The machinery regulation and the CRA apply in parallel to connected machines. Manufacturers should implement both sets of requirements as a single project rather than duplicate work.
- Connected machines with a data connection will fall simultaneously under the machinery regulation (Regulation (EU) 2023/1230) and the Cyber Resilience Act (Regulation (EU) 2024/2847) from 2027. Neither regulation excludes the other.
- The start dates differ: the machinery regulation applies from 20 January 2027, the CRA from 11 December 2027. Individual CRA obligations already take effect in 2026.
- The security requirements overlap substantively: the machinery regulation requires protection against corruption and reliable controls, and the CRA builds on that. Compliance with the CRA facilitates conformity with the machinery regulation.
- If you set up risk assessment, technical documentation and conformity assessment as one project, you avoid duplicate work instead of maintaining two parallel tracks.
What does it mean to implement machinery regulation and the CRA together?
Implementing the machinery regulation and the CRA together means: you handle the cybersecurity requirements of the machinery regulation (Regulation (EU) 2023/1230) and the requirements of the Cyber Resilience Act (Regulation (EU) 2024/2847) for a connected machine within a single project instead of two separate compliance tracks. Both regimes apply in parallel from 2027, but they overlap in substance.
Do the machinery regulation and the CRA really both apply to the same machine?
Yes. Both regulations apply side by side to a connected machine; one does not displace the other. We have discussed the basic interaction of CRA and the machinery regulation elsewhere in detail. Here we address practical implementation: how do you organise the obligations of both regimes within one project?
What does the machinery regulation govern and what does the CRA govern?
The machinery regulation covers machines, interchangeable equipment, safety components, lifting accessories, chains, ropes and webbing and removable drive shafts (Art. 2 MVO). Its point of reference is the physical product and the hazard it poses.
The Cyber Resilience Act captures products with digital elements that include a direct or indirect logical or physical data connection to a device or network (Art. 2(1) CRA). Its point of reference is the digital component and its connectivity.
The decisive difference is therefore the point of attachment: the machinery regulation asks about the functional safety of the machine, the CRA about the cybersecurity of its digital elements. For a connected machine both perspectives apply to the same product.
Why there is no mutual exception
The CRA explicitly excludes certain product groups from its scope, such as medical devices, in vitro diagnostics, motor vehicles, certain civil aviation products and ship equipment. Machines under the machinery regulation are not on that list. There is therefore no clause that exempts a machine from the CRA simply because it already falls under the machinery regulation.
A connected machine with a data connection is simultaneously subject to the CRA and the machinery regulation, and both conformity assessments are required. CRA, the machinery regulation and the Radio Equipment Directive are counted among the three major regulatory challenges for machine builders in the EU.
| Characteristic of the machine | Machinery regulation | Cyber Resilience Act |
|---|---|---|
| Physical machine, safety component, lifting accessory, removable drive shaft | falls within the scope (Art. 2 MVO) | only if digital elements are present |
| Product with digital elements and direct or indirect data connection to a device or network | not decisive | falls within the scope (Art. 2(1) CRA) |
| Connected machine with a control system and data connection | yes | yes |
| Medical devices, motor vehicles and other sectoral cases | own sector rules | excluded (Art. 2(2)–(4) CRA) |
Two start dates, one time window: when must you comply with what?
The two regulations do not become effective on the same day. For project planning this is an advantage: you can use the earlier machinery regulation deadline as the pacing requirement and address the CRA obligations at the same time.
The machinery regulation applies from 20 January 2027. The main obligations of the CRA apply from 11 December 2027. Individual CRA obligations are brought forward: the reporting obligations for actively exploited vulnerabilities and serious security incidents apply from 11 September 2026, and the chapter on notifying notified bodies applies from 11 June 2026.
| Date | Regulation | What applies from this day |
|---|---|---|
| 11 June 2026 | CRA | Notification of notified bodies applicable |
| 11 September 2026 | CRA | Reporting obligations for actively exploited vulnerabilities and serious incidents |
| 20 January 2027 | Machinery regulation | Machinery regulation applies in full |
| 11 December 2027 | CRA | CRA main obligations apply in full |
| 11 June 2028 | CRA | EU type-examination certificates from other harmonisation acts lose validity at the latest |
zeitschiene-mvo-cra.png
Where do you stand on CRA implementation?
The CRA-Readiness-Check shows in minutes which CRA requirements for your connected machine are already covered and where gaps remain before you set up the joint project with the machinery regulation.
Where do the security requirements of the machinery regulation and the CRA overlap?
The two regimes do not stand apart. The machinery regulation already contains its own requirements for the cybersecurity of the machine, and the CRA explicitly builds on those.
What the machinery regulation requires for security
The machinery regulation sets out two sections in its annex with essential health and safety requirements that address cybersecurity:
- The section on protection against corruption (Annex III 1.1.9 MVO) requires that connecting another device does not lead to a hazardous situation, that hardware for safety-related software is protected from corruption, that software and data essential for conformity are identified and protected, and that interventions are detectable.
