The Cyber Resilience Act for Machinery: Obligations, Deadlines and Reporting
If your machine has a controller with an Ethernet port, a remote-service router or a wireless handheld, the EU Cyber Resilience Act almost certainly applies to it. Part of it already applies: since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents, even for machines delivered years ago. The design, vulnerability handling and documentation requirements follow on 11 December 2027. This guide explains scope, deadlines, classification and what to prepare, with the article references you need to check it yourself.
The key dates
Published in the Official Journal
Regulation (EU) 2024/2847 of 23 October 2024, OJ L, 2024/2847. Corrected by OJ L, 2025/90555 of 2 July 2025 (Articles 13(8) and 64(10)) and OJ L, 2025/90828 of 17 October 2025 (Article 67).
Entry into force
Twenty days after publication (Article 71(1)). No manufacturer obligations apply yet on this date.
Notified bodies
Chapter IV (Articles 35 to 51) applies, so conformity assessment bodies can be notified under the CRA (Article 71(2)).
Reporting obligations apply
Actively exploited vulnerabilities and severe incidents must be reported, including for products placed on the market before this date (Articles 71(2) and 69(3)). ENISA's Single Reporting Platform went live the same day in an initial version.
Full application
Products placed on the market from this date must meet all requirements: Annex I, risk assessment, conformity assessment, declaration and CE marking (Article 71(2)). Products placed on the market earlier are only caught if they undergo a substantial modification after this date (Article 69(2)).
End of transitional validity of certificates
EU-type examination certificates and approval decisions on cybersecurity requirements issued under other Union harmonisation legislation remain valid until this date, unless they expire earlier or that legislation provides otherwise (Article 69(1)).
What decides which obligations apply is therefore the date on which a product is placed on the EU market. For running product lines, the Commission's guidance C(2026) 5252 (content approved on 27 July 2026; no formal adoption found as of 15 September 2026) offers some relief: products designed before 11 December 2027 and placed on the market afterwards do not need to be redesigned if the risk assessment shows that appropriate measures are in place. Conformity assessment, the declaration and CE marking are still required.
Is your machine in scope?
Article 2(1) covers products with digital elements made available on the market "whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network". A product with digital elements is any software or hardware product together with its remote data processing solutions (Article 3(1)), and under Article 3(2) this includes remote data processing software designed by or under the responsibility of the manufacturer, such as a cloud application that a machine function depends on.
Typical triggers on machinery
- Ethernet or fieldbus interface to the plant network or other machines
- Remote service access via router, VPN or portal
- USB port for loading programs or recipes
- Wi-Fi, Bluetooth or cellular, including wireless handhelds
- Connection to the manufacturer's cloud application
Exclusions in Article 2(2) to (7)
- Medical devices and in vitro diagnostics (Regulations (EU) 2017/745 and 2017/746)
- Vehicles under Regulation (EU) 2019/2144 and aviation products certified under Regulation (EU) 2018/1139
- Marine equipment under Directive 2014/90/EU
- Products excluded by delegated act, so far those under Regulation (EU) No 168/2013 (Article 2(5), Delegated Regulation (EU) 2025/1535)
- Identical spare parts (Article 2(6))
- Products developed exclusively for national security or defence (Article 2(7))
Machinery is not on that list. Recital 53 goes further: manufacturers of machinery under Regulation (EU) 2023/1230 should comply with both the CRA and the Machinery Regulation. The Commission's draft guidance adds that a data connection requires encoded digital information, so a purely mechanical machine without a controller or interface is outside the CRA. Software needed to operate, configure or control the machine counts as part of the product, even when customers download it separately.
