Cybersecurity for Machinery: How the Machinery Regulation, RED and CRA Fit Together

Legal references checked against the Official Journal

A machine with remote service, a wireless handheld and a cloud link has to satisfy up to three different EU cybersecurity regimes by the end of 2027, depending on when it is placed on the market. Each asks its own question: can people get hurt, are the network and data protected, and does the product stay resilient for as long as it is used? This guide sorts out the requirements, lays out the timeline and explains why the cybersecurity risk assessment needs a method of its own next to EN ISO 12100.

Three laws, three protection goals

TopicMachinery RegulationRadio Equipment DirectiveCyber Resilience Act
What it protectsHealth and safety of people: corruption and malicious interference must not lead to hazardous situations (Annex III sections 1.1.9 and 1.2.1).The network (point (d)), personal data and privacy (point (e)) and protection from fraud (point (f)) under Article 3(3) of Directive 2014/53/EU.Cybersecurity of the product over its life cycle: product properties under Annex I Part I, vulnerability handling under Part II, reporting under Article 14.
Who is coveredMachinery and related products.Radio equipment; whether a machine with a permanently integrated radio module counts as such as a whole is not fully settled. Point (d) for equipment that can communicate over the internet.Products with digital elements with a data connection to a device or network.
Appliesfrom 20 January 2027to equipment placed on the market from 1 August 2025 to 10 December 2027Article 14 since 11 September 2026, everything else from 11 December 2027
MethodRisk assessment under Annex III, in practice EN ISO 12100: threats treated as hazards with severity and probability.Mechanisms of EN 18031-1, -2 or -3:2024: applicability and appropriateness per mechanism with documented justification.Cybersecurity risk assessment under Article 13(2) to (4) with a statement on each requirement of Annex I Part I point 2.
Presumption of conformityNo harmonised standard under the Regulation cited in the Official Journal yet (sources as of 11 September 2026). Presumption via harmonised standards referenced in the Official Journal (Article 20(1)), common specifications adopted by the Commission (Article 20(6)) and, for sections 1.1.9 and 1.2.1, also via a Regulation (EU) 2019/881 scheme referenced in the Official Journal (Article 20(9)).EN 18031 is cited, but only without the options excluded by Implementing Decision (EU) 2025/138.No harmonised standard cited yet (sources as of 11 September 2026).

Timeline for a machine with a radio module

Which design and conformity requirements apply depends on the date the machine is placed on the EU market:

Placed on the marketMachinery lawRadio cybersecurityfor the radio equipment; whether the machine as a whole counts as radio equipment is not fully settledCyber Resilience Act
until 31 Jul 2025Machinery Directive 2006/42/ECRED points (d), (e), (f) not applicabledesign obligations not applicable
1 Aug 2025 to 19 Jan 2027Machinery Directive 2006/42/ECpoints (d), (e), (f) via Delegated Regulation (EU) 2022/30 where its criteria are metdesign obligations not applicable
20 Jan 2027 to 10 Dec 2027Machinery Regulation (EU) 2023/1230 including sections 1.1.9 and 1.2.1points (d), (e), (f) still apply via Delegated Regulation (EU) 2022/30design obligations not applicable
from 11 Dec 2027Machinery Regulation (EU) 2023/1230Delegated Regulation (EU) 2022/30 repealed; points (d), (e), (f) no longer apply to newly placed equipmentfully applicable: Annex I, Article 13, conformity assessment under Article 32

Regardless of the date: since 11 September 2026, the CRA reporting obligations in Article 14 apply to all products with digital elements, including machines delivered long before (Article 69(3) CRA). See The Cyber Resilience Act for machinery.

Since January 2026, industry associations have been asking for section 1.1.9 and section 1.2.1(f) of the Machinery Regulation to be aligned with the CRA timeline, i.e. postponed to 11 December 2027. No legal act to that effect was known as of 15 September 2026; plan for 20 January 2027.

Machinery Regulation: protection against corruption

Section 1.1.9 of Annex III is new to machinery law. In substance it asks for five things. Connecting another device, or remote access, must not lead to a hazardous situation. Hardware that carries signals or data relevant for access to safety-critical software must be protected against accidental or intentional corruption, and the machine must collect evidence of interventions in it. Safety-critical software and data must be identified and protected. The installed software needed for safe operation must be identifiable on the machine at any time. And the machine must collect evidence of legitimate or illegitimate interventions in the software or its configuration.

