Cyber Resilience Act: all tools and articles

Regulation (EU) 2024/2847, Annex III, and Regulation (EU) 2023/1230

You make industrial or connected equipment. What does the CRA ask of you?

In scope?
Yes. A controller, drive, sensor or machine with digital elements is in scope.
Which class?
Default for the equipment itself. The network and security layer around it is listed.
Due when?
Reporting since 11 September 2026. Machinery from 20 January 2027. The CRA in full from 11 December 2027.

What do you ship?

What is listed around the machine

PointClassAs the Regulation words it
III.I.1Class IIdentity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
III.I.5Class IProducts with digital elements with the function of virtual private network (VPN)
III.I.6Class INetwork management systems
III.I.10Class IPhysical and virtual network interfaces
III.I.11Class IOperating systems
III.I.12Class IRouters, modems intended for the connection to the internet, and switches
III.I.13Class IMicroprocessors with security-related functionalities
III.I.14Class IMicrocontrollers with security-related functionalities
III.II.1Class IIHypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
III.II.2Class IIFirewalls, intrusion detection and prevention systems

Regulation (EU) 2024/2847, Annex III, read from the Official Journal with its corrigenda; reporting duties apply since 11 September 2026.

The machine owes a second regulation

A machine with digital elements is also machinery. Regulation (EU) 2023/1230 applies from 20 January 2027 and asks, in Annex III, that connecting a device does not create a hazardous situation, that software and data critical to safety are protected against corruption, and that intervention in them leaves evidence. It has its own technical file, and the CRA's does not replace it.

See the machinery technical file

Two ways to be ready

CRA readiness, €1,500, 10 working days

We scope your product, list the gaps against Annex I, set up the reporting path and draft the technical file with you.

See what it covers

CRA technical file pack, €2,000

The same file, written by you from our template and product record, with no engagement.

See the pack

Questions people ask

Our controller is sold to machine builders, not to end users. Does the CRA still apply?
Yes. The duties follow placing a product with digital elements on the Union market, not who buys it. A component sold to another manufacturer is placed on the market.
The machine is not on the internet. Are we out?
No. The Regulation covers products with digital elements whose intended use includes a direct or indirect data connection to a device or network, which a plant network or a service laptop is.
Do we need a notified body for the whole machine, or only for the listed part?
Only for the product that is listed. A firewall placed on the market as a product sits in Annex III class II and is assessed as that product; the machine it protects stays default class and you assess it yourself.
What is actually due now, before 11 December 2027?
The reporting duty. Since 11 September 2026 an actively exploited vulnerability or a severe incident has to be notified, first within 24 hours and then within 72.

This page in:DeutschFrançaisNederlandsEspañolDansk