The machinery regulation and the CRA apply in parallel to connected machines. Manufacturers should address both sets of requirements as a single project instead of duplicating effort.
• Connected machine controls with remote maintenance access that you put on the market from 2027 are subject to two EU frameworks at once: machinery regulation (Regulation (EU) 2023/1230) and the Cyber Resilience Act (Regulation (EU) 2024/2847). Many manufacturers therefore start two separate compliance projects. That doubles costs, even though both regulations address largely the same security requirements.
- Connected machines with a data connection fall from 2027 simultaneously under the machinery regulation (Regulation (EU) 2023/1230) and the Cyber Resilience Act (Regulation (EU) 2024/2847). Neither framework excludes the other.
- The entry-into-force dates differ: the machinery regulation applies from 20 January 2027, the CRA from 11 December 2027. Individual CRA obligations already take effect in 2026.
- The security requirements overlap substantively: the machinery regulation requires protection against corruption and reliable controls; the CRA builds on those requirements. Fulfilling the CRA makes conformity with the machinery regulation easier.
- If you set up risk assessment, technical documentation and conformity assessment as a single project, you avoid duplicate work instead of maintaining two parallel tracks.
What it means to implement machinery regulation and CRA together
Implementing the machinery regulation and the CRA together means you treat the cybersecurity requirements of the machinery regulation (Regulation (EU) 2023/1230) and the requirements of the Cyber Resilience Act (Regulation (EU) 2024/2847) for a connected machine in one project rather than in two separate compliance tracks. Both frameworks apply in parallel from 2027, but they overlap in substance.
Do both the machinery regulation and the CRA really apply to the same machine?
Yes. A connected machine is subject to both regulations side by side; one does not displace the other. The basic interaction between CRA and machinery regulation has been analyzed elsewhere. Here we focus on practical implementation: how do you organise the obligations of both frameworks within a single project?
What does the machinery regulation regulate, and what does the CRA regulate?
The machinery regulation covers machines, interchangeable equipment, safety components, lifting accessories, chains, ropes and straps, and removable drive shafts (Art. 2 MVR). Its point of reference is the physical product and the hazard it poses.
The Cyber Resilience Act covers products with digital elements that include a direct or indirect logical or physical data connection to a device or network (Art. 2(1) CRA). Its point of reference is the digital component and its connectivity.
The crucial difference is therefore the point of attachment: the machinery regulation looks at the functional safety of the machine, the CRA at the cybersecurity of its digital elements. For a connected machine both apply to the same product.
Why there is no mutual exemption
The CRA explicitly excludes certain product groups from its scope, such as medical devices, in‑vitro diagnostics, motor vehicles, certain civil aviation products and ship equipment. Machines under the machinery regulation are not on that list. There is therefore no clause that exempts a machine from the CRA simply because it already falls under the machinery regulation.
A connected machine with a data connection is subject to both the CRA and the machinery regulation at the same time, and both conformity assessments are required. The CRA, the machinery regulation and the Radio Equipment Directive are among the three major regulatory challenges for machine builders in the EU.
| Feature of the machine | Machinery regulation | Cyber Resilience Act |
|---|---|---|
| Physical machine, safety component, lifting accessory, removable drive shaft | falls within the scope (Art. 2 MVR) | only if digital elements are present |
| Product with digital elements and direct or indirect data connection to a device or network | not decisive | falls within the scope (Art. 2(1) CRA) |
| Connected machine with control and data connection | yes | yes |
| Medical devices, motor vehicles and other sectoral cases | sectoral rules apply | excluded (Art. 2(2)–(4) CRA) |
Two start dates, one time window: when must you comply with what?
The two regulations do not become applicable on the same day. For project planning this is an advantage: you can use the earlier machinery regulation deadline as the project tempo and bring CRA requirements along at the same time.
The machinery regulation applies from 20 January 2027. The main obligations of the CRA apply from 11 December 2027. Individual CRA obligations are brought forward: the reporting obligations for actively exploited vulnerabilities and serious security incidents apply from 11 September 2026; the chapter on notified bodies applies from 11 June 2026.
| Date | Regulation | What applies from that date |
|---|---|---|
| 11 June 2026 | CRA | Notification of notified bodies applies |
| 11 September 2026 | CRA | Reporting obligations for actively exploited vulnerabilities and serious incidents |
| 20 January 2027 | Machinery regulation | Machinery regulation applies in full |
| 11 December 2027 | CRA | CRA main obligations apply in full |
| 11 June 2028 | CRA | EU type‑examination certificates from other harmonisation legislation expire at the latest |
Where do you stand with CRA implementation?
The CRA readiness check shows in a few minutes which CRA requirements for your connected machine are already covered and where gaps remain before you set up the joint project with the machinery regulation.
Where the security requirements of the machinery regulation and the CRA overlap
The two frameworks are not unrelated. The machinery regulation already contains its own cybersecurity requirements, and the CRA expressly builds on them.