Section 1.2.1 adds that control systems must, where appropriate to the circumstances and risks, withstand, among other things, reasonably foreseeable malicious attempts from third parties leading to a hazardous situation (point (a)), that the limits of safety functions follow from the risk assessment and hazardous changes to settings are prevented (point (d)), and that the tracing log of interventions and of uploaded safety software versions is enabled for five years after upload, for reasoned requests from competent authorities (point (f)).

The protection goal is still the safety of people, so these requirements belong in the risk assessment: threats such as a manipulated safety parameter or an unexpected remote start are assessed as hazards with severity and probability and reduced through the usual hierarchy of measures. The supporting standard, prEN 50742, is only a draft (industry reports of 31 July and 25 August 2026) and describes two routes: approach A with the standard's own process and product requirements, based on a manufacturer-specific threat analysis in line with EN ISO 12100, and approach B via the IEC 62443 series. A presumption of conformity under Article 20(1) will only come with a citation in the Official Journal; common specifications adopted by the Commission would also give one under Article 20(6). Separately, Article 20(9) of the Machinery Regulation grants a presumption for sections 1.1.9 and 1.2.1 to certification or a statement of conformity under a Cybersecurity Act (EU) 2019/881 scheme referenced in the Official Journal.

Radio Equipment Directive: EN 18031 until 10 December 2027

When the machine becomes radio equipment

Whether a machine with a permanently integrated radio module counts as radio equipment as a whole is not fully settled. The Commission's 2018 supplementary guidance treats a non-radio electrical product with incorporated, permanently affixed radio equipment as a single product under the RED; FEM and CAPIEL interpret the RED the same way in their guidance for the products of their sectors. The guide to the Machinery Directive is narrower. Under this reading, a plug-in or easily removable module remains a separate product. According to the associations, you build on the module manufacturer's evidence but assess the combination. If the machine counts as radio equipment, recital 8 of Delegated Regulation (EU) 2022/30 says all aspects and parts of the equipment should comply, not only the radio function.

Which points apply

  • Point (d), network protection: all radio equipment that can itself communicate over the internet, directly or via other equipment (Article 1(1) of Delegated Regulation 2022/30). Typical for machines with remote service over cellular or Wi-Fi.
  • Point (e), personal data and privacy: among others, internet-connected radio equipment that can process personal, traffic or location data (Article 1(2)), such as operator log-ins or location data of mobile machinery.
  • Point (f), fraud protection: internet-connected radio equipment that allows the transfer of money, monetary value or virtual currency (Article 1(3)); rare on machinery.

EN 18031 and its restrictions

EN 18031-1, -2 and -3:2024 were cited by Implementing Decision (EU) 2025/138 of 28 January 2025, with restrictions. The sections titled "rationale" and "guidance" give no presumption. If users may choose not to set or use a password under clauses 6.2.5.1 and 6.2.5.2, the presumption is lost in all three parts. In part 2 it is also lost for certain child and toy categories where parental access control is not ensured through the designated clauses, and in part 3 the assessment criteria of clause 6.3.2.4 on secure updates give no presumption.

Consequence for the procedure: without the presumption, Article 17(4) of Directive 2014/53/EU leaves only EU-type examination (Annex III) or full quality assurance (Annex IV) for the cybersecurity requirements, both with a notified body. This applies to the restrictions on passwords, parental access control and clause 6.3.2.4; the restriction on the "rationale" and "guidance" sections alone does not require a notified body. The Commission's EN 18031 guidance states that part 3 with clause 6.3.2.4 always requires third-party assessment. Internal production control remains available for safety and EMC (Article 3(1)) either way.

The standards work with mechanisms. For each interface and each asset that needs protection, you decide whether a mechanism applies and whether its implementation is appropriate, with a documented justification:

  • ACMaccess control to assets that need protection
  • AUMauthentication, including password rules and brute-force protection
  • SUMsecure updates
  • SSMsecure storage
  • SCMsecure communication
  • RLMresilience against overload (part 1 only)
  • NMM, TCMnetwork monitoring and traffic control (network equipment, part 1)
  • LGMlogging (parts 2 and 3)
  • DLM, UNMdeletion of data and user notification (part 2)
  • CCK, CRYcryptographic keys and state-of-the-art cryptography
  • GECgeneral equipment capabilities, such as no known exploitable vulnerabilities and no unnecessary interfaces

Codes from EN 18031, descriptions in our own words. Relevant for machinery: the standard allows an exception from updatability where functional safety does not permit it, and exceptions for access-restricted environments, which must be justified. Radio signals often reach beyond the factory wall.

