Cybersecurity for Machinery: How the Machinery Regulation, RED and CRA Fit Together
A machine with remote service, a wireless handheld and a cloud link has to satisfy up to three different EU cybersecurity regimes by the end of 2027, depending on when it is placed on the market. Each asks its own question: can people get hurt, are the network and data protected, and does the product stay resilient for as long as it is used? This guide sorts out the requirements, lays out the timeline and explains why the cybersecurity risk assessment needs a method of its own next to EN ISO 12100.
Three laws, three protection goals
| Topic | Machinery Regulation | Radio Equipment Directive | Cyber Resilience Act |
|---|---|---|---|
| What it protects | Health and safety of people: corruption and malicious interference must not lead to hazardous situations (Annex III sections 1.1.9 and 1.2.1). | The network (point (d)), personal data and privacy (point (e)) and protection from fraud (point (f)) under Article 3(3) of Directive 2014/53/EU. | Cybersecurity of the product over its life cycle: product properties under Annex I Part I, vulnerability handling under Part II, reporting under Article 14. |
| Who is covered | Machinery and related products. | Radio equipment; whether a machine with a permanently integrated radio module counts as such as a whole is not fully settled. Point (d) for equipment that can communicate over the internet. | Products with digital elements with a data connection to a device or network. |
| Applies | from 20 January 2027 | to equipment placed on the market from 1 August 2025 to 10 December 2027 | Article 14 since 11 September 2026, everything else from 11 December 2027 |
| Method | Risk assessment under Annex III, in practice EN ISO 12100: threats treated as hazards with severity and probability. | Mechanisms of EN 18031-1, -2 or -3:2024: applicability and appropriateness per mechanism with documented justification. | Cybersecurity risk assessment under Article 13(2) to (4) with a statement on each requirement of Annex I Part I point 2. |
| Presumption of conformity | No harmonised standard under the Regulation cited in the Official Journal yet (sources as of 11 September 2026). Presumption via harmonised standards referenced in the Official Journal (Article 20(1)), common specifications adopted by the Commission (Article 20(6)) and, for sections 1.1.9 and 1.2.1, also via a Regulation (EU) 2019/881 scheme referenced in the Official Journal (Article 20(9)). | EN 18031 is cited, but only without the options excluded by Implementing Decision (EU) 2025/138. | No harmonised standard cited yet (sources as of 11 September 2026). |
Timeline for a machine with a radio module
Which design and conformity requirements apply depends on the date the machine is placed on the EU market:
| Placed on the market | Machinery law | Radio cybersecurityfor the radio equipment; whether the machine as a whole counts as radio equipment is not fully settled | Cyber Resilience Act |
|---|---|---|---|
| until 31 Jul 2025 | Machinery Directive 2006/42/EC | RED points (d), (e), (f) not applicable | design obligations not applicable |
| 1 Aug 2025 to 19 Jan 2027 | Machinery Directive 2006/42/EC | points (d), (e), (f) via Delegated Regulation (EU) 2022/30 where its criteria are met | design obligations not applicable |
| 20 Jan 2027 to 10 Dec 2027 | Machinery Regulation (EU) 2023/1230 including sections 1.1.9 and 1.2.1 | points (d), (e), (f) still apply via Delegated Regulation (EU) 2022/30 | design obligations not applicable |
| from 11 Dec 2027 | Machinery Regulation (EU) 2023/1230 | Delegated Regulation (EU) 2022/30 repealed; points (d), (e), (f) no longer apply to newly placed equipment | fully applicable: Annex I, Article 13, conformity assessment under Article 32 |
Regardless of the date: since 11 September 2026, the CRA reporting obligations in Article 14 apply to all products with digital elements, including machines delivered long before (Article 69(3) CRA). See The Cyber Resilience Act for machinery.
Since January 2026, industry associations have been asking for section 1.1.9 and section 1.2.1(f) of the Machinery Regulation to be aligned with the CRA timeline, i.e. postponed to 11 December 2027. No legal act to that effect was known as of 15 September 2026; plan for 20 January 2027.
Machinery Regulation: protection against corruption
Section 1.1.9 of Annex III is new to machinery law. In substance it asks for five things. Connecting another device, or remote access, must not lead to a hazardous situation. Hardware that carries signals or data relevant for access to safety-critical software must be protected against accidental or intentional corruption, and the machine must collect evidence of interventions in it. Safety-critical software and data must be identified and protected. The installed software needed for safe operation must be identifiable on the machine at any time. And the machine must collect evidence of legitimate or illegitimate interventions in the software or its configuration.
