Implement machinery regulation and CRA together

The Machinery Regulation and the CRA apply in parallel to connected machines. Manufacturers should implement both requirements as a single project instead of duplicating work.

  • Connected machines with a data connection will fall from 2027 under both the Machinery Regulation (Verordnung (EU) 2023/1230) and the Cyber Resilience Act (Verordnung (EU) 2024/2847). Neither regulation exempts the other.
  • The start dates differ: the Machinery Regulation applies from 20 January 2027, the CRA from 11 December 2027. Individual CRA obligations apply already in 2026.
  • The security requirements overlap in substance: the Machinery Regulation requires protection against corruption and reliable controls, and the CRA builds on that. Complying with the CRA makes conformity with the Machinery Regulation easier.
  • Setting up risk assessment, technical documentation and conformity assessment as a single project avoids duplicated work instead of running two parallel tracks.

What it means to implement the machinery regulation and CRA together

Implementing the Machinery Regulation and the CRA together means treating the cybersecurity requirements of the Machinery Regulation (Verordnung (EU) 2023/1230) and the requirements of the Cyber Resilience Act (Verordnung (EU) 2024/2847) for a connected machine in one project rather than in two separate compliance tracks. Both regulations apply in parallel from 2027 but overlap in content.

Do both the machinery regulation and CRA really apply to the same machine?

Yes. A connected machine is subject to both regulations side by side; one does not displace the other. We have discussed the fundamental interaction of CRA and the Machinery Regulation elsewhere. Here we focus on practical implementation: how do you organize the obligations of both regulations within one project?

What the machinery regulation covers and what the CRA covers

The Machinery Regulation applies to machines, interchangeable equipment, safety components, lifting accessories, chains, ropes and straps as well as detachable drive shafts (Art. 2 MVO). Its point of reference is the physical product and the hazards it presents.

The Cyber Resilience Act covers products with digital elements that include a direct or indirect logical or physical data connection to a device or network (Art. 2 para. 1 CRA). Its point of reference is the digital component and its connectivity.

The decisive difference is thus the point of attachment: the Machinery Regulation asks about the functional safety of the machine, the CRA about the cybersecurity of its digital elements. For a connected machine, both apply to the same product.

Why there is no mutual exemption

The CRA explicitly excludes certain product groups from its scope, such as medical devices, in vitro diagnostics, motor vehicles, certain civil aviation products and ship equipment. Machines covered by the Machinery Regulation are not on that list. There is therefore no clause that exempts a machine from the CRA simply because it already falls under the Machinery Regulation.

A connected machine with a data connection is subject to both the CRA and the Machinery Regulation at the same time, and both conformity assessments are required. The CRA, the Machinery Regulation and the Radio Equipment Directive are counted among the three major regulatory challenges for machine builders in the EU.

Characteristic of the machine Machinery Regulation Cyber Resilience Act
Physical machine, safety component, lifting accessory, detachable drive shaft falls within the scope (Art. 2 MVO) only if digital elements are present
Product with digital elements and direct or indirect data connection to a device or network not decisive falls within the scope (Art. 2 para. 1 CRA)
Connected machine with control and data connection yes yes
Medical devices, motor vehicles and other sectoral cases own sector rules excluded (Art. 2 paras. 2 to 4 CRA)

Two start dates, one time window When must you comply with what?

The two regulations do not take effect on the same day. For project planning this is an advantage: you can use the earlier Machinery Regulation deadline as a cadence and pull the CRA requirements along at the same time.

The Machinery Regulation applies from 20 January 2027. The main obligations of the CRA apply from 11 December 2027. Some CRA obligations are brought forward: the reporting obligations for actively exploited vulnerabilities and serious security incidents apply from 11 September 2026, and the chapter on notification of notified bodies applies from 11 June 2026.

Date Regulation What applies from this date
11 June 2026 CRA Notification of notified bodies applicable
11 September 2026 CRA Reporting obligations for actively exploited vulnerabilities and serious incidents
20 January 2027 Machinery Regulation Machinery Regulation applies in full
11 December 2027 CRA CRA main obligations apply in full
11 June 2028 CRA EU type-examination certificates from other harmonisation acts lose validity at the latest

Where do you stand with CRA implementation?

The CRA readiness check shows in a few minutes which CRA requirements for your connected machine are already covered and where gaps remain before you set up the joint project with the Machinery Regulation.

Where the security requirements of the machinery regulation and CRA intersect

The two regulations are not unrelated. The Machinery Regulation already contains its own cybersecurity requirements for the machine, and the CRA explicitly builds on them.

What security the machinery regulation requires

The Machinery Regulation sets out two sections in its annex of essential health and safety requirements that address cybersecurity:

  • The section on protection against corruption (Annex III 1.1.9 MVO) requires that connecting another device does not lead to a dangerous situation, that hardware for safety-related software is protected against corruption, that software and data essential for conformity are identified and protected, and that interventions are detectable.
  • The section on the safety and reliability of controls (Annex III 1.2.1 MVO) requires that controls are designed against foreseeable malicious attempts by third parties, that a defect in the control hardware or software does not lead to a hazardous situation, and that the limits of safety functions are taken into account in the risk assessment.

