Cyber Resilience Act (CRA): Cybersecurity Obligations, SBOM and Technical File for Machine Builders
What does the EU Cyber Resilience Act (CRA) require from industrial machine builders? The Cyber Resilience Act (Regulation (EU) 2024/2847) introduces mandatory cybersecurity requirements for all "products with digital elements" placed on the EU market, including networked machinery, programmable logic controllers (PLCs), industrial IoT gateways, SCADA interfaces, and connected sensors. Machine builders must: (1) perform a cybersecurity risk assessment during design (Security-by-Design), (2) compile and maintain a machine-readable Software Bill of Materials (SBOM in SPDX or CycloneDX format), (3) report actively exploited vulnerabilities to ENISA and national CSIRTs within 24 hours, and (4) guarantee security updates and vulnerability handling for the expected product lifecycle or at least 5 years. Cybersecurity becomes a mandatory prerequisite for CE marking.
Regulation (EU) 2024/2847 compliance for industrial machine builders: Software Bill of Materials (SBOM), 24h vulnerability reporting, and CE cyber conformity.
Technical Specifications & Regulatory Comparison Matrix
| CRA Milestone | Effective Date | Core Obligation for Machine Builders | Enforcement Body |
|---|---|---|---|
| Entry into Force | Late 2024 | Regulation published; 36-month transition period commences | European Commission |
| Vulnerability & Incident Reporting | Mid-2026 (21 months) | Mandatory 24h notification of actively exploited zero-days to ENISA/CSIRTs | National CSIRTs & ENISA |
| Full CRA Enforcement & CE Marking | Late 2027 (36 months) | All connected machinery must meet Essential Cyber Requirements & have SBOM | National Market Surveillance Authorities |
| Security Support Window | Continuous (min 5 years) | Regular security patches delivered free of charge for operating machines | Market Surveillance Authorities |
1. Synergy between CRA and Machinery Regulation Annex III 1.1.9
While Machinery Regulation (EU) 2023/1230 focuses on preventing cyber corruption that causes physical harm or safety function failures (e.g., overriding an emergency stop), the Cyber Resilience Act covers the broader digital integrity of the asset—preventing ransomware, data exfiltration, industrial espionage, and unauthorized network pivoting. A single harmonized cybersecurity technical file satisfies both regimes.