Ihre Anmeldung konnte nicht gespeichert werden. Bitte versuchen Sie es erneut.
Ihre Anmeldung war erfolgreich.
X

Newsletter

Melden Sie sich zu unserem Newsletter an, um auf dem Laufenden zu bleiben.

Wir verwenden Brevo als unsere Marketing-Plattform. Indem du das Formular absendest, erklärst du dich einverstanden, dass die von dir angegebenen persönlichen Informationen an Brevo zur Bearbeitung übertragen werden gemäß den Datenschutzrichtlinien von Brevo.

Cyber Resilience Act (CRA)

Cybersecurity Is Becoming a Manufacturer’s Responsibility

Cyber Resilience Act: Cybersecurity Becomes a Manufacturer’s Responsibility

As of June 2026

The Cyber Resilience Act (CRA) is the first comprehensive EU regulation to directly link cybersecurity requirements to products with digital elements. Compliance will be mandatory starting December 11, 2027—and the penalties are substantial. Those who fail to act now risk fines of up to 15 million euros.

What is the Cyber Resilience Act?

The Cyber Resilience Act (EU) 2024/2847 requires manufacturers to securely develop, test, and deploy products with digital components. This applies to control systems, machines, equipment, PLC systems, and industrial software—in short, to anything with a network connection.

CharacteristicDetails
Effective Date: Manufacturer ObligationsDecember 11, 2027
Reporting DeadlineSeptember 11, 2026
Applies toAll products with digital elements (PDEs)
PenaltiesUp to €15 million or 2.5% of global annual revenue
Reference StandardIEC 62443

Who is covered by the CRA?

The CRA applies to all products with digital elements that are made available on the EU market and have a direct or indirect data connection to a device or network. Specifically, this applies to:

  • Control Systems (PLC) with Network Connectivity
  • Machines and systems with embedded software or remote access
  • Firmware and Embedded Systems
  • Industrial Software (SCADA, MES, HMI Software)
  • Switches, Firewalls, and Routers in Industrial Environments

In short: If your product has or can have a network connection—directly or indirectly—it falls under the CRA.

What, specifically, do manufacturers need to do?

Basic Cybersecurity Requirements (Effective December 2027)

  • Released with no known exploitable vulnerabilities
  • Secure Default Configuration (Security by Default)
  • Protecting the Confidentiality and Integrity of Data
  • Minimizing the attack surface
  • Automatic Security Updates

Vulnerability Management

  • Document vulnerabilities and components (including Software Bill of Materials / SBOM)
  • Address vulnerabilities immediately and provide free security updates
  • Conduct regular security tests

Cybersecurity Product Lifecycle Management System (CPLMS)

Implementing CRA requirements calls for clear responsibilities and well-established processes throughout the entire product lifecycle. In particular, a CPLMS defines:

  • Roles and Responsibilities
  • Governance and Approval Processes
  • Collaboration Between Development, Quality Management, Service, and IT Security
  • Guidelines for Maintaining Technical Documentation
  • The continuous monitoring and improvement of cybersecurity processes

Note: The CRA does not explicitly require a CPLMS. However, it is difficult to implement the required processes in a sustainable manner without an appropriate management system.

Reporting Requirements – Effective as Early as September 11, 2026!

The reporting requirements will take effect more than a year before the other CRA requirements. Manufacturers must report actively exploited vulnerabilities and serious security incidents:

  • 24 hours after becoming aware: first early warning
  • 72 hours: Full report of the incident
  • Day 14: Final Report

Anyone who hasn’t yet established processes for this needs to take action now.

Penalties for Noncompliance

The CRA is no paper tiger. Significant penalties may be imposed:

  • Failure to comply with essential CRA requirements: up to 15 million euros or 2.5% of global annual revenue
  • Providing false information to government agencies: up to 5 million euros or 1% of annual revenue
  • Products That Do Not Comply with CRA: Market Access Will Be Restricted or Prohibited

What You Should Do Now

  • Impact Analysis: Which of your products are subject to the CRA?
  • Gap Analysis: How do your current processes differ from the new requirements?
  • Reporting Requirements: Do you have processes in place for reporting security incidents? (Required as of September 11, 2026)
  • Security Risk Assessment: Do you have an industrial security strategy for your products?
  • Check Standards: Are you already complying with IEC 62443?

We can help you with CRA compliance

ROTH Steuerungstechnik GmbH supports you on your path to compliance:

  • Impact Analysis and Gap Analysis
  • Cybersecurity Risk Assessment (TARA) in accordance with IEC 62443
  • Establishing a Secure Development Lifecycle
  • Preparation of technical documentation and the EU Declaration of Conformity

Please contact us for an initial assessment of whether and how the CRA affects your company.

Note: Manufacturers of machines with digital interfaces are also subject to the new Machinery Regulation (MVO) 2027. Read our article on the MVO to learn how to best combine both sets of requirements.

As of June 2026. All information is based on the Cyber Resilience Act (EU 2024/2847). 

Other Topics in Focus

SHOW ALL

Machining of Transmission and Clutch Housings

Machine Safety

Smart Control Cabinet Solutions – Designed “Out of the Box”

Contact us!

Roth Index

Are you looking for a specific area of expertise?