Reporting obligations that already apply
Two events trigger Article 14. An actively exploited vulnerability is one for which there is reliable evidence that a malicious actor has exploited it in a system without the owner's permission (Article 3(42)). A severe incident affects or can affect the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or has led or can lead to malicious code being introduced or executed in the product or in a user's network (Article 14(5)).
| Step | Actively exploited vulnerability | Severe incident |
|---|---|---|
| Early warning | without undue delay, at the latest within 24 hours of becoming aware, naming the member states where, to the manufacturer's knowledge, the product has been made available (Art. 14(2)(a)) | without undue delay, at the latest within 24 hours of becoming aware, stating whether unlawful or malicious acts are suspected and, where applicable, the member states concerned (Art. 14(4)(a)) |
| Notification | unless already provided, without undue delay and within 72 hours: the product, the general nature of the exploit and vulnerability, corrective measures taken and measures users can take (Art. 14(2)(b)) | unless already provided, without undue delay and within 72 hours: nature of the incident, initial assessment, measures taken and measures users can take (Art. 14(4)(b)) |
| Intermediate report | on request of the CSIRT (Art. 14(6)) | on request of the CSIRT (Art. 14(6)) |
| Final report | unless already provided, no later than 14 days after a corrective or mitigating measure is available (Art. 14(2)(c)) | unless already provided, within one month after the 72-hour notification (Art. 14(4)(c)) |
Reports are submitted through the Single Reporting Platform under Article 16, via the electronic endpoint of the coordinating CSIRT of the member state where the manufacturer has its main establishment, and are simultaneously accessible to ENISA (Article 14(7)). The main establishment is where cybersecurity decisions about the products are predominantly taken, or failing that, the member state of its establishment with the highest number of employees in the EU. Manufacturers without an EU main establishment follow a fallback order in the same paragraph: the member state of the authorised representative acting for most of their products, then that of the importer placing most of them on the market, then that of the distributor making most of them available, and finally the member state where most of their users are. Affected users must also be informed, where needed with mitigation steps (Article 14(8)).
The clock starts at awareness. Under the Commission's draft guidance, a manufacturer becomes aware once an initial assessment, carried out without delay, gives a reasonable degree of certainty that exploitation or a severe incident has occurred. A vulnerability in a third-party component only has to be reported if it was exploited in your own product. Meeting 24 hours takes a process agreed in advance: who assesses, who reports, and which countries each machine type was sold into.
Relief for small manufacturers: the fines under Article 64 CRA do not apply to micro and small enterprises for missing the 24-hour early warning deadline alone (Article 64(10)(a) as corrected by OJ L, 2025/90555). The reporting duty itself and the other deadlines remain. Note the timing, though: under Article 71(2), Article 64 only applies from 11 December 2027, as only Article 14 and Chapter IV were brought forward. Whether and how breaches of the reporting obligations can be penalised before then depends on national law; in Germany, no promulgation of the national implementing act could be found as of 15 September 2026.
Default, important or critical?
The conformity assessment route depends on classification, and classification follows the product's core functionality (Articles 7(1) and 8(1)). Implementing Regulation (EU) 2025/2392 contains the technical descriptions of the categories. According to the Commission's draft guidance, a product has exactly one core functionality for this purpose, which should be named in the technical documentation.
| Category | What falls under it | Conformity assessment |
|---|---|---|
| Default product | Everything whose core functionality does not match a category in Annex III or IV. This is where machinery itself normally sits. | Internal control (module A), or on a voluntary basis EU-type examination plus conformity to type (modules B and C), full quality assurance (module H) or, where available and applicable, a European cybersecurity certification scheme (Article 32(1)). |
| Important, Class I (Annex III) | 19 categories, including routers, modems intended for internet connection and switches (point 12), physical and virtual network interfaces (point 10), operating systems (point 11), network management systems (point 6) and VPN products (point 5). | Module A only where harmonised standards, common specifications or European certification schemes at assurance level 'substantial' or higher are applied in full; otherwise modules B and C or module H (Article 32(2)). |
| Important, Class II (Annex III) | Hypervisors and container runtime systems, firewalls, intrusion detection and prevention systems, tamper-resistant microprocessors and microcontrollers. | Modules B and C, module H, or, where available and applicable, a European certification scheme at level 'substantial' or higher; module A is not available (Article 32(3)). |
| Critical (Annex IV) | Hardware devices with security boxes, smart meter gateways and other devices for advanced security purposes, smartcards and secure elements. | A European certification scheme once a delegated act under Article 8(1) requires it; until then the Class II procedures (Article 32(4)). |
The integration rule
Article 7(1) states that integrating a product with the core functionality of an Annex III category does not in itself make the host product subject to the procedures of Article 32(2) and (3). The managed switch in the control cabinet, the HMI panel running an operating system or the fieldbus card do not turn your machine into an important product. The machine normally stays a default product.