The expiry date

Delegated Regulation (EU) 2026/339 of 16 February 2026 repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027. Recitals 3 and 4 explain why: the CRA's essential requirements cover all elements of points (d), (e) and (f), and radio equipment should not be subject to both regimes at once. Market surveillance of radio equipment placed on the market from 1 August 2025 to 10 December 2027 remains possible under the old requirements (recital 5), so your EN 18031 files stay relevant for those units. EN 18031 has no reference under the CRA (sources as of 11 September 2026), but it is solid groundwork: recital 30 CRA says the standardisation work carried out under Implementing Decision C(2022) 5637 should be taken into account when harmonised standards for the CRA are developed.

Cyber Resilience Act: the product over its time in use

The CRA applies to the machine as a product with digital elements as soon as it has a data connection to a device or network. Its focus is the cybersecurity of the product itself, while keeping the impact of incidents on users' health and safety as low as possible (Article 13(2)): secure default configuration, protection against unauthorised access, data integrity and confidentiality, a small attack surface, security updates throughout a defined support period, a software bill of materials and vulnerability handling. Reporting already applies; everything else follows on 11 December 2027. Scope, classification, procedures and reporting are explained in The Cyber Resilience Act for machinery.

Why cybersecurity risk assessment needs its own method

An EN ISO 12100 risk assessment looks for hazards, meaning potential sources of injury or damage to health, and rates risk as a combination of the severity and probability of that harm (Annex III Part A of the Machinery Regulation). A cybersecurity risk under Article 3(37) CRA is something else: the potential for loss or disruption caused by an incident, expressed by its magnitude and likelihood. The CRA does take effects on users' health and safety into account (Article 13(2)), but its starting point is the incident. Leaked recipe data, a crippled plant network or tampered production counts injure nobody, so they never show up in a safety risk assessment.

The required form differs too. The CRA wants a statement on every requirement in Annex I Part I point 2: whether and how it applies and how it is implemented, with a clear justification where it does not apply (Article 13(3) and (4)). EN 18031 wants a decision per mechanism. And Article 13(4) CRA, as amended by Regulation (EU) 2025/327, explicitly provides for embedding the CRA assessment in another act's risk assessment only for high-risk AI systems and electronic health record systems. This mirrors a general principle of EU product law: the required risk analysis follows the protection goals of the act in question.

According to the Commission's CRA guidance, internal risk appetite and cost are not the benchmark, risks may not be shifted onto users, and restricting use to trusted environments is acceptable (content approved on 27 July 2026; no formal adoption found as of 15 September 2026).

Example: remote service access via a cellular router

Legal actKey questionOutcome
Machinery Regulation, Annex III sections 1.1.9 and 1.2.1Can remote access create a hazardous situation, such as a start-up during maintenance or a changed safety parameter?A hazard in the risk assessment with a risk rating; measures in the three-step hierarchy, e.g. remote access only after local approval, safety parameters not changeable remotely, evidence of interventions.
RED, Delegated Regulation (EU) 2022/30 point (d)Is the router internet-connected radio equipment, and does the combination protect the network?EN 18031-1: authentication without a 'no password' option, secure communication, secure updates, no unnecessary services, each with a justification.
Cyber Resilience ActIs the product resilient against attacks and maintained throughout its time in use?A statement on Annex I Part I point 2, e.g. (d) unauthorised access and (j) attack surface; a support period that covers the router firmware, an SBOM, vulnerability handling and a reporting process.

The same interface appears in three assessments with three key questions. That is not duplicate work as long as all three build on one shared inventory.

The starting point: an interface and asset inventory

All three laws assume you know how your machine can be attacked and what needs protecting. Section 1.1.9 of the Machinery Regulation explicitly requires safety-critical software and data to be identified; EN 18031 distinguishes security, network, privacy and financial assets; and Annex VII point 2(a) CRA mentions, where applicable, drawings, schemes or a description of the system architecture for the technical documentation.

