OEMs, are you ready for the coming mandatory EU regulations? | Rockwell Automation | US

Источник: Rockwell Automation

OEMs, are you ready for the coming mandatory EU regulations? | Rockwell Automation | US

Source: Rockwell Automation

Get your machines and business ready for the EU Machinery Regulation and Cyber Resilience Act.

•Updated: October 1, 2026

Preparing for the Machinery Regulation and Cyber Resilience Act: Two regulations, one connected challenge

Original equipment manufacturers (OEMs) are preparing for two significant regulatory changes that will impact the design, development and lifecycle management of their connected machines.

The Machinery Regulation (EU) 2023/1230 will become fully applicable on 20 January 2027 and applies to machinery, related products and partly completed machinery within the EU market. While its primary focus remains the protection of people and machine safety, it also explicitly addresses risks introduced by digital technologies, including protection against corruption and the integrity of safety-related control systems. To learn more about how you can meet the standards within this regulation, explore our guide. The Cyber Resilience Act (EU) 2024/2847 will become fully applicable on 11 December 2027 and introduces a uniform legal framework for cybersecurity requirements for products with digital elements (PDEs) placed on the European market. This includes not only individual components such as controllers, drives, and software, but also complete connected machines. The CRA requires manufacturers to integrate cybersecurity throughout the product lifecycle, from design and development to vulnerability management, security updates and incident reporting.

While the Machinery Regulation and Cyber Resilience Act have distinct requirements, both reinforce the need for stronger cybersecurity across connected machines. To meet the requirements in these regulations, OEMs should focus on cybersecurity compliance that integrates safety, security and risk management throughout the machine lifecycle.

How these regulations apply to OEMs

These regulations are broadly applicable to machine builders. If the machine target is the EU market, the regulation applies, regardless of where the supplier is located. Supplying non-compliant machines will be illegal and violators could be subject to penalties up to €15 million or 2.5% of global turnover.

Additionally, compliance is no longer limited to just the machine design. The Machinery Regulation and Cyber Resilience Act require OEMs to think beyond the initial build and consider how safety and cybersecurity will be managed throughout the entire machine lifecycle.

What can you do to prepare for the Machinery Regulation and Cyber Resilience Act?

Together, the Machinery Regulation and Cyber Resilience Act reinforce the need for a secure-by-design and lifecycle-based approach. To prepare, OEMs should consider the following areas:

  • Risk Assessments Manufacturers should document how cybersecurity-related risks have been identified, evaluated and addressed as part of the product development process, helping support regulatory readiness and technical documentation requirements.
  • Manufacturers should document how cybersecurity-related risks have been identified, evaluated and addressed as part of the product development process, helping support regulatory readiness and technical documentation requirements.
  • Secure by Default Products must be made available on the market with a secure by default posture
  • Products must be made available on the market with a secure by default posture
  • Data Confidentiality Help protect the confidentiality and integrity of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state-of-the-art mechanisms​
  • Help protect the confidentiality and integrity of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state-of-the-art mechanisms​
  • Data Integrity Help ensure the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorized by the user, and report on corruptions
  • Help ensure the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorized by the user, and report on corruptions
  • Access Control Deliver protection from unauthorized access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorized access
  • Deliver protection from unauthorized access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorized access
  • Event Logging Provide security-related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user
  • Provide security-related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user
  • Vulnerability Reporting Develop processes to identify, assess and remediate vulnerabilities throughout the product lifecycle. CRA also introduces reporting obligations for actively exploited vulnerabilities and significant cybersecurity incidents, making governance and response processes increasingly important. Reporting responsibilities are both to customers and ENISA
  • Develop processes to identify, assess and remediate vulnerabilities throughout the product lifecycle. CRA also introduces reporting obligations for actively exploited vulnerabilities and significant cybersecurity incidents, making governance and response processes increasingly important. Reporting responsibilities are both to customers and ENISA

Let’s advance your Machinery Regulation and Cyber Resilience Act compliance journey together

Rockwell Automation can help OEMs like you bring safety, cybersecurity, and lifecycle considerations together to support an intelligent compliance pathway. We have systematically developed and implemented a robust cybersecurity foundation across our product portfolio and architectures, demonstrated by being the first industrial automation company to achieve IEC 62443-4-1 ML4 certification, the highest certification level for a secure product development lifecycle (SDL).

Many of the cybersecurity capabilities OEMs need to support their compliance strategies are already embedded within Rockwell Automation technologies today. These include secure communications through CIP Security, event logging through Syslog, secure-by-design development practices, access control capabilities and security policy management. Additionally, our SecureOT™ services can help OEMs evaluate cybersecurity risks, strengthen operational technology environments, and develop strategies for ongoing vulnerability management, security updates and lifecycle support. These capabilities align with many of the functional cybersecurity requirements outlined in Annex I of the Cyber Resilience Act and can support a defense in depth approach across the machine lifecycle.

Compliance, however, extends beyond individual products or technologies. No single component can make a machine compliant. Ultimately, compliance remains the responsibility of the machine manufacturer and depends on factors such as the intended use of the machine, system architecture, safety and cybersecurity risk assessments, system integration, technical documentation, and ongoing lifecycle processes.

Our goal is to help OEMs select the right technologies, implement cybersecurity best practices and establish repeatable lifecycle management processes that support both regulatory readiness and long-term operational resilience.

What should I do next?

Start with the machines you plan to place on the EU market and map the applicable requirements, key gaps and decision owners. Prioritize Machinery Regulation readiness for the January 2027 application date, while building Cyber Resilience Act cybersecurity and lifecycle requirements into the same product roadmap.

Have questions? We are here to help. Visit the trust center or contact to your local Rockwell Automation representative to learn more about how we can help solve your unique OEM compliance challenges.

What this article says

Something is unclear? Ask about the article — I will explain in plain words.

Do not want to dig deeper? We will sort it out for you.