Cyber Resilience Act Software for Machinery: Implementing the CRA in CE-Copilot
Since 11 September 2026, manufacturers of machines with a data connection have had to report actively exploited vulnerabilities and severe incidents, including for machines already placed on the market, and from 11 December 2027 the full Cyber Resilience Act follows. This guide sums up what is new and then walks through how you handle the work in CE-Copilot: the steps, where they live in the app, what each produces and what the software deliberately leaves to you.
What is new
Since 11 September 2026
Reporting under Article 14 CRA
Actively exploited vulnerabilities and severe incidents having an impact on the security of the product are notified through ENISA's Single Reporting Platform to the CSIRT designated as coordinator and to ENISA: an early warning within 24 hours and a notification within 72 hours of becoming aware, followed by a final report. This also covers machines with a data connection that are already on the market (Article 69(3)).
From 20 January 2027
Protection against corruption under the Machinery Regulation
Under Annex III, sections 1.1.9 and 1.2.1 of Regulation (EU) 2023/1230, connected devices, remote access and interventions in software and data must not lead to a hazardous situation. CE-Copilot handles this in the risk assessment to EN ISO 12100.
Until 10 December 2027
Cybersecurity of radio equipment
Radio equipment within the scope of Delegated Regulation (EU) 2022/30 that is placed on the market from 1 August 2025 to 10 December 2027 has to meet the applicable requirements of Article 3(3)(d), (e) and (f) of the Radio Equipment Directive. EN 18031 only gives a presumption within the restrictions of Implementing Decision (EU) 2025/138, for example not where users may choose to use no password. Delegated Regulation (EU) 2026/339 repeals the rule with effect from 11 December 2027.
From 11 December 2027
The Cyber Resilience Act applies in full
For machines placed on the market on or after that date, or substantially modified on or after it: Annex I requirements, cybersecurity risk assessment, support period, conformity assessment under Article 32, EU declaration of conformity and CE marking (Article 71(2), Article 69(2)).
Scope, classification, procedures and penalties with every legal reference are covered in the Cyber Resilience Act for machinery; how it fits with the Machinery Regulation and the Radio Equipment Directive is explained in cybersecurity for machinery.
Six steps through CE-Copilot
1. Check whether the CRA applies
Starter and aboveStandards finder and machine description
The finder only marks the CRA as applicable when the description shows a data connection; negated statements such as “no data connection” do not count, and without evidence it is listed as “REVIEW” and left unticked. A note on the reporting obligation comes with it.
2. Classify and confirm the date
Starter and aboveRisk assessment, cybersecurity module
Data connection, exclusions under Article 2, core functionality and category under Annex III or IV, plus the confirmed date of placing on the market. The app derives which obligations apply and, once the main obligations apply, the permitted Article 32 procedures.
3. Record interfaces and assets
Starter and aboveRisk assessment, protection against corruption module (also on the project page from Professional)
One inventory feeds three assessments: protection against corruption under the Machinery Regulation, radio equipment cybersecurity and the CRA. Each interface carries reachability, access protection and update path.
4. Assess risks and evidence the requirements
Professional and aboveCybersecurity (CRA) project page
Scope of the assessment, threats with measures and residual risk, a requirements matrix for Annex I Parts I and II, third-party components, support period, vulnerability handling with SBOM storage and the Annex II user information.
5. Set up reporting and track cases
Professional and aboveProject page, reporting section
Coordinating CSIRT and availability, and per case the time of awareness, deadlines with a traffic light and advance warning, text templates following the wording of Article 14 and the platform's case number.
6. Produce the evidence and documents
depends on the moduleExports, declaration of conformity, operating instructions
CRA report as PDF and Word, a chapter in the complete dossier, a section in the technical file, check items C1 to C10, the CRA as a legal act in the declaration and the cybersecurity chapter of the operating instructions.
The features in detail
Obligations derived from the confirmed date of placing on the market
The app applies Articles 69 and 71 CRA as fixed rules: for units placed on the market before 11 December 2027 only the reporting obligations apply; for units placed on the market on or after that date, or substantially modified on or after it, the whole Regulation does. A date merely read from the machine description has no legal effect until you confirm it.
The project page, report, dossier, declaration of conformity, test report and operating instructions all say the same thing. You neither demand a CRA conformity assessment for a machine placed on the market before 11 December 2027 nor miss an obligation for a later one.
One inventory for the Machinery Regulation, radio equipment and the CRA
Interfaces such as fieldbus, OPC UA, remote maintenance, USB or radio and the assets behind them are recorded once. The corruption assessment, the EN 18031 checklist and the CRA risk assessment all build on it.
No three lists drifting apart. A new interface shows up in every assessment it matters for.
