation (EU) No 168/2013 (Article 2(5), Delegated Regulation (EU) 2025/1535)
  • Identical spare parts (Article 2(6))
  • Products developed exclusively for national security or defence (Article 2(7))

Machinery is not on that list. Recital 53 goes further: manufacturers of machinery under Regulation (EU) 2023/1230 should comply with both the CRA and the Machinery Regulation. The Commission's draft guidance adds that a data connection requires encoded digital information, so a purely mechanical machine without a controller or interface is outside the CRA. Software needed to operate, configure or control the machine counts as part of the product, even when customers download it separately.

Reporting obligations that already apply

Two events trigger Article 14. An actively exploited vulnerability is one for which there is reliable evidence that a malicious actor has exploited it in a system without the owner's permission (Article 3(42)). A severe incident affects or can affect the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or has led or can lead to malicious code being introduced or executed in the product or in a user's network (Article 14(5)).

StepActively exploited vulnerabilitySevere incident
Early warningwithout undue delay, at the latest within 24 hours of becoming aware, naming the member states where, to the manufacturer's knowledge, the product has been made available (Art. 14(2)(a))without undue delay, at the latest within 24 hours of becoming aware, stating whether unlawful or malicious acts are suspected and, where applicable, the member states concerned (Art. 14(4)(a))
Notificationunless already provided, without undue delay and within 72 hours: the product, the general nature of the exploit and vulnerability, corrective measures taken and measures users can take (Art. 14(2)(b))unless already provided, without undue delay and within 72 hours: nature of the incident, initial assessment, measures taken and measures users can take (Art. 14(4)(b))
Intermediate reporton request of the CSIRT (Art. 14(6))on request of the CSIRT (Art. 14(6))
Final reportunless already provided, no later than 14 days after a corrective or mitigating measure is available (Art. 14(2)(c))unless already provided, within one month after the 72-hour notification (Art. 14(4)(c))

Reports are submitted through the Single Reporting Platform under Article 16, via the electronic endpoint of the coordinating CSIRT of the member state where the manufacturer has its main establishment, and are simultaneously accessible to ENISA (Article 14(7)). The main establishment is where cybersecurity decisions about the products are predominantly taken, or failing that, the member state of its establishment with the highest number of employees in the EU. Manufacturers without an EU main establishment follow a fallback order in the same paragraph: the member state of the authorised representative acting for most of their products, then that of the importer placing most of them on the market, then that of the distributor making most of them available, and finally the member state where most of their users are. Affected users must also be informed, where needed with mitigation steps (Article 14(8)).

The clock starts at awareness. Under the Commission's draft guidance, a manufacturer becomes aware once an initial assessment, carried out without delay, gives a reasonable degree of certainty that exploitation or a severe incident has occurred. A vulnerability in a third-party component only has to be reported if it was exploited in your own product. Meeting 24 hours takes a process agreed in advance: who assesses, who reports, and which countries each machine type was sold into.

Relief for small manufacturers: the fines under Article 64 CRA do not apply to micro and small enterprises for missing the 24-hour early warning deadline alone (Article 64(10)(a) as corrected by OJ L, 2025/90555). The reporting duty itself and the other deadlines remain. Note the timing, though: under Article 71(2), Article 64 only applies from 11 December 2027, as only Article 14 and Chapter IV were brought forward. Whether and how breaches of the reporting obligations can be penalised before then depends on national law; in Germany, no promulgation of the national implementing act could be found as of 15 September 2026.

Default, important or critical?

The conformity assessment route depends on classification, and classification follows the product's core functionality (Articles 7(1) and 8(1)). Implementing Regulation (EU) 2025/2392 contains the technical descriptions of the categories. According to the Commission's draft guidance, a product has exactly one core functionality for this purpose, which should be named in the technical documentation.