Per interface

  • Type: Ethernet, fieldbus, USB, Wi-Fi, Bluetooth, cellular, HMI, service port, cloud
  • Protocol and connection: local, plant network or internet
  • Authentication and access rights
  • Update path
  • Reachability, for radio also outside the building

Per asset

  • Safety functions, safety parameters and safety software
  • Programs, recipes and configuration
  • Credentials and cryptographic keys
  • Personal data such as operator log-ins or location data
  • Impact of manipulation, disclosure and loss

Purchased PLCs, HMIs and routers belong in the inventory together with their security information and support periods. Where such components are intended for integration into other products and placed on the market from 11 December 2027, Annex II point 8(f) CRA requires their manufacturers to tell integrators how to meet the requirements.

A roadmap for machinery manufacturers

1

Build the inventory: Interfaces, assets and purchased components per machine type.

2

Pin down the legal situation per product line: Record the date of placing on the market; radio cybersecurity, Machinery Regulation and CRA obligations follow from it.

3

Set up CRA reporting under Article 14: Already required for machines in the field: responsibilities, contact address, list of countries, access to the reporting platform.

4

Add corruption to the risk assessment: Threats that can lead to hazardous situations, with a risk rating and measures, well before 20 January 2027.

5

Demonstrate radio cybersecurity: Determine the applicable EN 18031 parts, justify each mechanism and avoid the excluded options, or plan for a notified body.

6

Prepare the CRA file by 11 December 2027: Risk assessment with requirements matrix, support period, SBOM, disclosure policy and Annex II user information.

7

Issue one declaration: A single EU declaration of conformity listing all applicable acts with their Official Journal references.

How CE-Copilot covers this

In CE-Copilot the three strands are separate assessments in the same project, built on a shared interface and asset inventory: the CRA project page works with it in full, the corruption analysis takes recorded interfaces as a starting point, and the radio module maps the recorded assets to the EN 18031 mechanisms.

  • Protection against corruption (Starter and above): threat analysis for sections 1.1.9 and 1.2.1 following approach A of draft prEN 50742 (manufacturer-specific threat analysis in line with EN ISO 12100), with threat scenarios as hazards with risk ratings and three-step measures, the related IEC 62443-3-3 requirements as reference and a requirements checklist in the test reports (Professional and above).
  • Radio equipment (Starter and above): a checklist of EN 18031 mechanisms per applicable part, the restrictions of Implementing Decision (EU) 2025/138 with their consequence for the procedure, and the applicable rules based on the date of placing on the market.
  • Cyber Resilience Act: classification and obligations in force in the risk assessment editor (Starter and above), plus the cybersecurity project page with risk assessment, requirements matrix, vulnerability handling, reporting and the CRA report (Professional and above).
  • Clean separation in the documents: in the PDF and Word risk assessment, the radio and CRA assessments appear as separately titled sections next to the EN ISO 12100 hazards. Corruption scenarios deliberately stay hazards of the risk assessment, because section 1.1.9 belongs to the Machinery Regulation. With CRA data, the complete dossier gets its own cybersecurity chapter.

See an example in the sample dossier and compare plans on the pricing page. Assessment, technical implementation and approval stay with the manufacturer.