Annex I requirements matrix with justification, implementation and evidence
For Part I, point 2(a) to (m) you record whether the requirement applies based on the risk assessment, with a justification if it does not; point 1 and Part II on vulnerability handling always apply. For each requirement you document implementation and evidence.
That is what Article 13(3) and (4) and Annex VII require of the technical documentation. The status of each section is always visible, and open items appear as notes in the report.
Article 14 reporting cases with deadline tracking and templates
From the time of awareness the app calculates the early warning (24 hours), the notification (72 hours) and the final report (for vulnerabilities no later than 14 days after a corrective or mitigating measure is available, for incidents within one month of the notification) and flags them as “due soon” on the project page before they expire. While the initial assessment is open, the app runs the deadlines as a precaution from the recorded time of awareness. Reported cases stay on record and cannot be deleted.
When it matters, every hour counts. The templates follow the wording of Article 14; you fill the gaps and submit through ENISA's platform.
CRA report, dossier chapter and technical file
The CRA report brings all sections of the project page together as PDF or Word, with a confidentiality notice. In the complete dossier it appears as a chapter without reporting cases and without the access protection or update path of individual interfaces; the technical file gets a section on Annex VII.
Customers and bodies receive only what belongs with them. Internally you keep the full report with every case and deadline.
Declaration of conformity, test report and operating instructions kept consistent
The declaration only lists the Regulation once classification and date are confirmed and the main obligations apply; procedure fields are pre-filled. The test report marks C1 to C10 as mandatory depending on the date and flags a contradictory “not applicable”. The operating instructions get a cybersecurity chapter with the user information, presented as Annex II information once the classification is confirmed.
No legal act in the declaration that does not apply to this unit, and nothing missing when it does. You maintain the user information once and find it in the report and the instructions.
What the app shows depending on the date of placing on the market
The confirmed date decides which obligations apply to a unit. CE-Copilot derives the same answer in every document:
| Area | Date not confirmed | Before 11 December 2027 | On or after 11 December 2027, or substantially modified on or after that date |
|---|---|---|---|
| Article 14 reporting | applies to every covered product | applies | applies |
| Declaration of conformity | CRA not ticked, reason shown below the boxes | no declaration under the CRA, reason shown below the boxes | CRA ticked (with confirmed classification), procedure fields pre-filled |
| Technical file, Annex VII section | preparation without mandatory markers | preparation without mandatory markers | mandatory items |
| Test report C1 to C10 | classification and reporting mandatory, note on “not applicable” | classification and reporting mandatory | all ten items mandatory |
| Operating instructions, cybersecurity chapter | manufacturer's information, no mandatory check | voluntary information | check rule and export warning; Annex II information with confirmed classification |
| CRA report | warning “date not confirmed” | note on voluntary preparation | full application with the Article 32 procedure |
What CE-Copilot deliberately does not do
- It does not report to ENISA. You submit through the Single Reporting Platform; CE-Copilot provides deadlines, templates and the record of evidence.
- It gives no legal advice and no automatic conformity. You confirm classification, date and assessment; technical implementation and approval stay with the manufacturer.
- It cannot create a presumption of conformity: that needs a harmonised standard, common specification or certification scheme, and none exists yet under the CRA (sources as of 11 September 2026); record specifications such as IEC 62443 as applied specifications.
- It does not generate the SBOM. That comes from your development tools; CE-Copilot stores it.
- It uses no AI for legal consequences. Key dates, procedures and deadlines are fixed rules, and the class follows from the categories you tick.
See the result
The sample dossier for a robotic welding cell with remote maintenance contains the cybersecurity chapter (chapter 7, pp. 125–138), and the sample operating instructions contain the cybersecurity chapter (chapter 13, pp. 109–113). The cell is placed on the market before 11 December 2027, so you can see how the app treats the reporting obligations as applicable and the other sections as preparation. Plans are listed on the pricing page.
FAQ
Frequently asked questions
Does CE-Copilot submit reports to ENISA?
Do I need this if my machine is placed on the market before 11 December 2027?
Which plan includes which CRA features?
Does the CRA risk assessment replace the risk assessment to EN ISO 12100?
Does an AI decide the classification or the deadlines?
Does CE-Copilot generate the software bill of materials (SBOM)?
Run EU machinery compliance in-house, in English
This guide is written by the team behind CE-Copilot, a software platform covering the whole EU CE process for machinery: directive classification, a standards finder across 3,600+ standards with harmonisation status, risk assessment per EN ISO 12100, functional safety documentation, test reports, the technical file, operating instructions and the EU Declaration of Conformity with exports in English, German, French and Italian. The platform is available in English; the AI drafts, you review and sign off.
More English guides
This guide is general information for machinery manufacturers, verified against the official EU legal texts as of 15 September 2026. It is not legal advice. For decisions about your specific product, consult the legal texts (EUR-Lex) or a qualified advisor.