Cyber Resilience Act: Cybersecurity Becomes a Manufacturer’s Responsibility
As of June 2026
The Cyber Resilience Act (CRA) is the first comprehensive EU regulation to directly link cybersecurity requirements to products with digital elements. Compliance will be mandatory starting December 11, 2027—and the penalties are substantial. Those who fail to act now risk fines of up to 15 million euros.
What is the Cyber Resilience Act?
The Cyber Resilience Act (EU) 2024/2847 requires manufacturers to securely develop, test, and deploy products with digital components. This applies to control systems, machines, equipment, PLC systems, and industrial software—in short, to anything with a network connection.
| Characteristic | Details |
| Effective Date: Manufacturer Obligations | December 11, 2027 |
| Reporting Deadline | September 11, 2026 |
| Applies to | All products with digital elements (PDEs) |
| Penalties | Up to €15 million or 2.5% of global annual revenue |
| Reference Standard | IEC 62443 |
Who is covered by the CRA?
The CRA applies to all products with digital elements that are made available on the EU market and have a direct or indirect data connection to a device or network. Specifically, this applies to:
- Control Systems (PLC) with Network Connectivity
- Machines and systems with embedded software or remote access
- Firmware and Embedded Systems
- Industrial Software (SCADA, MES, HMI Software)
- Switches, Firewalls, and Routers in Industrial Environments
In short: If your product has or can have a network connection—directly or indirectly—it falls under the CRA.
What, specifically, do manufacturers need to do?
Basic Cybersecurity Requirements (Effective December 2027)
- Released with no known exploitable vulnerabilities
- Secure Default Configuration (Security by Default)
- Protecting the Confidentiality and Integrity of Data
- Minimizing the attack surface
- Automatic Security Updates
Vulnerability Management
- Document vulnerabilities and components (including Software Bill of Materials / SBOM)
- Address vulnerabilities immediately and provide free security updates
- Conduct regular security tests
Cybersecurity Product Lifecycle Management System (CPLMS)
Implementing CRA requirements calls for clear responsibilities and well-established processes throughout the entire product lifecycle. In particular, a CPLMS defines:
- Roles and Responsibilities
- Governance and Approval Processes
- Collaboration Between Development, Quality Management, Service, and IT Security
- Guidelines for Maintaining Technical Documentation
- The continuous monitoring and improvement of cybersecurity processes
Note: The CRA does not explicitly require a CPLMS. However, it is difficult to implement the required processes in a sustainable manner without an appropriate management system.
Reporting Requirements – Effective as Early as September 11, 2026!
The reporting requirements will take effect more than a year before the other CRA requirements. Manufacturers must report actively exploited vulnerabilities and serious security incidents:
- 24 hours after becoming aware: first early warning
- 72 hours: Full report of the incident
- Day 14: Final Report
Anyone who hasn’t yet established processes for this needs to take action now.
Penalties for Noncompliance
The CRA is no paper tiger. Significant penalties may be imposed:
- Failure to comply with essential CRA requirements: up to 15 million euros or 2.5% of global annual revenue
- Providing false information to government agencies: up to 5 million euros or 1% of annual revenue
- Products That Do Not Comply with CRA: Market Access Will Be Restricted or Prohibited
What You Should Do Now
- Impact Analysis: Which of your products are subject to the CRA?
- Gap Analysis: How do your current processes differ from the new requirements?
- Reporting Requirements: Do you have processes in place for reporting security incidents? (Required as of September 11, 2026)
- Security Risk Assessment: Do you have an industrial security strategy for your products?
- Check Standards: Are you already complying with IEC 62443?
We can help you with CRA compliance
ROTH Steuerungstechnik GmbH supports you on your path to compliance:
- Impact Analysis and Gap Analysis
- Cybersecurity Risk Assessment (TARA) in accordance with IEC 62443
- Establishing a Secure Development Lifecycle
- Preparation of technical documentation and the EU Declaration of Conformity
Please contact us for an initial assessment of whether and how the CRA affects your company.
Note: Manufacturers of machines with digital interfaces are also subject to the new Machinery Regulation (MVO) 2027. Read our article on the MVO to learn how to best combine both sets of requirements.
As of June 2026. All information is based on the Cyber Resilience Act (EU 2024/2847).