Shape

Industry

Machine builders: cybersecurity, CRA and the Machinery Regulation

Two EU regulations change how connected machines are designed in 2027. We help you build them into your products and your technical file.

Context

Regulatory context

  1. Machinery Regulation (EU) 2023/1230, applicable on 20 January 2027: protection against corruption of control systems and handling of evolving behaviour.

  2. Cyber Resilience Act: reporting of exploited vulnerabilities since 11 September 2026, full essential requirements on 11 December 2027.

  3. RED directive for radio equipment: cybersecurity requirements since August 2025, EN 18031 standards.

Challenges

Your challenges

Security by design

Secure boot, OTA updates, secrets management: architecture choices that are hard to retrofit.

Documenting for CE marking

Cybersecurity becomes part of the machine’s risk assessment and technical file.

Long-term follow-up

SBOM, vulnerability monitoring, patches and reporting over the whole support period.

FAQ

Frequently asked questions

Does the Machinery Regulation replace the Machinery Directive?

Yes. Regulation (EU) 2023/1230 replaces Directive 2006/42/EC from 20 January 2027, with new requirements on control-system cybersecurity.

Where should we start?

With a gap analysis on one representative product: it shows the design gaps to fix and what belongs to the organisation (monitoring, reporting).

A regulatory deadline is coming up?

Let’s talk about your site or product. One call is enough to know where to start.

Shape