← All guides

CRA for machine builders: how it stacks on CE marking and the Machinery Regulation

Machine builders already know CE marking. The Cyber Resilience Act adds a cybersecurity layer on top: when your machine is in scope, how the CRA interacts with the Machinery Regulation, and what changes in your technical file.

Nordchecks TeamPublished 8 min

Not sure if you’re in scope?

Run the free 3-minute scope check for your product and get your risk class, deadlines and obligations.

Check if the CRA applies to you

If you build machines, CE marking is nothing new: you've been compiling technical files, running risk assessments and signing Declarations of Conformity for years under the Machinery Directive — now the Machinery Regulation. The Cyber Resilience Act doesn't replace any of that. It adds a parallel track: from now on, the software and connectivity in your machine need their own cybersecurity conformity, with their own technical documentation requirements and their own deadlines.

This guide explains when a machine falls under the CRA, how the two regulations stack, and what practically changes in your compliance work.

Want a quick answer for your specific machine? Run the free 3-minute scope check.

When does the CRA apply to a machine?

The CRA covers "products with digital elements" — and a modern machine almost always qualifies. In scope, among others:

  • Machines with a PLC, HMI or embedded controller running software
  • Machines with network connectivity: Ethernet, WiFi, Bluetooth, fieldbus with remote access, cellular modems
  • Machines with remote monitoring, telemetry or cloud dashboards — the CRA explicitly includes the remote data processing a product depends on
  • Retrofit kits and components with digital elements that you place on the market separately

Practically out of scope: purely mechanical or electromechanical machines with no software and no connectivity — a genuinely dumb machine. But a relay-and-contactor machine with a small touchscreen controller is already in.

The classification question matters too: most machines land in the default class (self-assessment). Industrial network equipment and security functions push toward Class I/II — if your machine ships with an industrial firewall or acts as network infrastructure, verify your class carefully.

How the two regulations stack

Think of it as two parallel conformity tracks that both end at the same CE marking:

Machinery Regulation track (what you already do): mechanical safety, risk assessment per ISO 12100, safety functions, the machinery technical file, DoC referencing the Machinery Regulation.

CRA track (the new one): cybersecurity risk assessment, secure-by-design measures, SBOM for the software in the machine, vulnerability handling process with security updates for the support period, cybersecurity technical documentation, and — from 11 September 2026 — the 24-hour reporting obligation for actively exploited vulnerabilities.

Both tracks feed one CE marking and one (or combined) Declaration of Conformity listing all applicable regulations. You don't get a separate cyber-CE mark; you extend your existing conformity to cover the CRA.

Worth knowing: the new Machinery Regulation (2023/1230, applying from January 2027) itself adds "protection against corruption" requirements for safety-related control systems — so cybersecurity enters your machinery track too. The CRA work you do largely covers you there; doing it once, properly, serves both.

What changes in your technical file

Concretely, your documentation gains a cybersecurity chapter:

  1. An SBOM — the software bill of materials for everything digital in the machine: PLC runtime and function blocks from vendors, HMI software, the OS on the panel PC, network stacks, remote-access agents, any libraries in your own control software. For machine builders this is mostly a structured inventory exercise — our SBOM guide covers how to do it without a software pipeline.
  2. A cybersecurity risk assessment — same discipline as your ISO 12100 assessment, different threat model: unauthorized access to the controller, manipulation of safety functions over the network, compromised remote access, malicious firmware updates.
  3. A vulnerability handling process — how you receive reports (a security contact), how you assess whether a published CVE in a vendor component affects your machine, how you deliver security updates to machines in the field, for at least five years.
  4. Reporting readiness — from 11 September 2026, an actively exploited vulnerability in your machine's software must be reported to ENISA within 24 hours. This applies to machines already delivered. You need to know what's inside them (the SBOM) and who files the notification before it happens.

The vendor-component question

Machine builders assemble: the PLC comes from one vendor, the HMI from another, the remote-access box from a third. Two practical rules:

  • You are the manufacturer of the machine — the integrated product is yours, and so is its CRA conformity. You can't point at your PLC vendor.
  • But you can lean on their compliance. Component vendors are themselves in scope for what they place on the market; ask them for their SBOMs and security documentation (they'll increasingly have it — their other customers are asking too). Your SBOM references their components; their vulnerability advisories feed your monitoring.

Start asking your vendors for this now — the ones who can't answer are telling you something about your supply-chain risk.

Timeline for a machine builder

  • Now: determine scope and class per machine family; inventory the digital components; set up the SBOM and monitoring; write the reporting playbook.
  • 11 September 2026: reporting obligation live — including for machines already in the field.
  • January 2027: new Machinery Regulation applies, with its own corruption-protection requirements.
  • 11 December 2027: machines placed on the market from this date need full CRA conformity in the CE marking. A substantially modified machine counts as newly placed — a major software/connectivity retrofit can trigger it.

The work compounds nicely: one SBOM, one risk assessment and one vulnerability process serve every unit of a machine family. For most builders this is weeks of structured work, not months — our compliance checklist sequences it step by step.

First step: check your machine's scope and class free — three minutes, no signup, based on the regulation text.

Does the CRA apply to your product?

Find out in three minutes — your risk class, the deadlines that apply, and exactly what you’ll need to comply.

Start the free check