CategoryWhat falls under itConformity assessment
Default productEverything whose core functionality does not match a category in Annex III or IV. This is where machinery itself normally sits.Internal control (module A), or on a voluntary basis EU-type examination plus conformity to type (modules B and C), full quality assurance (module H) or, where available and applicable, a European cybersecurity certification scheme (Article 32(1)).
Important, Class I (Annex III)19 categories, including routers, modems intended for internet connection and switches (point 12), physical and virtual network interfaces (point 10), operating systems (point 11), network management systems (point 6) and VPN products (point 5).Module A only where harmonised standards, common specifications or European certification schemes at assurance level 'substantial' or higher are applied in full; otherwise modules B and C or module H (Article 32(2)).
Important, Class II (Annex III)Hypervisors and container runtime systems, firewalls, intrusion detection and prevention systems, tamper-resistant microprocessors and microcontrollers.Modules B and C, module H, or, where available and applicable, a European certification scheme at level 'substantial' or higher; module A is not available (Article 32(3)).
Critical (Annex IV)Hardware devices with security boxes, smart meter gateways and other devices for advanced security purposes, smartcards and secure elements.A European certification scheme once a delegated act under Article 8(1) requires it; until then the Class II procedures (Article 32(4)).

The integration rule

Article 7(1) states that integrating a product with the core functionality of an Annex III category does not in itself make the host product subject to the procedures of Article 32(2) and (3). The managed switch in the control cabinet, the HMI panel running an operating system or the fieldbus card do not turn your machine into an important product. The machine normally stays a default product.

Take a closer look if you also sell components on their own. Implementing Regulation (EU) 2025/2392 explicitly lists fieldbus controllers and adapters among the Class I network interfaces and real-time operating systems among the Class I operating systems. A remote-service router, fieldbus interface card or cabinet firewall that you market separately therefore needs its own classification.

Conformity assessment and the missing standards

Important Class I products may only use internal control if harmonised standards, common specifications or certification schemes are applied in full (Article 32(2)). That is exactly where the bottleneck lies: as of 11 September 2026, no harmonised standard under the CRA has been cited in the Official Journal, according to standards trackers and industry reports. The Commission's standardisation request M/606 of 3 February 2025 covers 41 standards, with work under way on the horizontal EN 40000 series and, for operational technology products, the prEN 50770 series based on IEC 62443. A postponement of the standardisation deadlines exists only as a draft.

For the machine itself this is less critical. As a default product it can use module A without harmonised standards; the technical documentation then has to describe the solutions adopted for Annex I Parts I and II and list any other technical specifications applied (Annex VII point 5). IEC 62443-4-1 and -4-2 remain the obvious technical basis, even though an industry analysis of 6 July 2026 considers a citation under the CRA unlikely.

Where a machine falls under both the Machinery Regulation and the CRA, a single EU declaration of conformity covers both acts and lists them with their Official Journal references (Article 28(3)). Annex V sets out what the declaration has to contain for the CRA.

What applies from 11 December 2027

1. Cybersecurity risk assessment (Article 13(2) to (4))

The assessment starts from the intended purpose and reasonably foreseeable use, considers the operational environment, the assets to be protected and the expected time in use, and feeds into planning, design, production, delivery and maintenance. For every requirement in Annex I Part I point 2 it must state whether and how it applies and how it is implemented; a requirement that does not apply needs a clear justification in the technical documentation. It is documented and, where appropriate, updated during the support period (Article 13(3)).

2. Product requirements (Annex I Part I)

Based on the risk assessment, and where applicable, point 2 requires:

  • ano known exploitable vulnerabilities when made available
  • ba secure-by-default configuration and a way to reset to the original state
  • cthe ability to fix vulnerabilities through security updates
  • dprotection against unauthorised access, e.g. authentication and access management, with reporting of possible unauthorised access
  • econfidentiality of stored, transmitted or processed data
  • fintegrity of data, commands, programs and configuration, with reporting of corruption
  • gdata minimisation
  • havailability of essential functions, including resilience against denial-of-service attacks
  • iminimal negative impact on other devices and networks
  • jlimited attack surfaces, including external interfaces
  • kmechanisms that reduce the impact of an incident
  • lrecording or monitoring of relevant internal activity, with an opt-out for users
  • msecure and easy deletion of all data and settings, and secure data transfer

Our own summary of points (a) to (m); the binding wording is in the Regulation. Point (c) only calls for automatic security updates where applicable, and according to recital 56 the related rules should not apply where users would not normally expect automatic updates, for example in industrial environments where an automatic update could disrupt operations.

