The Machinery Regulation and the Cyber Resilience Act apply in parallel to connected machines. Manufacturers should address both sets of requirements as a single project instead of duplicating effort.
• Connected machines with a data connection will fall, from 2027, simultaneously under the Machinery Regulation (Regulation (EU) 2023/1230) and the Cyber Resilience Act (Regulation (EU) 2024/2847). Neither regulation excludes the other.
• The start dates differ: the Machinery Regulation applies from 20 January 2027, the CRA from 11 December 2027. Individual CRA obligations already take effect in 2026.
• The security requirements overlap in content: the Machinery Regulation requires protection against corruption and reliable controls; the CRA builds on that. Compliance with the CRA can ease conformity with the Machinery Regulation.
• Setting up risk assessment, technical documentation and conformity assessment as a single project avoids double work instead of running two parallel tracks.
What does it mean to implement the machinery regulation and CRA together?
Implementing the Machinery Regulation and the CRA together means treating the cybersecurity requirements of the Machinery Regulation (Regulation (EU) 2023/1230) and the requirements of the Cyber Resilience Act (Regulation (EU) 2024/2847) for a connected machine in one project rather than in two separate compliance tracks. Both legal acts apply in parallel from 2027 but overlap in content.
Do both the machinery regulation and the CRA really apply to the same machine?
Yes. A connected machine falls under both regulations side by side, without one displacing the other. The basic interaction of CRA and Machinery Regulation has been analysed elsewhere in detail. Here we focus on practical implementation: how to organise the obligations of both legal acts within a single project?
What does the machinery regulation regulate, and what does the CRA regulate?
The Machinery Regulation covers machines, interchangeable equipment, safety components, lifting accessories, chains, ropes and webbing and removable drive shafts (Art. 2 MVR). Its point of reference is the physical product and the hazards it presents.
The Cyber Resilience Act covers products with digital elements that include a direct or indirect logical or physical data connection to a device or network (Art. 2(1) CRA). Its point of reference is the digital component and its connectivity.
The decisive difference is therefore the point of attachment: the Machinery Regulation asks about the functional safety of the machine; the CRA asks about the cybersecurity of its digital elements. For a connected machine both aspects apply to the same product.
Why there is no mutual exemption
The CRA explicitly excludes certain product groups from its scope, such as medical devices, in vitro diagnostics, motor vehicles, certain civil aviation products and ship equipment. Machines under the Machinery Regulation are not on that list. There is therefore no clause that exempts a machine from the CRA simply because it already falls under the Machinery Regulation.
A connected machine with a data connection is simultaneously subject to the CRA and the Machinery Regulation, and both conformity assessments are required. The CRA, the Machinery Regulation and the Radio Equipment Directive are counted among the three major regulatory challenges for machine builders in the EU.
| Machine characteristic | Machinery Regulation | Cyber Resilience Act |
|---|---|---|
| Physical machine, safety component, lifting accessory, removable drive shaft | falls within the scope (Art. 2 MVR) | only if digital elements are present |
| Product with digital elements and direct or indirect data connection to a device or network | not decisive | falls within the scope (Art. 2(1) CRA) |
| Connected machine with control system and data connection | yes | yes |
| Medical devices, motor vehicles and other sectoral cases | own sector rules | excluded (Art. 2(2)–(4) CRA) |
Two start dates, one time window: when must you comply with what?
The two regulations do not take effect on the same day. For project planning this is an advantage: you can use the earlier Machinery Regulation deadline as the pacing milestone and address CRA requirements at the same time.
The Machinery Regulation applies from 20 January 2027. The main obligations of the CRA apply from 11 December 2027. Some CRA obligations are brought forward: reporting obligations for actively exploited vulnerabilities and serious security incidents apply from 11 September 2026; the chapter on notified bodies applies from 11 June 2026.
| Date | Regulation | What applies from this date |
|---|---|---|
| 11 June 2026 | CRA | Notification of notified bodies applicable |
| 11 September 2026 | CRA | Reporting obligations for actively exploited vulnerabilities and serious incidents |
| 20 January 2027 | Machinery Regulation | Machinery Regulation fully applies |
| 11 December 2027 | CRA | Main CRA obligations fully apply |
| 11 June 2028 | CRA | EU type-examination certificates from other harmonisation legislation lose validity at the latest |
zeitschiene-mvo-cra-1024×614.png
Where do you stand with CRA implementation?
The CRA readiness check shows in minutes which CRA requirements for your connected machine are already covered and where gaps remain before you set up the joint project with the Machinery Regulation.
Where do the security requirements of the machinery regulation and the CRA overlap?
The two legal acts do not stand unrelated to each other. The Machinery Regulation already contains its own requirements for the cybersecurity of the machine, and the CRA explicitly builds on those.
