Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge
  • English (US)
  • English (UK)
  • Deutsch
All context cards

Context card

Machinery Regulation and CRA: coupled through standards, not cross-references

Why can the Machinery Regulation and the Cyber Resilience Act not simply refer to each other?

By knowledge.aitechdoc.world

Reviewed

Review log and changes

The short answer

Because they overlap only on the surface. The Machinery Regulation sets safety objectives — a machine must not become dangerous, including through corruption of its control system — while the CRA sets cybersecurity objectives for products with digital elements. Their scopes and exemptions differ, so a legal cross-reference would leave gaps. The final CRA dropped the presumption its proposal had foreseen and asks for the coupling in harmonized standards instead, where safety and security are linked methodically.

For: Machine builders, safety and security engineers, compliance managers and technical writers

Key points

  • Machinery Regulation (EU) 2023/1230, Annex III: 1.1.9 protection against corruption and 1.2.1 safety and reliability of control systems are safety requirements; the regulation applies from January 20, 2027.
  • CRA (EU) 2024/2847, Annex I: essential cybersecurity requirements and vulnerability handling for products with digital elements; reporting obligations apply from September 11, 2026, all requirements from December 11, 2027.
  • Scopes differ: machinery without digital elements is outside the CRA; software and components that are not machinery are outside the MR; each act has its own exemptions.
  • The CRA proposal of 2022 deemed CRA-compliant machinery to meet 1.1.9 and 1.2.1; the final text dropped this and, in Recital 53, asks for harmonized standards for the MR that take the CRA into account.
  • A product under both acts complies with both; work done for one can support the other, but the manufacturer demonstrates it.

The context

Two objectives

The Machinery Regulation asks whether a machine stays safe. Its requirements 1.1.9 and 1.2.1 of Annex III treat corruption — accidental or malicious, physical or through a network — as a cause of hazards: a manipulated parameter, a defeated safety function, an unsafe state after an attack.

The Cyber Resilience Act asks whether a product with digital elements is secure: secure by design and default, protected against unauthorized access, with vulnerability handling and security updates over the support period.

Both meet at the safety-security interface, but they ask different questions. A secure product can still be unsafe, and a safe machine does not meet CRA obligations such as vulnerability reporting.

Why a cross-reference does not work

A direct reference would only be clean if both acts covered the same products and the same requirements. They do not:

  • Scope: the MR covers machinery and related products whether or not they contain digital elements; the CRA covers products with digital elements, including software and components that are not machinery.
  • Exemptions: each act excludes different product groups and refers to different sector law.
  • Content: 1.2.1 covers far more than security (faults, logic errors, foreseeable human error), so CRA conformity could not stand in for it.

The CRA proposal therefore lost its machinery article, which would have deemed a CRA declaration of conformity to cover 1.1.9 and 1.2.1. The final CRA keeps the link in Recital 53: the Commission and the European standardization organizations take the CRA into account when preparing harmonized standards for the Machinery Regulation.

Where the coupling happens

Consistency comes from standards. Standards committees define the method that links a hazard analysis with a threat analysis, assign protection needs to safety functions and point to the security controls of IEC 62443. That is safety-security convergence done methodically. The machinery draft standard EN 50742 on protection against corruption is one example.

For documentation

The technical documentation of a product under both acts keeps two lines of evidence: the risk assessment and safety evidence for the MR, the cybersecurity risk assessment and vulnerability handling for the CRA, with explicit links where one supports the other. Only a harmonized standard whose reference is cited in the Official Journal gives presumption of conformity, and only for the requirements it covers.

Questions readers ask next

Does meeting the CRA mean meeting 1.1.9 and 1.2.1 of the Machinery Regulation?
Not automatically. CRA work can contribute, but the manufacturer has to show which MR requirements it covers; 1.2.1 in particular goes beyond security.
Is there any presumption between the two acts?
Not between MR and CRA. The Machinery Regulation does provide a presumption for 1.1.9 and 1.2.1 based on certification under a scheme of the Cybersecurity Act (EU) 2019/881, limited to what the certificate covers.

Sources

  1. Regulation (EU) 2023/1230 on machinery and related products — Official Journal of the European Union, June 29, 2023
  2. Regulation (EU) 2024/2847 (Cyber Resilience Act) — Official Journal of the European Union, November 20, 2024
  3. Cyber Resilience Act: Recommendations for the trilogue — ZVEI, October 5, 2023

Review log and changes

Every context card is checked against its sources before it is published, and again whenever it changes; the date under the byline is the last review. Corrections (something was wrong) and additions (something was missing) are logged below with date and time (Berlin time). Typos, formatting and link fixes are not listed.

Reviewed

No corrections or additions since publication.