Independent information resource Product security · EU CRA
CRA and overlapping EU regulation / 03

Cyber Resilience Act and the EU Machinery Regulation

How the Cyber Resilience Act interacts with Regulation (EU) 2023/1230 on machinery, including protection against corruption, malicious external influence, safety-related software, control systems, risk assessment, conformity assessment and shared cybersecurity evidence.

IN BRIEF

The Machinery Regulation is not a general CRA exclusion. For connected machinery, map CRA cybersecurity risks and Machinery Regulation safety risks together, then distinguish where a cyber event can create a hazardous situation. Machinery Regulation Annex III sections 1.1.9 and 1.2.1 are especially important because they address corruption, safety-related software and malicious third-party influence. Regulation (EU) 2023/1230 generally applies from 14 January 2027, before the CRA's main product requirements apply from 11 December 2027.

01 / 11

Connected Machinery Can Fall Under Both Regulations

The CRA does not contain a general exclusion for machinery covered by Regulation (EU) 2023/1230. If machinery is also a product with digital elements within CRA scope, the manufacturer should assess both legal frameworks. The Machinery Regulation asks whether machinery is safe, while the CRA establishes dedicated cybersecurity and vulnerability-handling requirements for the digital product.

02 / 11

The Machinery Regulation Generally Applies From 14 January 2027

Regulation (EU) 2023/1230 generally applies from 14 January 2027, with specified provisions applying earlier. That means machinery manufacturers can face the new machinery framework before the CRA's main product obligations apply from 11 December 2027. The implementation programmes should therefore be coordinated rather than sequenced as unrelated projects.

03 / 11

Annex III Section 1.1.9 Requires Protection Against Corruption

Machinery Regulation Annex III section 1.1.9 requires machinery and related products to be designed so that connection of another device, including a remote communicating device, does not lead to a hazardous situation. Hardware components, software and data that are critical to compliance with essential health and safety requirements must be adequately protected against accidental or intentional corruption.

04 / 11

Safety-Related Software Must Be Identifiable and Protected

The Machinery Regulation requires software and data critical to health and safety compliance to be identified and adequately protected. It also requires machinery to identify installed software necessary for safe operation and to collect evidence of legitimate or illegitimate intervention in installed software or its configuration. Those records can overlap with CRA architecture, logging, integrity and change-control evidence.

05 / 11

Control Systems Must Withstand Reasonably Foreseeable Malicious Attempts

Annex III section 1.2.1 requires control systems to prevent hazardous situations and, where appropriate to circumstances and risks, to withstand intended and unintended external influences, including reasonably foreseeable malicious attempts from third parties that could lead to a hazardous situation. This creates a direct bridge between cybersecurity threat analysis and machinery safety engineering.

06 / 11

CRA Annex I Covers a Broader Cybersecurity Lifecycle

The CRA is not limited to cybersecurity events that create a physical safety hazard. Its Annex I requirements address product cybersecurity properties and vulnerability handling more broadly, including risk-appropriate confidentiality, integrity, availability, secure defaults, attack-surface reduction, security updates and vulnerability remediation. A machinery manufacturer therefore cannot reduce the CRA analysis only to safety-related cyber scenarios.

07 / 11

Coordinate the Two Risk Assessments

The machinery risk assessment and CRA cybersecurity risk assessment should exchange information. A threat model can identify malicious actions against control logic, sensors, interfaces or remote access, while the machinery analysis determines whether those actions can create hazardous situations. Keep each legally required assessment identifiable while linking shared scenarios and controls.

08 / 11

Reuse Architecture and Test Evidence Where It Supports Both Laws

Network diagrams, software inventories, authentication design, integrity controls, penetration tests, secure-update evidence and intervention logs can support both frameworks. Reuse reduces duplicated testing, but each evidence item should identify which CRA requirement and which Machinery Regulation essential health and safety requirement it supports.

09 / 11

Cybersecurity Certification Can Have Machinery-Law Significance

The Machinery Regulation provides a presumption mechanism for specified cybersecurity certification schemes under Regulation (EU) 2019/881 where references are published in the Official Journal. The presumption is limited to Annex III sections 1.1.9 and 1.2.1 insofar as the certificate covers those requirements. It does not automatically establish compliance with the complete Machinery Regulation or CRA.

10 / 11

Coordinate Conformity Assessment Without Merging It

A machine can require conformity work under several Union acts. Build one controlled evidence architecture, but identify the applicable conformity modules, standards, notified bodies and legal declarations for each act. A single CE mark can reflect compliance with multiple applicable Union harmonisation laws, but the underlying assessments remain law-specific.

11 / 11

Review Cybersecurity Changes for Safety Consequences

Security updates, remote-service changes, access-control changes and software modifications can alter both cybersecurity risk and machinery safety behaviour. Change management should therefore ask whether a cyber change affects an essential health and safety requirement, safety-related control logic or the CRA conformity evidence and risk assessment.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.