Cyber Resilience Act Software for Machinery: Implementing the CRA in CE-Copilot

Legal status as of 15 September 2026

Since 11 September 2026, manufacturers of machines with a data connection have had to report actively exploited vulnerabilities and severe incidents, including for machines already placed on the market, and from 11 December 2027 the full Cyber Resilience Act follows. This guide sums up what is new and then walks through how you handle the work in CE-Copilot: the steps, where they live in the app, what each produces and what the software deliberately leaves to you.

What is new

Since 11 September 2026

Reporting under Article 14 CRA

Actively exploited vulnerabilities and severe incidents having an impact on the security of the product are notified through ENISA's Single Reporting Platform to the CSIRT designated as coordinator and to ENISA: an early warning within 24 hours and a notification within 72 hours of becoming aware, followed by a final report. This also covers machines with a data connection that are already on the market (Article 69(3)).

From 20 January 2027

Protection against corruption under the Machinery Regulation

Under Annex III, sections 1.1.9 and 1.2.1 of Regulation (EU) 2023/1230, connected devices, remote access and interventions in software and data must not lead to a hazardous situation. CE-Copilot handles this in the risk assessment to EN ISO 12100.

Until 10 December 2027

Cybersecurity of radio equipment

Radio equipment within the scope of Delegated Regulation (EU) 2022/30 that is placed on the market from 1 August 2025 to 10 December 2027 has to meet the applicable requirements of Article 3(3)(d), (e) and (f) of the Radio Equipment Directive. EN 18031 only gives a presumption within the restrictions of Implementing Decision (EU) 2025/138, for example not where users may choose to use no password. Delegated Regulation (EU) 2026/339 repeals the rule with effect from 11 December 2027.

From 11 December 2027

The Cyber Resilience Act applies in full

For machines placed on the market on or after that date, or substantially modified on or after it: Annex I requirements, cybersecurity risk assessment, support period, conformity assessment under Article 32, EU declaration of conformity and CE marking (Article 71(2), Article 69(2)).

Scope, classification, procedures and penalties with every legal reference are covered in the Cyber Resilience Act for machinery; how it fits with the Machinery Regulation and the Radio Equipment Directive is explained in cybersecurity for machinery.

Six steps through CE-Copilot

  1. 1. Check whether the CRA applies

    Starter and above

    Standards finder and machine description

    The finder only marks the CRA as applicable when the description shows a data connection; negated statements such as “no data connection” do not count, and without evidence it is listed as “REVIEW” and left unticked. A note on the reporting obligation comes with it.

  2. 2. Classify and confirm the date

    Starter and above

    Risk assessment, cybersecurity module

    Data connection, exclusions under Article 2, core functionality and category under Annex III or IV, plus the confirmed date of placing on the market. The app derives which obligations apply and, once the main obligations apply, the permitted Article 32 procedures.

  3. 3. Record interfaces and assets

    Starter and above

    Risk assessment, protection against corruption module (also on the project page from Professional)

    One inventory feeds three assessments: protection against corruption under the Machinery Regulation, radio equipment cybersecurity and the CRA. Each interface carries reachability, access protection and update path.

  4. 4. Assess risks and evidence the requirements

    Professional and above

    Cybersecurity (CRA) project page

    Scope of the assessment, threats with measures and residual risk, a requirements matrix for Annex I Parts I and II, third-party components, support period, vulnerability handling with SBOM storage and the Annex II user information.

  5. 5. Set up reporting and track cases

    Professional and above

    Project page, reporting section

    Coordinating CSIRT and availability, and per case the time of awareness, deadlines with a traffic light and advance warning, text templates following the wording of Article 14 and the platform's case number.

  6. 6. Produce the evidence and documents

    depends on the module

    Exports, declaration of conformity, operating instructions

    CRA report as PDF and Word, a chapter in the complete dossier, a section in the technical file, check items C1 to C10, the CRA as a legal act in the declaration and the cybersecurity chapter of the operating instructions.