Section 1.2.1 adds that control systems must, where appropriate to the circumstances and risks, withstand, among other things, reasonably foreseeable malicious attempts from third parties leading to a hazardous situation (point (a)), that the limits of safety functions follow from the risk assessment and hazardous changes to settings are prevented (point (d)), and that the tracing log of interventions and of uploaded safety software versions is enabled for five years after upload, for reasoned requests from competent authorities (point (f)).
The protection goal is still the safety of people, so these requirements belong in the risk assessment: threats such as a manipulated safety parameter or an unexpected remote start are assessed as hazards with severity and probability and reduced through the usual hierarchy of measures. The supporting standard, prEN 50742, is only a draft (industry reports of 31 July and 25 August 2026) and describes two routes: approach A with the standard's own process and product requirements, based on a manufacturer-specific threat analysis in line with EN ISO 12100, and approach B via the IEC 62443 series. A presumption of conformity under Article 20(1) will only come with a citation in the Official Journal; common specifications adopted by the Commission would also give one under Article 20(6). Separately, Article 20(9) of the Machinery Regulation grants a presumption for sections 1.1.9 and 1.2.1 to certification or a statement of conformity under a Cybersecurity Act (EU) 2019/881 scheme referenced in the Official Journal.
Radio Equipment Directive: EN 18031 until 10 December 2027
When the machine becomes radio equipment
Whether a machine with a permanently integrated radio module counts as radio equipment as a whole is not fully settled. The Commission's 2018 supplementary guidance treats a non-radio electrical product with incorporated, permanently affixed radio equipment as a single product under the RED; FEM and CAPIEL interpret the RED the same way in their guidance for the products of their sectors. The guide to the Machinery Directive is narrower. Under this reading, a plug-in or easily removable module remains a separate product. According to the associations, you build on the module manufacturer's evidence but assess the combination. If the machine counts as radio equipment, recital 8 of Delegated Regulation (EU) 2022/30 says all aspects and parts of the equipment should comply, not only the radio function.
Which points apply
- Point (d), network protection: all radio equipment that can itself communicate over the internet, directly or via other equipment (Article 1(1) of Delegated Regulation 2022/30). Typical for machines with remote service over cellular or Wi-Fi.
- Point (e), personal data and privacy: among others, internet-connected radio equipment that can process personal, traffic or location data (Article 1(2)), such as operator log-ins or location data of mobile machinery.
- Point (f), fraud protection: internet-connected radio equipment that allows the transfer of money, monetary value or virtual currency (Article 1(3)); rare on machinery.
EN 18031 and its restrictions
EN 18031-1, -2 and -3:2024 were cited by Implementing Decision (EU) 2025/138 of 28 January 2025, with restrictions. The sections titled "rationale" and "guidance" give no presumption. If users may choose not to set or use a password under clauses 6.2.5.1 and 6.2.5.2, the presumption is lost in all three parts. In part 2 it is also lost for certain child and toy categories where parental access control is not ensured through the designated clauses, and in part 3 the assessment criteria of clause 6.3.2.4 on secure updates give no presumption.
Consequence for the procedure: without the presumption, Article 17(4) of Directive 2014/53/EU leaves only EU-type examination (Annex III) or full quality assurance (Annex IV) for the cybersecurity requirements, both with a notified body. This applies to the restrictions on passwords, parental access control and clause 6.3.2.4; the restriction on the "rationale" and "guidance" sections alone does not require a notified body. The Commission's EN 18031 guidance states that part 3 with clause 6.3.2.4 always requires third-party assessment. Internal production control remains available for safety and EMC (Article 3(1)) either way.
The standards work with mechanisms. For each interface and each asset that needs protection, you decide whether a mechanism applies and whether its implementation is appropriate, with a documented justification:
- ACMaccess control to assets that need protection
- AUMauthentication, including password rules and brute-force protection
- SUMsecure updates
- SSMsecure storage
- SCMsecure communication
- RLMresilience against overload (part 1 only)
- NMM, TCMnetwork monitoring and traffic control (network equipment, part 1)
- LGMlogging (parts 2 and 3)
- DLM, UNMdeletion of data and user notification (part 2)
- CCK, CRYcryptographic keys and state-of-the-art cryptography
- GECgeneral equipment capabilities, such as no known exploitable vulnerabilities and no unnecessary interfaces
Codes from EN 18031, descriptions in our own words. Relevant for machinery: the standard allows an exception from updatability where functional safety does not permit it, and exceptions for access-restricted environments, which must be justified. Radio signals often reach beyond the factory wall.