- The section on the safety and reliability of controls (Annex III 1.2.1 MVO) requires that controls are designed against foreseeable malicious attempts by third parties, that a defect of the control hardware or software does not lead to a hazardous situation, and that the limits of safety functions are taken into account in the risk assessment.
How the CRA builds on that
The CRA recognises this overlap. According to its recital 53 manufacturers whose product falls under both the CRA and the machinery regulation must meet both sets of requirements. The CRA notes, however, that meeting the CRA requirements can facilitate conformity with the machinery regulation. The conformity assessment procedures of both regulations must be observed, and standardisation should aim for coherence between the two regimes.
EN 50742 and IEC 62443 as a common technical bridge
At the technical level both worlds converge on the same standards. EN 50742 is envisaged as a harmonised standard for protecting machines against corruption and thus addresses the relevant section of the machinery regulation. The draft standard offers two routes to conformity. One route is independent, the other route refers for machines to IEC 62443-3-3 and for components to IEC 62443-4-2, each in conjunction with a development process according to IEC 62443-4-1.
For manufacturers this means: if you build the apparatus of EN 50742 and IEC 62443 for the CRA anyway, you can use it for the machinery regulation at the same time. IEC 62443 is not an alternative route but the established state of the art for industrial cybersecurity in mechanical engineering.
Understand EN 50742 as a common basis
EN 50742 regulates the protection of machines against corruption and is the anchor point through which the security requirements of the machinery regulation and the CRA presumption of conformity practically converge.
Conformity assessment: what you do twice and what once is enough
Two regulations mean two conformity assessments. That is the bad news. The good news: the substantive basis is largely the same, and for cybersecurity evidence there is a transitional rule that avoids duplicate checks.
For the machinery regulation the risk classification determines the procedure. Machines with high risk are listed in Annex I of the machinery regulation in two lists. For these categories a stricter conformity assessment is provided that requires involvement of a notified body. The CRA, in turn, classifies products by their cybersecurity risk. A product with digital elements can generally be assessed by the manufacturer via internal conformity assessment (module A). Important and critical products are subject to stricter procedures that require involvement of a notified body (module B+C or H) or the use of a scheme under the Cybersecurity Act. A connected machine typically does not fall into these special CRA categories unless it fulfils their core functions.
For evidence the CRA provides a transitional rule: EU type-examination certificates from other harmonisation legal acts, including the machinery regulation, remain valid until 11 June 2028, provided they do not expire earlier.
How this rule works in practice is explained in the European Commission’s guidelines on the application of the Cyber Resilience Act. They are not legally binding but indicate the direction of interpretation. According to them, a valid EU type-examination certificate under the machinery regulation does not exempt the manufacturer from comprehensively assessing cybersecurity risks under the CRA and from fulfilling the remaining CRA obligations. However, in the conformity assessment procedure the manufacturer may rely on the certificate as evidence insofar as it already covers the relevant risks, for example those arising from the sections on protection against corruption and on controls; for the purposes of the CRA this possibility ends on 11 June 2028, even if the certificate remains valid beyond that. If the CRA risk assessment identifies additional cybersecurity risks not covered by the certificate, the manufacturer remains responsible for these under the CRA.
| Project component | Covers |
|---|---|
| Risk assessment and risk evaluation | both (a common process is possible) |
| Technical documentation | both (separate evidence parts, common basis) |
| Conformity assessment | both (a separate procedure per regulation) |
| Reporting channels and vulnerability handling | CRA |
The assignments in the “both” column reflect our consulting practice, not an explicit prescription of the regulations. They show where project components can sensibly be bundled and where an obligation exists only in one of the two regimes: reporting channels and ongoing vulnerability handling are required by the CRA; the machinery regulation does not know them in this form.
How do you implement the machinery regulation and the CRA together?
The biggest lever is the risk assessment. Both regulations require a structured risk analysis as a basis. In practice a joint assessment process usually serves the requirements of both regimes instead of running them twice. This is an observation from practice: the regulations do not prescribe this exact process, but it can be combined so that it satisfies both worlds.
As orientation for a combined project, four steps have proven their worth in our consulting practice:
- Clarify the scope. For each machine check whether it has a data connection within the meaning of the CRA and therefore falls under both regimes.
- Set up a joint risk assessment. Combine functional safety and cybersecurity in a single process, for example along IEC 62443-3-2.
- Reuse evidence. Build your evidence so that it counts for both the presumption of conformity and, where applicable, the transitional rule.
- Plan conformity assessment by risk class. Determine early which procedures require a notified body and plan the project using the earlier machinery regulation deadline.
This turns two obligation catalogues into a project with a common foundation and two evidence objectives.
Set up the machinery regulation and the CRA as one project
Talk to us about how to organise risk assessment, technical documentation and conformity assessment for the machinery regulation and the CRA in a single project instead of two separate compliance tracks.