The features in detail

Feature

Obligations derived from the confirmed date of placing on the market

Advantage

The app applies Articles 69 and 71 CRA as fixed rules: for units placed on the market before 11 December 2027 only the reporting obligations apply; for units placed on the market on or after that date, or substantially modified on or after it, the whole Regulation does. A date merely read from the machine description has no legal effect until you confirm it.

Your benefit

The project page, report, dossier, declaration of conformity, test report and operating instructions all say the same thing. You neither demand a CRA conformity assessment for a machine placed on the market before 11 December 2027 nor miss an obligation for a later one.

Feature

One inventory for the Machinery Regulation, radio equipment and the CRA

Advantage

Interfaces such as fieldbus, OPC UA, remote maintenance, USB or radio and the assets behind them are recorded once. The corruption assessment, the EN 18031 checklist and the CRA risk assessment all build on it.

Your benefit

No three lists drifting apart. A new interface shows up in every assessment it matters for.

Feature

Annex I requirements matrix with justification, implementation and evidence

Advantage

For Part I, point 2(a) to (m) you record whether the requirement applies based on the risk assessment, with a justification if it does not; point 1 and Part II on vulnerability handling always apply. For each requirement you document implementation and evidence.

Your benefit

That is what Article 13(3) and (4) and Annex VII require of the technical documentation. The status of each section is always visible, and open items appear as notes in the report.

Feature

Article 14 reporting cases with deadline tracking and templates

Advantage

From the time of awareness the app calculates the early warning (24 hours), the notification (72 hours) and the final report (for vulnerabilities no later than 14 days after a corrective or mitigating measure is available, for incidents within one month of the notification) and flags them as “due soon” on the project page before they expire. While the initial assessment is open, the app runs the deadlines as a precaution from the recorded time of awareness. Reported cases stay on record and cannot be deleted.

Your benefit

When it matters, every hour counts. The templates follow the wording of Article 14; you fill the gaps and submit through ENISA's platform.

Feature

CRA report, dossier chapter and technical file

Advantage

The CRA report brings all sections of the project page together as PDF or Word, with a confidentiality notice. In the complete dossier it appears as a chapter without reporting cases and without the access protection or update path of individual interfaces; the technical file gets a section on Annex VII.

Your benefit

Customers and bodies receive only what belongs with them. Internally you keep the full report with every case and deadline.

Feature

Declaration of conformity, test report and operating instructions kept consistent

Advantage

The declaration only lists the Regulation once classification and date are confirmed and the main obligations apply; procedure fields are pre-filled. The test report marks C1 to C10 as mandatory depending on the date and flags a contradictory “not applicable”. The operating instructions get a cybersecurity chapter with the user information, presented as Annex II information once the classification is confirmed.

Your benefit

No legal act in the declaration that does not apply to this unit, and nothing missing when it does. You maintain the user information once and find it in the report and the instructions.

What the app shows depending on the date of placing on the market

The confirmed date decides which obligations apply to a unit. CE-Copilot derives the same answer in every document:

AreaDate not confirmedBefore 11 December 2027On or after 11 December 2027, or substantially modified on or after that date
Article 14 reportingapplies to every covered productappliesapplies
Declaration of conformityCRA not ticked, reason shown below the boxesno declaration under the CRA, reason shown below the boxesCRA ticked (with confirmed classification), procedure fields pre-filled
Technical file, Annex VII sectionpreparation without mandatory markerspreparation without mandatory markersmandatory items
Test report C1 to C10classification and reporting mandatory, note on “not applicable”classification and reporting mandatoryall ten items mandatory
Operating instructions, cybersecurity chaptermanufacturer's information, no mandatory checkvoluntary informationcheck rule and export warning; Annex II information with confirmed classification
CRA reportwarning “date not confirmed”note on voluntary preparationfull application with the Article 32 procedure

What CE-Copilot deliberately does not do

  • It does not report to ENISA. You submit through the Single Reporting Platform; CE-Copilot provides deadlines, templates and the record of evidence.
  • It gives no legal advice and no automatic conformity. You confirm classification, date and assessment; technical implementation and approval stay with the manufacturer.
  • It cannot create a presumption of conformity: that needs a harmonised standard, common specification or certification scheme, and none exists yet under the CRA (sources as of 11 September 2026); record specifications such as IEC 62443 as applied specifications.
  • It does not generate the SBOM. That comes from your development tools; CE-Copilot stores it.
  • It uses no AI for legal consequences. Key dates, procedures and deadlines are fixed rules, and the class follows from the categories you tick.