What security the machinery regulation requires
The Machinery Regulation sets out two sections in its annex of essential health and safety requirements that address cybersecurity:
• The section on protection against corruption (Annex III 1.1.9 MVR) requires that connecting another device does not lead to a hazardous situation, that hardware for safety-related software is protected against corruption, that software and data essential for conformity are identified and protected, and that tampering is traceable.
• The section on safety and reliability of control systems (Annex III 1.2.1 MVR) requires that controls are designed to withstand foreseeable malicious attempts by third parties, that a defect of the control hardware or software does not lead to a hazardous situation, and that the limits of safety functions are considered in the risk assessment.
How the CRA builds on this
The CRA recognises this overlap. In recital 53 it states that manufacturers whose product falls under both the CRA and the Machinery Regulation must meet both sets of requirements. The CRA also notes that meeting CRA requirements can facilitate conformity with the Machinery Regulation. The conformity assessment procedures of both regulations must be observed, and standardisation should aim for coherence between the two legal acts.
EN 50742 and IEC 62443 as a common technical bridge
At the technical level both domains converge on the same standards. EN 50742, currently published as draft prEN 50742, is intended as a harmonised standard for protecting machines against corruption and thus addresses the Machinery Regulation’s requirement section. The draft standard offers two routes to conformity. One route is standalone; the other refers, for machines, to IEC 62443-3-3 and, for components, to IEC 62443-4-2, each in conjunction with a development process according to IEC 62443-4-1.
For manufacturers this means: those who build the EN 50742 and IEC 62443 apparatus anyway for the CRA can use it at the same time for the Machinery Regulation. IEC 62443 is not a special route but the established state of the art for industrial cybersecurity in mechanical engineering.
Understand EN 50742 as a common basis
EN 50742 governs protection of machines against corruption and is the anchor point through which the Machinery Regulation’s security requirements and the CRA conformity presumption practically converge.
Conformity assessment: what you do twice and what is sufficient once
Two regulations mean two conformity assessments. That’s the bad news. The good news: the substantive basis is largely the same, and for cybersecurity evidence there is a transitional rule that avoids duplicate testing.
For the Machinery Regulation the risk classification determines the procedure. High-risk machines are listed in Annex I in two lists. For those categories a stricter conformity assessment is foreseen that requires involvement of a notified body. The CRA, for its part, classifies products according to their cybersecurity risk. A product with digital elements can, as a rule, be assessed by the manufacturer under internal conformity control (Module A). Important and critical products are subject to stricter procedures requiring involvement of a notified body (Module B+C or H) or the use of a scheme under the Cybersecurity Act. A connected machine typically does not fall into these special CRA categories unless it fulfils their core functions.
For evidence the CRA provides a transitional rule: EU type-examination certificates from other harmonisation legislation, including the Machinery Regulation, remain valid until 11 June 2028, provided they do not expire earlier.
How this rule works in practice is explained in the Commission’s draft guidance. The draft is not legally binding but indicates interpretative direction. According to it: if an EU type-examination certificate under the Machinery Regulation covers certain cybersecurity risks, in particular those from the sections on protection against corruption and controls, then those risks do not require a new assessment under the CRA while the certificate is valid. If, however, the CRA risk assessment identifies additional cybersecurity risks not covered by the certificate, the manufacturer remains responsible for those under the CRA.
| Project component | Covers |
|---|---|
| Risk analysis and risk assessment | both (a common process is possible) |
| Technical documentation | both (separate proof sections, common basis) |
| Conformity assessment | both (a separate procedure per regulation) |
| Reporting channels and vulnerability handling | CRA |
The assignment in the “both” column reflects our consulting practice, not an explicit prescription of the regulations. It shows where project components can sensibly be combined and where an obligation exists only under one of the two legal acts: reporting channels and ongoing vulnerability handling are required by the CRA; the Machinery Regulation does not require them in this form.
How do you implement the machinery regulation and the CRA together?
The biggest lever is the risk assessment. Both regulations require a structured risk analysis as a basis. In practice, a single combined assessment process typically serves the requirements of both legal acts rather than running them twice. This is an observation from practice: the regulations do not prescribe this concrete process, but it can be combined so that it satisfies both domains.
As orientation for a combined project, four steps have proven useful in our consulting practice:
- Clarify the scope. For each machine, check whether it has a data connection within the meaning of the CRA and thus falls under both regulations.
- Set up a common risk assessment. Combine functional safety and cybersecurity in one process, for example along IEC 62443-3-2.
- Use evidence twice. Build your evidence so that it counts for both regulations via the conformity presumption and, where applicable, the transitional rule.
- Plan conformity assessment according to risk class. Early on determine which procedures require a notified body, and plan the project using the earlier Machinery Regulation deadline.
This approach turns two sets of obligations into one project with a shared basis and two evidence targets.
Set up the machinery regulation and CRA as one project
Talk to us about how to organise risk assessment, technical documentation and conformity assessment for the Machinery Regulation and the CRA in a single project rather than two separate compliance tracks.