
The Cyber Resilience Act turns cybersecurity into a selling point
The EU’s Cyber Resilience Act (CRA) reaches further than most machine builders expect, and getting ahead of it isn’t just about avoiding trouble. Manufacturers who build compliant secure products now will be the ones customers trust first.
If your machine has a data connection to a device or network, the CRA applies to it, regardless of your company domain of business, software or not. A PLC, an HMI, or a networked sensor almost always carries that connection even it is internal part of a product. CRA reporting obligations already took effect on 11 September 2026, and full enforcement follows from December 2027, which is the deadline that still gives most manufacturers room to prepare properly.
The two principles it comes down to
Security by design: cybersecurity must be built into the product from the start, with a threat assessment and risk analysis as a standard part of the design process.
Security by default: the product should reach the customer already configured with the safest settings, not left for the end user to figure out.
Your responsibility doesn't end at delivery
Manufacturers now need to maintain a product's cybersecurity for full support period: at least five years, and for most industrial equipment, considerably longer than that. The CRA ties the period to how long the product is realistically expected to stay in use. This means monitoring for vulnerabilities, and shipping updates throughout that period. Along comes fast reporting: an actively exploited vulnerability goes to your national CSIRT and ENISA within 24 hours as an early warning, a fuller notification within 72 hours, and a final report within 14 days. All this means documentation: a risk assessment, traceability documents, a Software Bill of Materials (SBOM) listing every software component used, and compliance as a precondition for CE marking.
What this means in practice
Not every product faces the same rules. Most fall under the default category and can be self-assessed by the manufacturer. Few critical types need a third-party assessment or full certification against an EU scheme. Machines already on the market generally don't need retroactive compliance unless they get a substantial upgrade; bug fixes don't count. Spare parts that keep the product's function unchanged are exempt. During commissioning and maintenance, secure remote access and clear log retention practices matter most.
Five steps to get ahead of CRA
Map your digital footprint
Map your products for anything with a digital element.
Check your supply chain
Ask your suppliers for an SBOM and statement about CRA readiness, so you know what's inside what you buy.
Build security into design
Build threat assessment and risk analysis into the design process, not as an afterthought.
Plan for updates
Set up an update process for vulnerabilities found after delivery.
Train your people
Train your team: design, project management and sales all need to know what's changed.
How Etteplan and Bosch Rexroth help
Bosch Rexroth maintains the ctrlX platform, built Secure by Design to meet CRA requirements. Etteplan handles the integration side: CRA compliance analysis, security guidance, and support toward CE marking, so you can stay focused on your core business while the compliance work gets done properly.

Ask our expert a question
Architect, Software