Take a closer look if you also sell components on their own. Implementing Regulation (EU) 2025/2392 explicitly lists fieldbus controllers and adapters among the Class I network interfaces and real-time operating systems among the Class I operating systems. A remote-service router, fieldbus interface card or cabinet firewall that you market separately therefore needs its own classification.
Conformity assessment and the missing standards
Important Class I products may only use internal control if harmonised standards, common specifications or certification schemes are applied in full (Article 32(2)). That is exactly where the bottleneck lies: as of 11 September 2026, no harmonised standard under the CRA has been cited in the Official Journal, according to standards trackers and industry reports. The Commission's standardisation request M/606 of 3 February 2025 covers 41 standards, with work under way on the horizontal EN 40000 series and, for operational technology products, the prEN 50770 series based on IEC 62443. A postponement of the standardisation deadlines exists only as a draft.
For the machine itself this is less critical. As a default product it can use module A without harmonised standards; the technical documentation then has to describe the solutions adopted for Annex I Parts I and II and list any other technical specifications applied (Annex VII point 5). IEC 62443-4-1 and -4-2 remain the obvious technical basis, even though an industry analysis of 6 July 2026 considers a citation under the CRA unlikely.
Where a machine falls under both the Machinery Regulation and the CRA, a single EU declaration of conformity covers both acts and lists them with their Official Journal references (Article 28(3)). Annex V sets out what the declaration has to contain for the CRA.
What applies from 11 December 2027
1. Cybersecurity risk assessment (Article 13(2) to (4))
The assessment starts from the intended purpose and reasonably foreseeable use, considers the operational environment, the assets to be protected and the expected time in use, and feeds into planning, design, production, delivery and maintenance. For every requirement in Annex I Part I point 2 it must state whether and how it applies and how it is implemented; a requirement that does not apply needs a clear justification in the technical documentation. It is documented and, where appropriate, updated during the support period (Article 13(3)).
2. Product requirements (Annex I Part I)
Based on the risk assessment, and where applicable, point 2 requires:
- ano known exploitable vulnerabilities when made available
- ba secure-by-default configuration and a way to reset to the original state
- cthe ability to fix vulnerabilities through security updates
- dprotection against unauthorised access, e.g. authentication and access management, with reporting of possible unauthorised access
- econfidentiality of stored, transmitted or processed data
- fintegrity of data, commands, programs and configuration, with reporting of corruption
- gdata minimisation
- havailability of essential functions, including resilience against denial-of-service attacks
- iminimal negative impact on other devices and networks
- jlimited attack surfaces, including external interfaces
- kmechanisms that reduce the impact of an incident
- lrecording or monitoring of relevant internal activity, with an opt-out for users
- msecure and easy deletion of all data and settings, and secure data transfer
Our own summary of points (a) to (m); the binding wording is in the Regulation. Point (c) only calls for automatic security updates where applicable, and according to recital 56 the related rules should not apply where users would not normally expect automatic updates, for example in industrial environments where an automatic update could disrupt operations.
3. Vulnerability handling (Annex I Part II)
Part II applies without the "where applicable" qualifier. It requires a software bill of materials in a commonly used, machine-readable format covering at least the top-level dependencies, remediation without delay through security updates kept separate from feature updates where technically feasible, regular security testing, publication of fixed vulnerabilities, a coordinated vulnerability disclosure policy, a contact address for vulnerability reports, secure update distribution and free security updates. The SBOM does not have to be published (recital 77), but market surveillance can request it on a reasoned basis (Annex VII point 8).
4. Third-party components (Article 13(5) and (6))
Manufacturers must exercise due diligence when integrating third-party components, including open-source software, so that they do not compromise the product's cybersecurity. A vulnerability found in a component is reported to whoever manufactures or maintains it, together with any fix you developed. For PLCs, HMIs, routers and drives this means collecting and documenting your suppliers' security information and support periods.
5. Support period (Article 13(8), (9) and (19))
The support period reflects the expected time in use and lasts at least five years, unless the product is expected to be in use for less. The Commission's draft guidance makes clear that five years is not a default, and recital 60 names industrial control systems as an example of much longer use. The end date must be stated at the time of purchase with at least month and year, and each security update stays available for at least ten years or the remainder of the support period, whichever is longer. The reasoning behind the chosen period belongs in the technical documentation.
