CRA and EU Machinery Regulation 2027: Rules change. Reliability remains.

SIKO is prepared for the requirements of the Cyber Resilience Act (CRA) and the EU Machinery Regulation (CSR). Affected products and processes will be aligned with the new requirements to ensure that the relevant requirements are met at the respective start of application. For your planning, we will provide you with clear information, comprehensible evidence and competent advice.

New requirements. Clear security.

The Cyber Resilience Act places new cybersecurity requirements on products with digital elements. At the same time, the EU Machinery Regulation takes into account the increasing digitalization of modern machines and new safety-related risks posed by software and networked systems.

Manufacturers must systematically assess relevant risks, integrate safety requirements into their development processes, produce necessary evidence and meet the respective information and support obligations.

SIKO prepared for these changes at an early stage and aligns affected products and processes with the new specifications. In this way, we create the prerequisites for you to be able to plan safely in the future.

The EU Machinery Regulation (EU) 2023/1230 applies in principle from January 20, 2027. The Cyber Resilience Act (EU) 2024/2847 will apply starting December 11, 2027. Provisions on conformity assessment bodies have been in force since June 11, 2026, and the reporting requirements for manufacturers under Article 14 from September 11, 2026.

What the new requirements mean for you

Cyber Resilience Act ((EU) 2024/2847)

The Cyber Resilience Act increases the cybersecurity of products with digital elements. Manufacturers must already take cybersecurity risks into account during development and product design and effectively address vulnerabilities during the specified support period.

These include, among others:

  • Systematic assessment of potential cyber risks
  • Integration of cybersecurity requirements into development and product design
  • Handling and remediation of vulnerabilities during the support period
  • Defined processes for reporting specific vulnerabilities and security incidents
  • Provide relevant safety information and guidance

The support period is generally at least five years unless the expected useful life of the product is shorter.

EU Machinery Regulation 2027 ((EU) 2023/1230)

The EU Machinery Regulation takes into account the increasing digitization and networking of modern machines.

 

It includes software-based safety functions and digital controls and addresses the protection of safety-related systems against corruption or unauthorized changes, insofar as this can affect machine safety.

 

Manufacturers must assess, document and reduce relevant risks through appropriate protective measures.

CRA and EU Machinery Regulation 2027: SIKO is prepared

A specialized working group at SIKO has been working on the implementation of the new regulatory requirements since 2024. We not only consider individual products, but all relevant processes from development to long-term support.

What you can expect from SIKO

Compliant with the rules at the start of application

SIKO aligns the respective products concerned with the relevant requirements of the Cyber Resilience Act and the EU Machinery Regulation and ensures their fulfillment at the respective date of application.

Clear documentation

Depending on the product, SIKO will provide the intended proof of conformity, declarations and safety-relevant information and instructions. The necessary technical documents are prepared and kept available in accordance with the legal requirements.

Competent advice

Our experts will assist you in answering your questions about products, requirements, areas of application and required evidence.

Safety with foresight

We consider security to be a continuous task and have initiated the SIKO Product Security Incident Response Team (PSIRT). 

In addition, relevant safety information is continuously monitored and necessary measures are implemented during the planned support period.

Security is created together

The new requirements do not only concern individual components. The interaction between product, machine, application and operator environment is decisive.

The conformity of a SIKO product does not replace the necessary risk assessment and conformity assessment of the respective overall machine or application. That is why we support you in classifying the requirements relevant to your application and in taking appropriate measures into account. We look forward to your request.

Contact

Report a vulnerability or security incident to SIKO

Have you detected a possible vulnerability in a SIKO product or would you like to report a security incident?

You can submit the relevant information directly to us via our reporting form. Our responsible team will review your message and contact you if you have any questions.

Report Vulnerability

CRA and EU Machinery Regulation 2027: Frequently Asked Questions

Are SIKO products prepared for the new requirements?
Yes. SIKO systematically assesses all relevant product groups and aligns affected products and processes with the respective applicable requirements. SIKO ensures that the relevant requirements are met at the respective start of validity.

Which products are affected?
The requirements depend on the product type, function and application. SIKO checks all product groups for their relevance to the Cyber Resilience Act and the EU Machinery Regulation and provides the relevant information.

What documents does SIKO provide?
Depending on the product and regulatory requirement, SIKO provides the intended proofs of conformity, declarations and safety-relevant information and instructions. The legally required technical documentation is prepared and kept on file.

Does SIKO support specific customer projects?
Yes. Our experts will support you in classifying the requirements and answer questions about products, areas of application and required proof.

How can I report a vulnerability?
Use thereporting form. Your information will be forwarded to the SIKO Product Security Incident Response Team (PSIRT) and checked.

Where can I find information about vulnerabilities and available security updates for SIKO products?
The SIKO PSIRT publishes onthis page information on identified vulnerabilities in SIKO solutions as well as available updates and recommended actions. Customers and partners are also informed about the Product Change Notification (PCN) process. An overview of all safety instructions can be found in theSecurity Advisories.