Machine Builders Face New Cybersecurity Demands as EU Cyber Resilience Act Nears
With the increased connectedness of industrial equipment, cybersecurity is now increasingly becoming a requirement for product design. To meet this change, ei³ has published a guidance aimed at...
With the increased connectedness of industrial equipment, cybersecurity is now increasingly becoming a requirement for product design. To meet this change, ei³ has published a guidance aimed at supporting machine builders in preparing for the new obligations of the Cyber Resilience Act (CRA) of the European Union, which aims to establish a new regulatory framework for products containing digital elements.
The regulation is expected to impact manufacturers of connected industrial machinery, automation systems, gateways, embedded software and applications for the cloud. The CRA does more than just put the onus on the factory, however, and also expects original equipment manufacturers (OEMs) to embed cybersecurity into products, all the way up to their end of life.
The key areas raised include vulnerability management, software updates, asset visibility, secure remote access and Software Bills of Materials (SBOMs). The guide also provides practical guidance for manufacturers in anticipation of the implementation of the regulation’s milestones in 2026 and 2027.
Industry context
Cybersecurity issues can appear decades after deployment and existing industrial machines are expected to run for long periods of time. Consequently, it’s becoming more common for manufacturers to offer continuous security support rather than security support as a one-and-done compliance project.
This is spurring broader implementation of lifecycle cybersecurity practices such as continuous monitoring of assets, vulnerability assessment and secure remote maintenance. International standards including IEC 62443 and the NIST Cybersecurity Framework are also increasingly being a key component in helping manufacturers stay current with emerging regulations.
The Cyber Resilience Act builds on global efforts to enhance cybersecurity governance for connected products. Machine builders will likely need to be more involved in the compliance aspect of product development, services, and support. In addition to regulatory compliance, companies with a strong vulnerability management and secure update regimen will be better prepared to cultivate customer confidence and provide support for connected machines securely throughout their life cycle.