3. Vulnerability handling (Annex I Part II)

Part II applies without the "where applicable" qualifier. It requires a software bill of materials in a commonly used, machine-readable format covering at least the top-level dependencies, remediation without delay through security updates kept separate from feature updates where technically feasible, regular security testing, publication of fixed vulnerabilities, a coordinated vulnerability disclosure policy, a contact address for vulnerability reports, secure update distribution and free security updates. The SBOM does not have to be published (recital 77), but market surveillance can request it on a reasoned basis (Annex VII point 8).

4. Third-party components (Article 13(5) and (6))

Manufacturers must exercise due diligence when integrating third-party components, including open-source software, so that they do not compromise the product's cybersecurity. A vulnerability found in a component is reported to whoever manufactures or maintains it, together with any fix you developed. For PLCs, HMIs, routers and drives this means collecting and documenting your suppliers' security information and support periods.

5. Support period (Article 13(8), (9) and (19))

The support period reflects the expected time in use and lasts at least five years, unless the product is expected to be in use for less. The Commission's draft guidance makes clear that five years is not a default, and recital 60 names industrial control systems as an example of much longer use. The end date must be stated at the time of purchase with at least month and year, and each security update stays available for at least ten years or the remainder of the support period, whichever is longer. The reasoning behind the chosen period belongs in the technical documentation.

6. Information for users (Annex II)

The machine has to come with, among other things: manufacturer contact details, the single point of contact for vulnerability reports and the disclosure policy, unambiguous product identification, intended purpose with the security environment and security properties, known circumstances that may lead to significant cybersecurity risks, where applicable the internet address of the declaration of conformity, the type of security support and end of the support period, and instructions on secure commissioning, updates, decommissioning and integration. This fits naturally into a dedicated chapter of the operating instructions and must stay available for at least ten years or the support period, whichever is longer (Article 13(18)).

7. Technical documentation, declaration and CE marking

Before placing on the market come the Annex VII technical documentation, the conformity assessment under Article 32, the EU declaration of conformity and CE marking (Article 13(12)). Documentation and declaration are kept for at least ten years or the support period, whichever is longer (Article 13(13)). Manufacturers also designate a single point of contact through which users can reach them directly (Article 13(17)).

How the CRA relates to the Machinery Regulation and the RED

The CRA does not replace any machinery requirement. From 20 January 2027, Annex III of the Machinery Regulation requires protection against corruption (section 1.1.9) and control systems that, where appropriate to the circumstances and risks, withstand reasonably foreseeable malicious attempts from third parties leading to a hazardous situation (section 1.2.1). Recital 53 of the CRA says that meeting the CRA may facilitate compliance with those sections, but the manufacturer has to demonstrate that synergy and should follow both conformity assessment procedures. CRA compliance alone gives no presumption of conformity for sections 1.1.9 and 1.2.1. Under the Machinery Regulation, that presumption comes from harmonised standards referenced in the Official Journal (Article 20(1)) or common specifications (Article 20(6)) and, for these two sections specifically, also from certification or a statement of conformity under a Cybersecurity Act (EU) 2019/881 scheme referenced in the Official Journal (Article 20(9)).

If a machine with a radio module counts as radio equipment and meets the criteria of Delegated Regulation (EU) 2022/30, such as communicating over the internet, the resulting cybersecurity requirements of the Radio Equipment Directive apply to units placed on the market until 10 December 2027; the Delegated Regulation is repealed with effect from 11 December 2027 by Delegated Regulation (EU) 2026/339. How the three regimes interact, and why the cybersecurity risk assessment needs its own method next to EN ISO 12100, is covered in Cybersecurity for machinery.

Penalties and authorities

  • Non-compliance with Annex I or the obligations in Articles 13 and 14: up to EUR 15 million or 2.5 % of worldwide annual turnover (Article 64(2)).
  • Breaches of other obligations, including the declaration, CE marking, technical documentation and conformity assessment: up to EUR 10 million or 2 % (Article 64(3)).
  • Incorrect, incomplete or misleading information to notified bodies and market surveillance authorities: up to EUR 5 million or 1 % (Article 64(4)).

In each case the higher amount applies; the nature, gravity and duration of the infringement and the size of the company are taken into account (Article 64(5)). Article 64 applies from 11 December 2027 (Article 71(2)); whether breaches of the reporting obligations that have applied since 11 September 2026 can be penalised earlier depends on national law.

