Cyber Resilience Act: all tools and articles
Regulation (EU) 2024/2847, Annex III, and Regulation (EU) 2023/1230
You make industrial or connected equipment. What does the CRA ask of you?
- In scope?
- Yes. A controller, drive, sensor or machine with digital elements is in scope.
- Which class?
- Default for the equipment itself. The network and security layer around it is listed.
- Due when?
- Reporting since 11 September 2026. Machinery from 20 January 2027. The CRA in full from 11 December 2027.
What do you ship?
What is listed around the machine
| Point | Class | As the Regulation words it |
|---|---|---|
| III.I.1 | Class I | Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers |
| III.I.5 | Class I | Products with digital elements with the function of virtual private network (VPN) |
| III.I.6 | Class I | Network management systems |
| III.I.10 | Class I | Physical and virtual network interfaces |
| III.I.11 | Class I | Operating systems |
| III.I.12 | Class I | Routers, modems intended for the connection to the internet, and switches |
| III.I.13 | Class I | Microprocessors with security-related functionalities |
| III.I.14 | Class I | Microcontrollers with security-related functionalities |
| III.II.1 | Class II | Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments |
| III.II.2 | Class II | Firewalls, intrusion detection and prevention systems |
Regulation (EU) 2024/2847, Annex III, read from the Official Journal with its corrigenda; reporting duties apply since 11 September 2026.
The machine owes a second regulation
A machine with digital elements is also machinery. Regulation (EU) 2023/1230 applies from 20 January 2027 and asks, in Annex III, that connecting a device does not create a hazardous situation, that software and data critical to safety are protected against corruption, and that intervention in them leaves evidence. It has its own technical file, and the CRA's does not replace it.
See the machinery technical fileTwo ways to be ready
CRA readiness, €1,500, 10 working days
We scope your product, list the gaps against Annex I, set up the reporting path and draft the technical file with you.
See what it coversCRA technical file pack, €2,000
The same file, written by you from our template and product record, with no engagement.
See the packQuestions people ask
- Our controller is sold to machine builders, not to end users. Does the CRA still apply?
- Yes. The duties follow placing a product with digital elements on the Union market, not who buys it. A component sold to another manufacturer is placed on the market.
- The machine is not on the internet. Are we out?
- No. The Regulation covers products with digital elements whose intended use includes a direct or indirect data connection to a device or network, which a plant network or a service laptop is.
- Do we need a notified body for the whole machine, or only for the listed part?
- Only for the product that is listed. A firewall placed on the market as a product sits in Annex III class II and is assessed as that product; the machine it protects stays default class and you assess it yourself.
- What is actually due now, before 11 December 2027?
- The reporting duty. Since 11 September 2026 an actively exploited vulnerability or a severe incident has to be notified, first within 24 hours and then within 72.