6. Information for users (Annex II)
The machine has to come with, among other things: manufacturer contact details, the single point of contact for vulnerability reports and the disclosure policy, unambiguous product identification, intended purpose with the security environment and security properties, known circumstances that may lead to significant cybersecurity risks, where applicable the internet address of the declaration of conformity, the type of security support and end of the support period, and instructions on secure commissioning, updates, decommissioning and integration. This fits naturally into a dedicated chapter of the operating instructions and must stay available for at least ten years or the support period, whichever is longer (Article 13(18)).
7. Technical documentation, declaration and CE marking
Before placing on the market come the Annex VII technical documentation, the conformity assessment under Article 32, the EU declaration of conformity and CE marking (Article 13(12)). Documentation and declaration are kept for at least ten years or the support period, whichever is longer (Article 13(13)). Manufacturers also designate a single point of contact through which users can reach them directly (Article 13(17)).
How the CRA relates to the Machinery Regulation and the RED
The CRA does not replace any machinery requirement. From 20 January 2027, Annex III of the Machinery Regulation requires protection against corruption (section 1.1.9) and control systems that, where appropriate to the circumstances and risks, withstand reasonably foreseeable malicious attempts from third parties leading to a hazardous situation (section 1.2.1). Recital 53 of the CRA says that meeting the CRA may facilitate compliance with those sections, but the manufacturer has to demonstrate that synergy and should follow both conformity assessment procedures. CRA compliance alone gives no presumption of conformity for sections 1.1.9 and 1.2.1. Under the Machinery Regulation, that presumption comes from harmonised standards referenced in the Official Journal (Article 20(1)) or common specifications (Article 20(6)) and, for these two sections specifically, also from certification or a statement of conformity under a Cybersecurity Act (EU) 2019/881 scheme referenced in the Official Journal (Article 20(9)).
If a machine with a radio module counts as radio equipment and meets the criteria of Delegated Regulation (EU) 2022/30, such as communicating over the internet, the resulting cybersecurity requirements of the Radio Equipment Directive apply to units placed on the market until 10 December 2027; the Delegated Regulation is repealed with effect from 11 December 2027 by Delegated Regulation (EU) 2026/339. How the three regimes interact, and why the cybersecurity risk assessment needs its own method next to EN ISO 12100, is covered in Cybersecurity for machinery.
Penalties and authorities
- Non-compliance with Annex I or the obligations in Articles 13 and 14: up to EUR 15 million or 2.5 % of worldwide annual turnover (Article 64(2)).
- Breaches of other obligations, including the declaration, CE marking, technical documentation and conformity assessment: up to EUR 10 million or 2 % (Article 64(3)).
- Incorrect, incomplete or misleading information to notified bodies and market surveillance authorities: up to EUR 5 million or 1 % (Article 64(4)).
In each case the higher amount applies; the nature, gravity and duration of the infringement and the size of the company are taken into account (Article 64(5)). Article 64 applies from 11 December 2027 (Article 71(2)); whether breaches of the reporting obligations that have applied since 11 September 2026 can be penalised earlier depends on national law.
Member states designate their own market surveillance authorities. In Germany, BSI announced that its CERT-Bund acts as coordinating CSIRT since 11 September 2026, and a draft federal act implementing the CRA (Bundestag document 21/6134 of 26 May 2026) makes BSI the market surveillance authority, notifying authority and authority for fines; as of 15 September 2026 no promulgation could be found. For machinery law, the market surveillance authorities of the German federal states remain responsible, and how checks of CRA aspects on machinery will be split with BSI is still open. Manufacturer obligations apply directly from the Regulation regardless.
Still open as of 15 September 2026
- The Commission's guidance C(2026) 5252 of 27 July 2026 has been approved in content; no formal adoption with all language versions could be found. It is not legally binding; the interpretations quoted in this guide come from that version.
- No harmonised standard under the CRA is cited in the Official Journal (sources as of 11 September 2026).