Member states designate their own market surveillance authorities. In Germany, BSI announced that its CERT-Bund acts as coordinating CSIRT since 11 September 2026, and a draft federal act implementing the CRA (Bundestag document 21/6134 of 26 May 2026) makes BSI the market surveillance authority, notifying authority and authority for fines; as of 15 September 2026 no promulgation could be found. For machinery law, the market surveillance authorities of the German federal states remain responsible, and how checks of CRA aspects on machinery will be split with BSI is still open. Manufacturer obligations apply directly from the Regulation regardless.

Still open as of 15 September 2026

  • The Commission's guidance C(2026) 5252 of 27 July 2026 has been approved in content; no formal adoption with all language versions could be found. It is not legally binding; the interpretations quoted in this guide come from that version.
  • No harmonised standard under the CRA is cited in the Official Journal (sources as of 11 September 2026).
  • Not yet adopted, among others: the SBOM format (Article 13(24)), the format and procedure of notifications (Article 14(10)) and the simplified technical documentation form for micro and small enterprises (Article 33(5)).

How CE-Copilot covers this

CE-Copilot handles CRA work in the same project as the risk assessment, the declaration of conformity and the operating instructions. Classification, deadlines and procedure rules are fixed logic, not AI estimates.

  • Standards finder and risk assessment (Starter and above): the standards finder only lists the CRA as mandatory when the machine description shows a data connection, together with a note on the reporting obligation. In the risk assessment editor, the cybersecurity module guides you through scope, core functionality and Annex III and IV classification, shows what applies based on the date of placing on the market and, for machines placed on the market from 11 December 2027, records the Article 32 procedure.
  • Cybersecurity project page (Professional and above): interface and asset inventory, cybersecurity risk assessment, Annex I requirements matrix with applicability, justification, implementation and evidence, third-party components, support period, vulnerability handling with SBOM storage, Article 14 reporting cases with deadline tracking and templates, and the Annex II user information.
  • Documents: CRA report as PDF and Word, a cybersecurity chapter in the complete dossier, a cybersecurity section in the technical file, the CRA as an additional act in the declaration of conformity (ticked only once the main obligations apply to the unit) and a cybersecurity chapter with the Annex II information in the operating instructions (add-on from Professional, one-off purchase per project).

The step-by-step walkthrough is in Cyber Resilience Act software for machinery. See the result in the sample dossier (chapter 7, pp. 125–138) and the sample operating instructions (chapter 13). Plans are listed on the pricing page.

The software structures and documents the work. Assessment, technical implementation and approval stay with the manufacturer, and Article 14 reports are submitted through ENISA's Single Reporting Platform, not from CE-Copilot.