The expiry date
Delegated Regulation (EU) 2026/339 of 16 February 2026 repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027. Recitals 3 and 4 explain why: the CRA's essential requirements cover all elements of points (d), (e) and (f), and radio equipment should not be subject to both regimes at once. Market surveillance of radio equipment placed on the market from 1 August 2025 to 10 December 2027 remains possible under the old requirements (recital 5), so your EN 18031 files stay relevant for those units. EN 18031 has no reference under the CRA (sources as of 11 September 2026), but it is solid groundwork: recital 30 CRA says the standardisation work carried out under Implementing Decision C(2022) 5637 should be taken into account when harmonised standards for the CRA are developed.
Cyber Resilience Act: the product over its time in use
The CRA applies to the machine as a product with digital elements as soon as it has a data connection to a device or network. Its focus is the cybersecurity of the product itself, while keeping the impact of incidents on users' health and safety as low as possible (Article 13(2)): secure default configuration, protection against unauthorised access, data integrity and confidentiality, a small attack surface, security updates throughout a defined support period, a software bill of materials and vulnerability handling. Reporting already applies; everything else follows on 11 December 2027. Scope, classification, procedures and reporting are explained in The Cyber Resilience Act for machinery.
Why cybersecurity risk assessment needs its own method
An EN ISO 12100 risk assessment looks for hazards, meaning potential sources of injury or damage to health, and rates risk as a combination of the severity and probability of that harm (Annex III Part A of the Machinery Regulation). A cybersecurity risk under Article 3(37) CRA is something else: the potential for loss or disruption caused by an incident, expressed by its magnitude and likelihood. The CRA does take effects on users' health and safety into account (Article 13(2)), but its starting point is the incident. Leaked recipe data, a crippled plant network or tampered production counts injure nobody, so they never show up in a safety risk assessment.
The required form differs too. The CRA wants a statement on every requirement in Annex I Part I point 2: whether and how it applies and how it is implemented, with a clear justification where it does not apply (Article 13(3) and (4)). EN 18031 wants a decision per mechanism. And Article 13(4) CRA, as amended by Regulation (EU) 2025/327, explicitly provides for embedding the CRA assessment in another act's risk assessment only for high-risk AI systems and electronic health record systems. This mirrors a general principle of EU product law: the required risk analysis follows the protection goals of the act in question.
According to the Commission's CRA guidance, internal risk appetite and cost are not the benchmark, risks may not be shifted onto users, and restricting use to trusted environments is acceptable (content approved on 27 July 2026; no formal adoption found as of 15 September 2026).
Example: remote service access via a cellular router
| Legal act | Key question | Outcome |
|---|---|---|
| Machinery Regulation, Annex III sections 1.1.9 and 1.2.1 | Can remote access create a hazardous situation, such as a start-up during maintenance or a changed safety parameter? | A hazard in the risk assessment with a risk rating; measures in the three-step hierarchy, e.g. remote access only after local approval, safety parameters not changeable remotely, evidence of interventions. |
| RED, Delegated Regulation (EU) 2022/30 point (d) | Is the router internet-connected radio equipment, and does the combination protect the network? | EN 18031-1: authentication without a 'no password' option, secure communication, secure updates, no unnecessary services, each with a justification. |
| Cyber Resilience Act | Is the product resilient against attacks and maintained throughout its time in use? | A statement on Annex I Part I point 2, e.g. (d) unauthorised access and (j) attack surface; a support period that covers the router firmware, an SBOM, vulnerability handling and a reporting process. |
The same interface appears in three assessments with three key questions. That is not duplicate work as long as all three build on one shared inventory.
The starting point: an interface and asset inventory
All three laws assume you know how your machine can be attacked and what needs protecting. Section 1.1.9 of the Machinery Regulation explicitly requires safety-critical software and data to be identified; EN 18031 distinguishes security, network, privacy and financial assets; and Annex VII point 2(a) CRA mentions, where applicable, drawings, schemes or a description of the system architecture for the technical documentation.
Per interface
- Type: Ethernet, fieldbus, USB, Wi-Fi, Bluetooth, cellular, HMI, service port, cloud
- Protocol and connection: local, plant network or internet
- Authentication and access rights
- Update path
- Reachability, for radio also outside the building
Per asset
- Safety functions, safety parameters and safety software
- Programs, recipes and configuration
- Credentials and cryptographic keys
- Personal data such as operator log-ins or location data
- Impact of manipulation, disclosure and loss
Purchased PLCs, HMIs and routers belong in the inventory together with their security information and support periods. Where such components are intended for integration into other products and placed on the market from 11 December 2027, Annex II point 8(f) CRA requires their manufacturers to tell integrators how to meet the requirements.
