CRA and EU Machinery Regulation 2027: Rules change. Reliability remains.
SIKO is prepared for the requirements of the Cyber Resilience Act (CRA) and the EU Machinery Regulation (CSR). Affected products and processes will be aligned with the new requirements to ensure that the relevant requirements are met at the respective start of application. For your planning, we will provide you with clear information, comprehensible evidence and competent advice.
New requirements. Clear security.
The Cyber Resilience Act places new cybersecurity requirements on products with digital elements. At the same time, the EU Machinery Regulation takes into account the increasing digitalization of modern machines and new safety-related risks posed by software and networked systems.
Manufacturers must systematically assess relevant risks, integrate safety requirements into their development processes, produce necessary evidence and meet the respective information and support obligations.
SIKO prepared for these changes at an early stage and aligns affected products and processes with the new specifications. In this way, we create the prerequisites for you to be able to plan safely in the future.
The EU Machinery Regulation (EU) 2023/1230 applies in principle from January 20, 2027. The Cyber Resilience Act (EU) 2024/2847 will apply starting December 11, 2027. Provisions on conformity assessment bodies have been in force since June 11, 2026, and the reporting requirements for manufacturers under Article 14 from September 11, 2026.
What the new requirements mean for you


Cyber Resilience Act ((EU) 2024/2847)
The Cyber Resilience Act increases the cybersecurity of products with digital elements. Manufacturers must already take cybersecurity risks into account during development and product design and effectively address vulnerabilities during the specified support period.
These include, among others:
- Systematic assessment of potential cyber risks
- Integration of cybersecurity requirements into development and product design
- Handling and remediation of vulnerabilities during the support period
- Defined processes for reporting specific vulnerabilities and security incidents
- Provide relevant safety information and guidance
The support period is generally at least five years unless the expected useful life of the product is shorter.
EU Machinery Regulation 2027 ((EU) 2023/1230)
The EU Machinery Regulation takes into account the increasing digitization and networking of modern machines.
It includes software-based safety functions and digital controls and addresses the protection of safety-related systems against corruption or unauthorized changes, insofar as this can affect machine safety.
Manufacturers must assess, document and reduce relevant risks through appropriate protective measures.


Security is created together
The new requirements do not only concern individual components. The interaction between product, machine, application and operator environment is decisive.
The conformity of a SIKO product does not replace the necessary risk assessment and conformity assessment of the respective overall machine or application. That is why we support you in classifying the requirements relevant to your application and in taking appropriate measures into account. We look forward to your request.
Report a vulnerability or security incident to SIKO
Have you detected a possible vulnerability in a SIKO product or would you like to report a security incident?
You can submit the relevant information directly to us via our reporting form. Our responsible team will review your message and contact you if you have any questions.
CRA and EU Machinery Regulation 2027: Frequently Asked Questions
Are SIKO products prepared for the new requirements?
Yes. SIKO systematically assesses all relevant product groups and aligns affected products and processes with the respective applicable requirements. SIKO ensures that the relevant requirements are met at the respective start of validity.
Which products are affected?
The requirements depend on the product type, function and application. SIKO checks all product groups for their relevance to the Cyber Resilience Act and the EU Machinery Regulation and provides the relevant information.
What documents does SIKO provide?
Depending on the product and regulatory requirement, SIKO provides the intended proofs of conformity, declarations and safety-relevant information and instructions. The legally required technical documentation is prepared and kept on file.
Does SIKO support specific customer projects?
Yes. Our experts will support you in classifying the requirements and answer questions about products, areas of application and required proof.
How can I report a vulnerability?
Use thereporting form. Your information will be forwarded to the SIKO Product Security Incident Response Team (PSIRT) and checked.
Where can I find information about vulnerabilities and available security updates for SIKO products?
The SIKO PSIRT publishes onthis page information on identified vulnerabilities in SIKO solutions as well as available updates and recommended actions. Customers and partners are also informed about the Product Change Notification (PCN) process. An overview of all safety instructions can be found in theSecurity Advisories.