FAQ

Frequently asked questions

Which EU laws govern the cybersecurity of machinery?
Three, each with its own protection goal and timeline. The Machinery Regulation (EU) 2023/1230 requires protection against corruption (Annex III section 1.1.9) and control systems that, where appropriate to the circumstances and risks, withstand reasonably foreseeable malicious attempts from third parties leading to a hazardous situation (section 1.2.1) from 20 January 2027; the concern is the safety of people. The Radio Equipment Directive 2014/53/EU, through Delegated Regulation (EU) 2022/30, requires radio equipment placed on the market between 1 August 2025 and 10 December 2027 that meets the criteria of its Article 1, such as internet connectivity, to protect the network, personal data and against fraud. The Cyber Resilience Act (EU) 2024/2847 covers products with digital elements, with reporting obligations since 11 September 2026 and all other obligations from 11 December 2027.
Does a built-in Wi-Fi or cellular module make my machine radio equipment?
This is not fully settled. The Commission's 2018 supplementary guidance on the LVD, EMCD and RED treats a non-radio electrical product with incorporated, permanently affixed radio equipment as a single product under the RED. The industry associations FEM and CAPIEL interpret the RED the same way in their guidance for the products of their sectors. The guide to the Machinery Directive is narrower and only mentions the requirements on the use of the radio spectrum. Under this reading, a plug-in or easily removable module remains a separate product. If you follow the broad reading, assess the combination of machine and radio module.
Is a CE-marked radio module from my supplier enough?
Not on its own. According to FEM and CAPIEL, the module manufacturer's conformity assessment does not have to be repeated, but you check and document that the integration instructions were followed and that integration does not compromise conformity. If the machine counts as radio equipment, recital 8 of Delegated Regulation (EU) 2022/30 says that all aspects and parts of the equipment should comply, not just the radio function, so a web server or remote access on the machine controller can become part of the assessment. As the Blue Guide notes, CE-marked parts do not automatically guarantee that the finished product complies.
What happens to EN 18031 after 11 December 2027?
Delegated Regulation (EU) 2022/30 is repealed with effect from 11 December 2027 by Delegated Regulation (EU) 2026/339. Radio equipment placed on the market from that date is no longer subject to the RED cybersecurity requirements; the Cyber Resilience Act takes over. Market surveillance of equipment placed on the market between 1 August 2025 and 10 December 2027 remains possible under the old requirements (recital 5 of Delegated Regulation 2026/339), so keep your EN 18031 documentation. EN 18031 has no reference under the CRA (sources as of 11 September 2026), but it can serve as groundwork: according to recital 30 CRA, the CRA's essential cybersecurity requirements cover all elements of the requirements in Article 3(3)(d), (e) and (f) of the RED, and the standardisation work carried out under Implementing Decision C(2022) 5637 should be taken into account when harmonised standards for the CRA are developed.
If my machine complies with the CRA, does it automatically meet section 1.1.9 of the Machinery Regulation?
No. Recital 53 of the CRA says that compliance with the CRA may facilitate compliance with sections 1.1.9 and 1.2.1, but the manufacturer has to demonstrate the synergy and should follow both conformity assessment procedures. CRA compliance alone gives no presumption of conformity. The Machinery Regulation presumes conformity where harmonised standards referenced in the Official Journal (Article 20(1)) or common specifications adopted by the Commission (Article 20(6)) are applied and, for these two sections, also where certification or a statement of conformity under a Cybersecurity Act (EU) 2019/881 scheme referenced in the Official Journal exists (Article 20(9)).
Is there a harmonised standard for protection against corruption?
Not yet (sources as of 11 September 2026). prEN 50742 on protection against corruption is a draft; according to an industry report of 25 August 2026, the final vote is planned for September 2026, with publication possibly following in November 2026. Without a citation in the Official Journal under the Machinery Regulation there is no presumption of conformity. Until then, a threat analysis within the risk assessment, technically supported by the draft standard and the IEC 62443 series, remains the way to go.
Why is an EN ISO 12100 risk assessment not enough for cybersecurity?
Because it protects something else. Under the Machinery Regulation a hazard is a potential source of injury or damage to health. A cybersecurity risk under Article 3(37) CRA is the potential for loss or disruption caused by an incident, such as leaked data or a network outage that injures nobody. The CRA also asks for a statement on every requirement in Annex I Part I point 2, and EN 18031 for a decision per mechanism. Threats that can lead to hazardous situations stay in the EN ISO 12100 risk assessment; the other assessments sit next to it.
Can users run the machine without a password?
If the machine or its radio module is radio equipment covered by Delegated Regulation (EU) 2022/30 and is placed on the market between 1 August 2025 and 10 December 2027, that is risky: if the manufacturer lets users skip setting or using a password under EN 18031 clauses 6.2.5.1 and 6.2.5.2, the standard gives no presumption of conformity according to Implementing Decision (EU) 2025/138. For the cybersecurity requirement concerned, Article 17(4) of Directive 2014/53/EU then leaves only EU-type examination or full quality assurance, both involving a notified body. For machines placed on the market from 11 December 2027, the Cyber Resilience Act requires, where applicable on the basis of the cybersecurity risk assessment, a secure-by-default configuration and protection against unauthorised access (Annex I Part I point 2(b) and (d) CRA).

Sources

Only codes and our own short descriptions are taken from the EN 18031 standards.

Run EU machinery compliance in-house, in English

This guide is written by the team behind CE-Copilot, a software platform covering the whole EU CE process for machinery: directive classification, a standards finder across 3,600+ standards with harmonisation status, risk assessment per EN ISO 12100, functional safety documentation, test reports, the technical file, operating instructions and the EU Declaration of Conformity with exports in English, German, French and Italian. The platform is available in English; the AI drafts, you review and sign off.

More English guides

This guide is general information for machinery manufacturers, verified against the official EU legal texts as of 15 September 2026. It is not legal advice. For decisions about your specific product, consult the legal texts (EUR-Lex) or a qualified advisor.