A roadmap for machinery manufacturers
Build the inventory: Interfaces, assets and purchased components per machine type.
Pin down the legal situation per product line: Record the date of placing on the market; radio cybersecurity, Machinery Regulation and CRA obligations follow from it.
Set up CRA reporting under Article 14: Already required for machines in the field: responsibilities, contact address, list of countries, access to the reporting platform.
Add corruption to the risk assessment: Threats that can lead to hazardous situations, with a risk rating and measures, well before 20 January 2027.
Demonstrate radio cybersecurity: Determine the applicable EN 18031 parts, justify each mechanism and avoid the excluded options, or plan for a notified body.
Prepare the CRA file by 11 December 2027: Risk assessment with requirements matrix, support period, SBOM, disclosure policy and Annex II user information.
Issue one declaration: A single EU declaration of conformity listing all applicable acts with their Official Journal references.
How CE-Copilot covers this
In CE-Copilot the three strands are separate assessments in the same project, built on a shared interface and asset inventory: the CRA project page works with it in full, the corruption analysis takes recorded interfaces as a starting point, and the radio module maps the recorded assets to the EN 18031 mechanisms.
- Protection against corruption (Starter and above): threat analysis for sections 1.1.9 and 1.2.1 following approach A of draft prEN 50742 (manufacturer-specific threat analysis in line with EN ISO 12100), with threat scenarios as hazards with risk ratings and three-step measures, the related IEC 62443-3-3 requirements as reference and a requirements checklist in the test reports (Professional and above).
- Radio equipment (Starter and above): a checklist of EN 18031 mechanisms per applicable part, the restrictions of Implementing Decision (EU) 2025/138 with their consequence for the procedure, and the applicable rules based on the date of placing on the market.
- Cyber Resilience Act: classification and obligations in force in the risk assessment editor (Starter and above), plus the cybersecurity project page with risk assessment, requirements matrix, vulnerability handling, reporting and the CRA report (Professional and above).
- Clean separation in the documents: in the PDF and Word risk assessment, the radio and CRA assessments appear as separately titled sections next to the EN ISO 12100 hazards. Corruption scenarios deliberately stay hazards of the risk assessment, because section 1.1.9 belongs to the Machinery Regulation. With CRA data, the complete dossier gets its own cybersecurity chapter.
See an example in the sample dossier and compare plans on the pricing page. Assessment, technical implementation and approval stay with the manufacturer.
FAQ
Frequently asked questions
Which EU laws govern the cybersecurity of machinery?
Does a built-in Wi-Fi or cellular module make my machine radio equipment?
Is a CE-marked radio module from my supplier enough?
What happens to EN 18031 after 11 December 2027?
If my machine complies with the CRA, does it automatically meet section 1.1.9 of the Machinery Regulation?
Is there a harmonised standard for protection against corruption?
Why is an EN ISO 12100 risk assessment not enough for cybersecurity?
Can users run the machine without a password?
Sources
- Regulation (EU) 2023/1230 on machinery: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R1230
- Directive 2014/53/EU on radio equipment: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32014L0053
- Commission Delegated Regulation (EU) 2022/30: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R0030
- Commission Implementing Decision (EU) 2025/138 (EN 18031-1, -2, -3:2024 with restrictions): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32025D0138
- Commission Delegated Regulation (EU) 2026/339 repealing Delegated Regulation (EU) 2022/30: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026R0339
- Regulation (EU) 2024/2847 (Cyber Resilience Act): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2847
- European Commission: guidance on CRA implementation, C(2026) 5252 of 27 July 2026 (content approved): https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation
- European Commission, DG GROW: Guidance on the application of the harmonised standards series EN 18031:2024 (undated): https://circabc.europa.eu/rest/download/70c9aa5b-73a0-4821-8b96-96a7dc46eab1
Only codes and our own short descriptions are taken from the EN 18031 standards.
Run EU machinery compliance in-house, in English
This guide is written by the team behind CE-Copilot, a software platform covering the whole EU CE process for machinery: directive classification, a standards finder across 3,600+ standards with harmonisation status, risk assessment per EN ISO 12100, functional safety documentation, test reports, the technical file, operating instructions and the EU Declaration of Conformity with exports in English, German, French and Italian. The platform is available in English; the AI drafts, you review and sign off.
More English guides
This guide is general information for machinery manufacturers, verified against the official EU legal texts as of 15 September 2026. It is not legal advice. For decisions about your specific product, consult the legal texts (EUR-Lex) or a qualified advisor.