FAQ

Frequently asked questions

Does the Cyber Resilience Act apply to machinery?
Yes, whenever the machine is a product with digital elements whose intended purpose or reasonably foreseeable use includes a direct or indirect, logical or physical data connection to a device or network (Article 2(1) CRA). Machinery is not among the exclusions in Article 2, and recital 53 expects manufacturers of machinery under Regulation (EU) 2023/1230 to meet both the CRA's cybersecurity requirements and the Machinery Regulation's safety requirements. A controller with an Ethernet, fieldbus, USB or wireless interface, a remote-service connection or a cloud link is normally enough. According to the Commission's guidance C(2026) 5252 (content approved on 27 July 2026; no formal adoption found as of 15 September 2026), merely switching a device on and off without encoded information is not a data connection.
What do machinery manufacturers have to do since 11 September 2026?
Report. Once you become aware of an actively exploited vulnerability or a severe incident affecting the security of your product, Article 14 requires an early warning within 24 hours and a notification within 72 hours through ENISA's Single Reporting Platform, a final report later on, and information to affected users. In practice this means assigning responsibility, setting up a contact channel for vulnerability reports, knowing in which member states each machine type has been made available, and preparing access to the platform before the first case.
Do the reporting obligations cover machines we sold years ago?
Yes. Article 69(3) CRA extends the obligations of Article 14 to all in-scope products placed on the market before 11 December 2027. All other CRA requirements only reach such legacy products if they are substantially modified after 11 December 2027 (Article 69(2)). The Commission's guidance C(2026) 5252 (content approved on 27 July 2026; no formal adoption found as of 15 September 2026) states that reporting continues after the end of the support period, but that no retroactive report is due if active exploitation was already known before 11 September 2026.
Does an integrated industrial switch or router make my machine an important product?
No. Classification follows the product's core functionality, and Article 7(1) states that integrating a product with the core functionality of an Annex III category does not, in itself, subject the host product to the stricter procedures. A packaging machine with a built-in managed switch remains a default product; for the purchased switch, the due-diligence obligation of Article 13(5) applies. The picture changes if you also sell that switch or a remote-service router separately under your own name: that product then needs its own classification.
Do I need a notified body for my machine under the CRA?
Not for a machine that is a default product: Article 32(1) allows internal control under module A. A notified body only comes into play if you place on the market an important Class I product without fully applying harmonised standards, common specifications or European cybersecurity certification schemes at assurance level 'substantial' or higher (Article 32(2)), a Class II product or a critical product. For Class II products and, as long as no delegated act under Article 8(1) exists, for critical products, a European cybersecurity certification scheme at level 'substantial' or higher can be used instead where available and applicable (Article 32(3) and (4)). The Machinery Regulation may still require a notified body for other reasons (Annex I of Regulation (EU) 2023/1230).
How long should the support period be for industrial machinery?
It should reflect the time the product is expected to be in use, with a minimum of five years unless the expected use is shorter (Article 13(8)). The Commission's guidance C(2026) 5252 (content approved on 27 July 2026; no formal adoption found as of 15 September 2026) stresses that five years is not a default value, and recital 60 names industrial control systems as products that are often used for much longer. The end date has to be stated at the time of purchase with at least month and year (Article 13(19)), and every security update must remain available for at least ten years or the rest of the support period, whichever is longer (Article 13(9)).
We have no establishment in the EU. Where do we report?
Reports always go through the Single Reporting Platform to the coordinating CSIRT of a member state. For manufacturers established in the EU this is the member state where cybersecurity decisions are predominantly taken, or failing that the member state of its establishment with the highest number of employees in the EU. For manufacturers without an EU main establishment, Article 14(7) sets a fallback order based on the information available to you: the member state of the authorised representative acting for most of your products, then that of the importer placing most of them on the market, then that of the distributor making most of them available, and finally the member state where most of your users are.
Are there harmonised standards for the Cyber Resilience Act yet?
Not in the Official Journal as of 11 September 2026, according to standards trackers and industry reports. The standardisation request M/606 of 3 February 2025 covers 41 standards; work is under way on the horizontal EN 40000 series and, for operational technology products, on prEN 50770 based on IEC 62443. Without a citation there is no presumption of conformity. For a machine as a default product this is manageable, because module A is available anyway; the chosen solutions and any technical specifications applied, such as IEC 62443, are then described in the technical documentation (Annex VII point 5).
Can the cybersecurity risk assessment be part of our EN ISO 12100 risk assessment?
Not as a substitute. Article 13(4) CRA, as amended by Regulation (EU) 2025/327, explicitly provides for embedding the cybersecurity risk assessment in the risk assessments of other legislation only for high-risk AI systems (Article 12) and electronic health record systems (Article 32(5a)). For machinery it is best kept as a distinct, identifiable part of the Annex VII technical documentation, with a statement on every requirement in Annex I Part I point 2. The EN ISO 12100 risk assessment remains the place for hazards to people, including protection against corruption under section 1.1.9 of Annex III to the Machinery Regulation. Both can build on the same interface inventory.

Sources

Run EU machinery compliance in-house, in English

This guide is written by the team behind CE-Copilot, a software platform covering the whole EU CE process for machinery: directive classification, a standards finder across 3,600+ standards with harmonisation status, risk assessment per EN ISO 12100, functional safety documentation, test reports, the technical file, operating instructions and the EU Declaration of Conformity with exports in English, German, French and Italian. The platform is available in English; the AI drafts, you review and sign off.

More English guides

This guide is general information for machinery manufacturers, verified against the official EU legal texts as of 15 September 2026. It is not legal advice. For decisions about your specific product, consult the legal texts (EUR-Lex) or a qualified advisor.