How the CRA builds on that

The CRA itself recognises this overlap. According to recital 53, manufacturers whose product falls under both the CRA and the Machinery Regulation must meet both sets of requirements. The CRA also states that fulfilling CRA requirements can facilitate conformity with the Machinery Regulation. The conformity assessment procedures of both regulations must be respected, and standardisation should aim for coherence between the two regulatory frameworks.

EN 50742 and IEC 62443 as a common technical bridge

At the technical level both worlds converge via the same standards. EN 50742 is intended as a harmonised standard for protecting machines against corruption and thus addresses the requirement section of the Machinery Regulation. The draft standard offers two routes to conformity. One route is standalone; the other refers for machines to IEC 62443-3-3 and for components to IEC 62443-4-2, each in conjunction with a development process according to IEC 62443-4-1.

For manufacturers this means: if you build the apparatus of EN 50742 and IEC 62443 anyway for the CRA, you can use it at the same time for the Machinery Regulation. IEC 62443 is not a special path but the established state of the art for industrial cybersecurity in mechanical engineering.

Understand EN 50742 as a common basis

EN 50742 governs the protection of machines against corruption and is the anchor through which the security requirements of the Machinery Regulation and the CRA conformity presumption practically converge.

Conformity assessment What you do twice and what once is enough

Two regulations mean two conformity assessments. That is the bad news. The good news is that the substantive basis is largely the same, and the CRA provides a transitional rule for cybersecurity evidence that avoids duplicate checks.

For the Machinery Regulation the risk classification determines the procedure. High-risk machines are listed in Annex I of the Machinery Regulation in two lists. For those categories a stricter conformity assessment is foreseen that requires the involvement of a notified body. The CRA, in turn, classifies products according to their cybersecurity risk. A product with digital elements can generally be assessed by the manufacturer via internal conformity control (Module A). Important and critical products are subject to stricter procedures that require involvement of a notified body (Module B+C or H) or the use of a scheme under the Cybersecurity Act. A connected machine typically does not fall into these special CRA categories unless it fulfils their core functions.

For evidence the CRA provides a transitional rule: EU type-examination certificates from other harmonisation law instruments, including the Machinery Regulation, remain valid until 11 June 2028 at the latest, provided they do not expire earlier.

How this rule works in practice is explained in the European Commission’s guidance on the application of the Cyber Resilience Act. The guidance is not legally binding but indicates the interpretive direction. According to it, a valid EU type-examination certificate under the Machinery Regulation does not exempt the manufacturer from comprehensively assessing cybersecurity risks under the CRA and fulfilling his other CRA obligations. However, in the conformity assessment he may rely on the certificate as evidence insofar as it already covers the relevant risks, for example those from the sections on protection against corruption and on controls; for CRA purposes this possibility ends on 11 June 2028 even if the certificate remains valid beyond that date. If the CRA risk assessment identifies additional cybersecurity risks that the certificate does not cover, the manufacturer remains responsible for those under the CRA.

Project component Covers
Risk assessment and risk evaluation both (a common process is possible)
Technical documentation both (separate evidence parts, common basis)
Conformity assessment both (a separate procedure per regulation)
Reporting channels and vulnerability handling CRA

The assignment in the “both” column is an assessment from our consulting practice, not an explicit prescription of the regulations. It shows where project components can sensibly be bundled and where an obligation exists only in one of the two frameworks: reporting channels and ongoing vulnerability handling are required by the CRA; the Machinery Regulation does not contain them in this form.

How to implement the machinery regulation and CRA together

The greatest leverage is in the risk assessment. Both regulations require a structured risk analysis as a basis. In practice, a combined assessment process usually satisfies the requirements of both frameworks rather than running them twice. This is an insight from practice: the regulations do not prescribe this exact process, but it can be combined so that it fulfils both worlds.

Four steps have proven effective in our consulting practice as orientation for a combined project:

  1. Clarify the scope. Check each machine to determine whether it has a data connection within the meaning of the CRA and thus falls under both regulations.
  2. Set up a common risk assessment. Combine functional safety and cybersecurity in one process, for example following IEC 62443-4-1.
  3. Use evidence twice. Structure your evidence so that it counts for both regulations via the conformity presumption and, where applicable, the transitional rule.
  4. Plan the conformity assessment by risk class. Decide early which procedures require a notified body and plan the project using the earlier Machinery Regulation deadline.

This turns two catalogues of obligations into one project with a common basis and two evidence objectives.

Set up the Machinery Regulation and CRA as one project

Discuss with us how to organise risk assessment, technical documentation and conformity assessment for the Machinery Regulation and the CRA in one joint project instead of two separate compliance tracks.