What the machinery regulation requires for security
In its annex with the essential health and safety requirements the machinery regulation contains two sections that address cybersecurity:
- The section on protection against corruption (Annex III 1.1.9 MVR) requires that connecting to another device does not lead to a dangerous situation, that the hardware for safety‑related software is protected against corruption, that software and data essential for conformity are identified and protected, and that interventions are detectable.
- The section on safety and reliability of control systems (Annex III 1.2.1 MVR) requires that controls be designed against foreseeable malicious attempts by third parties, that a fault in the control hardware or software does not lead to a hazardous situation, and that the limits of safety functions are considered in the risk assessment.
How the CRA ties in
The CRA acknowledges this overlap. According to recital 53, manufacturers whose product falls under both the CRA and the machinery regulation must meet both sets of requirements. The CRA also states that meeting CRA requirements can facilitate conformity with the machinery regulation. The conformity assessment procedures of both regulations must be followed, and standardisation should aim for coherence between the two frameworks.
EN 50742 and IEC 62443 as a common technical bridge
On the technical level both worlds converge on the same standards. EN 50742, currently published as draft prEN 50742, is intended as a harmonised standard for protecting machines against corruption and thus addresses the machinery regulation requirement. The draft standard offers two routes to conformity. One route is standalone, the other refers for machines to IEC 62443‑3‑3 and for components to IEC 62443‑4‑2, each in conjunction with a development process according to IEC 62443‑4‑1.
For manufacturers this means: if you build the EN 50742 and IEC 62443 apparatus anyway for the CRA, you can use it at the same time for the machinery regulation. The IEC 62443 is not a special route but the established state of the art for industrial cybersecurity in mechanical engineering.
Understand EN 50742 as the common foundation
EN 50742 governs protection of machines against corruption and is the anchor point where the machinery regulation’s security requirements and the CRA’s presumption of conformity practically converge.
Conformity assessment: what you will do twice and what once is enough
Two regulations mean two conformity assessments. That is the bad news. The good news: the substantive basis is largely the same, and for cybersecurity evidence there is a transitional rule that avoids duplicate checks.
For the machinery regulation the risk classification determines the procedure. High‑risk machines are listed in two lists in Annex I of the machinery regulation. These categories require a stricter conformity assessment that involves a notified body. The CRA classifies products by their cybersecurity risk. A product with digital elements can normally be assessed by the manufacturer via internal conformity assessment (Module A). Important and critical products are subject to stricter procedures requiring involvement of a notified body (Module B+C or H) or the use of a scheme under the Cybersecurity Act. A connected machine typically does not fall into these special CRA categories unless it fulfils their core functions.
For evidence the CRA provides a transitional rule: EU type‑examination certificates from other harmonisation legislation, including the machinery regulation, remain valid until 11 June 2028, provided they do not expire earlier.
How this rule works in practice is explained in the Commission’s draft guidelines. This draft is not legally binding but indicates the direction of interpretation. According to it: if an EU type‑examination certificate under the machinery regulation covers certain cybersecurity risks, specifically those from the sections on protection against corruption and on control systems, then no renewed assessment under the CRA is required for those risks as long as the certificate remains valid. If the CRA risk assessment identifies additional cybersecurity risks not covered by the certificate, the manufacturer remains responsible for those under the CRA.
| Project element | Covers |
|---|---|
| Risk assessment and risk evaluation | both (a single combined process is possible) |
| Technical documentation | both (separate evidence parts, common basis) |
| Conformity assessment | both (one procedure per regulation) |
| Reporting channels and vulnerability handling | CRA |
The assignments in the “both” column reflect our consulting practice, not an explicit prescription of the regulations. They show where project elements can sensibly be bundled and where an obligation exists only in one of the two frameworks: reporting channels and ongoing vulnerability handling are required by the CRA; the machinery regulation does not contain them in the same form.
How to implement the machinery regulation and the CRA together
The greatest leverage lies in the risk assessment. Both regulations require a structured risk analysis as the basis. In practice, a combined assessment process typically serves the requirements of both frameworks instead of duplicating the effort. This is an insight from practice: the regulations do not mandate this exact process, but it can be combined in a way that satisfies both regimes.
In our consulting practice four steps have proven effective as guidance for a combined project:
- Clarify the scope. For each machine check whether it has a data connection within the meaning of the CRA and thus falls under both regulations.
- Set up a joint risk assessment. Combine functional safety and cybersecurity in one process, for example along IEC 62443‑3‑2.
- Reuse evidence. Structure your evidence so that it counts for both regulations via the presumption of conformity and, where applicable, the transitional rule.
- Plan conformity assessment by risk class. Decide early which procedures require a notified body and plan the project around the earlier machinery regulation deadline.
This is how two obligation catalogues become one project with a common foundation and two evidence goals.
Set up the machinery regulation and the CRA as a single project
Talk to us about how to organise risk assessment, technical documentation and conformity assessment for the machinery regulation and the CRA in a single project instead of two separate compliance tracks.