See the result

The sample dossier for a robotic welding cell with remote maintenance contains the cybersecurity chapter (chapter 7, pp. 125–138), and the sample operating instructions contain the cybersecurity chapter (chapter 13, pp. 109–113). The cell is placed on the market before 11 December 2027, so you can see how the app treats the reporting obligations as applicable and the other sections as preparation. Plans are listed on the pricing page.

FAQ

Frequently asked questions

Does CE-Copilot submit reports to ENISA?
No. Article 14 notifications go through ENISA's Single Reporting Platform to the coordinating CSIRT and ENISA. CE-Copilot calculates the deadlines from the time of awareness, flags them as “due soon” on the project page before they expire, provides templates following the wording of Article 14 and records the times and the case number as evidence. You submit the notification on the platform.
Do I need this if my machine is placed on the market before 11 December 2027?
For reporting, yes, if the machine has a data connection: the obligations have applied since 11 September 2026, including to machines placed on the market before 11 December 2027 (Article 69(3) CRA). According to the Commission guidance C(2026) 5252 (approved in content on 27 July 2026, not legally binding), cases already known before 11 September 2026 do not have to be reported retroactively. Classification, the reporting process and case tracking are therefore useful today. CE-Copilot presents the other sections for such machines as voluntary preparation until a substantial modification on or after 11 December 2027 brings the full Regulation into play (Article 69(2)). If a series continues beyond that date, the preparation carries over to the later units.
Which plan includes which CRA features?
Classification and obligations in the risk assessment editor, the interface inventory, the declaration of conformity and the technical file are available from the Starter plan. The cybersecurity project page with risk assessment, requirements matrix, reporting cases and CRA report, as well as test reports, are part of the Professional plan. Operating instructions are an add-on from Professional, bought once per project.
Does the CRA risk assessment replace the risk assessment to EN ISO 12100?
No, the two sit side by side. The EN ISO 12100 risk assessment covers hazards to people, including protection against corruption under Annex III, section 1.1.9 of the Machinery Regulation. The cybersecurity risk assessment under Article 13 CRA looks at the product's properties against attacks and belongs in the technical documentation as a part of its own. In CE-Copilot both build on the same interface inventory.
Does an AI decide the classification or the deadlines?
No. Key dates, Article 32 procedures and reporting deadlines are fixed rules. The app derives the classification from the Annex III and IV categories you tick for the core functionality; it only becomes binding once you confirm it, and the same goes for the date of placing on the market. Determining the core functionality remains the manufacturer's judgement (Article 7(1) CRA).
Does CE-Copilot generate the software bill of materials (SBOM)?
No. You create the SBOM with your development tools; CycloneDX and SPDX are common formats. CE-Copilot stores the file in the project, records whether and how users get access to it, and tracks the other vulnerability handling requirements of Annex I, Part II. An implementing act on the format (Article 13(24)) had not been adopted as of this guide.

Run EU machinery compliance in-house, in English

This guide is written by the team behind CE-Copilot, a software platform covering the whole EU CE process for machinery: directive classification, a standards finder across 3,600+ standards with harmonisation status, risk assessment per EN ISO 12100, functional safety documentation, test reports, the technical file, operating instructions and the EU Declaration of Conformity with exports in English, German, French and Italian. The platform is available in English; the AI drafts, you review and sign off.

More English guides

This guide is general information for machinery manufacturers, verified against the official EU legal texts as of 15 September 2026. It is not legal advice. For decisions about your specific product, consult the legal texts (EUR-Lex) or a qualified advisor.