- Not yet adopted, among others: the SBOM format (Article 13(24)), the format and procedure of notifications (Article 14(10)) and the simplified technical documentation form for micro and small enterprises (Article 33(5)).
How CE-Copilot covers this
CE-Copilot handles CRA work in the same project as the risk assessment, the declaration of conformity and the operating instructions. Classification, deadlines and procedure rules are fixed logic, not AI estimates.
- Standards finder and risk assessment (Starter and above): the standards finder only lists the CRA as mandatory when the machine description shows a data connection, together with a note on the reporting obligation. In the risk assessment editor, the cybersecurity module guides you through scope, core functionality and Annex III and IV classification, shows what applies based on the date of placing on the market and, for machines placed on the market from 11 December 2027, records the Article 32 procedure.
- Cybersecurity project page (Professional and above): interface and asset inventory, cybersecurity risk assessment, Annex I requirements matrix with applicability, justification, implementation and evidence, third-party components, support period, vulnerability handling with SBOM storage, Article 14 reporting cases with deadline tracking and templates, and the Annex II user information.
- Documents: CRA report as PDF and Word, a cybersecurity chapter in the complete dossier, a cybersecurity section in the technical file, the CRA as an additional act in the declaration of conformity (ticked only once the main obligations apply to the unit) and a cybersecurity chapter with the Annex II information in the operating instructions (add-on from Professional, one-off purchase per project).
The step-by-step walkthrough is in Cyber Resilience Act software for machinery. See the result in the sample dossier (chapter 7, pp. 125–138) and the sample operating instructions (chapter 13). Plans are listed on the pricing page.
The software structures and documents the work. Assessment, technical implementation and approval stay with the manufacturer, and Article 14 reports are submitted through ENISA's Single Reporting Platform, not from CE-Copilot.
FAQ
Frequently asked questions
Does the Cyber Resilience Act apply to machinery?
What do machinery manufacturers have to do since 11 September 2026?
Do the reporting obligations cover machines we sold years ago?
Does an integrated industrial switch or router make my machine an important product?
Do I need a notified body for my machine under the CRA?
How long should the support period be for industrial machinery?
We have no establishment in the EU. Where do we report?
Are there harmonised standards for the Cyber Resilience Act yet?
Can the cybersecurity risk assessment be part of our EN ISO 12100 risk assessment?
Sources
- Regulation (EU) 2024/2847 (Cyber Resilience Act), OJ L, 2024/2847, 20 November 2024: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2847
- Corrigendum to Regulation (EU) 2024/2847, OJ L, 2025/90555, 2 July 2025: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202590555
- Corrigendum to Regulation (EU) 2024/2847, OJ L, 2025/90828, 17 October 2025: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202590828
- Regulation (EU) 2025/327 (Article 104 amends Article 13(4) CRA): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32025R0327
- Commission Implementing Regulation (EU) 2025/2392 (technical description of important and critical products): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32025R2392
- European Commission: guidance on CRA implementation, C(2026) 5252 of 27 July 2026: https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation
- European Commission: CRA standardisation: https://digital-strategy.ec.europa.eu/en/policies/cra-standardisation
- ENISA: The CRA Single Reporting Platform is launched, 11 September 2026: https://www.enisa.europa.eu/news/the-cra-single-reporting-platform-is-launched
- BSI (German Federal Office for Information Security): press release on the start of CRA reporting, 11 September 2026 (German): https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2026/260911_CRA_Meldepflicht_Schwachstellen.html
- German draft act implementing the CRA, Bundestag document 21/6134 of 26 May 2026 (German): https://dserver.bundestag.de/btd/21/061/2106134.pdf
Run EU machinery compliance in-house, in English
This guide is written by the team behind CE-Copilot, a software platform covering the whole EU CE process for machinery: directive classification, a standards finder across 3,600+ standards with harmonisation status, risk assessment per EN ISO 12100, functional safety documentation, test reports, the technical file, operating instructions and the EU Declaration of Conformity with exports in English, German, French and Italian. The platform is available in English; the AI drafts, you review and sign off.
More English guides
This guide is general information for machinery manufacturers, verified against the official EU legal texts as of 15 September 2026. It is not legal advice. For decisions about your specific product, consult the legal texts (EUR-Lex) or a qualified advisor.