Context card
Machinery Regulation and CRA: coupled through standards, not cross-references
Why can the Machinery Regulation and the Cyber Resilience Act not simply refer to each other?
The short answer
Because they overlap only on the surface. The Machinery Regulation sets safety objectives — a machine must not become dangerous, including through corruption of its control system — while the CRA sets cybersecurity objectives for products with digital elements. Their scopes and exemptions differ, so a legal cross-reference would leave gaps. The final CRA dropped the presumption its proposal had foreseen and asks for the coupling in harmonised standards instead, where safety and security are linked methodically.
For: Machine builders, safety and security engineers, compliance managers and technical writers
Key points
- Machinery Regulation (EU) 2023/1230, Annex III: 1.1.9 protection against corruption and 1.2.1 safety and reliability of control systems are safety requirements; the regulation applies from January 20, 2027.
- CRA (EU) 2024/2847, Annex I: essential cybersecurity requirements and vulnerability handling for products with digital elements; reporting obligations apply from September 11, 2026, all requirements from December 11, 2027.
- Scopes differ: machinery without digital elements is outside the CRA; software and components that are not machinery are outside the MR; each act has its own exemptions.
- The CRA proposal of 2022 deemed CRA-compliant machinery to meet 1.1.9 and 1.2.1; the final text dropped this and, in Recital 53, asks for harmonised standards for the MR that take the CRA into account.
- A product under both acts complies with both; work done for one can support the other, but the manufacturer demonstrates it.
The context
Two objectives
The Machinery Regulation asks whether a machine stays safe. Its requirements 1.1.9 and 1.2.1 of Annex III treat corruption — accidental or malicious, physical or through a network — as a cause of hazards: a manipulated parameter, a defeated safety function, an unsafe state after an attack.
The Cyber Resilience Act asks whether a product with digital elements is secure: secure by design and default, protected against unauthorized access, with vulnerability handling and security updates over the support period.
Both meet at the safety-security interface, but they ask different questions. A secure product can still be unsafe, and a safe machine does not meet CRA obligations such as vulnerability reporting.
Why a cross-reference does not work
A direct reference would only be clean if both acts covered the same products and the same requirements. They do not:
- Scope: the MR covers machinery and related products whether or not they contain digital elements; the CRA covers products with digital elements, including software and components that are not machinery.
- Exemptions: each act excludes different product groups and refers to different sector law.
- Content: 1.2.1 covers far more than security (faults, logic errors, foreseeable human error), so CRA conformity could not stand in for it.
The CRA proposal therefore lost its machinery article, which would have deemed a CRA declaration of conformity to cover 1.1.9 and 1.2.1. The final CRA keeps the link in Recital 53: the Commission and the European standardisation organisations take the CRA into account when preparing harmonised standards for the Machinery Regulation.
Where the coupling happens
Consistency comes from standards. Standards committees define the method that links a hazard analysis with a threat analysis, assign protection needs to safety functions and point to the security controls of IEC 62443. That is safety-security convergence done methodically. The machinery draft standard EN 50742 on protection against corruption is one example.
For documentation
The technical documentation of a product under both acts keeps two lines of evidence: the risk assessment and safety evidence for the MR, the cybersecurity risk assessment and vulnerability handling for the CRA, with explicit links where one supports the other. Only a harmonised standard whose reference is cited in the Official Journal gives presumption of conformity, and only for the requirements it covers.
Questions readers ask next
- Does meeting the CRA mean meeting 1.1.9 and 1.2.1 of the Machinery Regulation?
- Not automatically. CRA work can contribute, but the manufacturer has to show which MR requirements it covers; 1.2.1 in particular goes beyond security.
- Is there any presumption between the two acts?
- Not between MR and CRA. The Machinery Regulation does provide a presumption for 1.1.9 and 1.2.1 based on certification under a scheme of the Cybersecurity Act (EU) 2019/881, limited to what the certificate covers.
Sources
- Regulation (EU) 2023/1230 on machinery and related products — Official Journal of the European Union, 29 June 2023
- Regulation (EU) 2024/2847 (Cyber Resilience Act) — Official Journal of the European Union, 20 November 2024
- Cyber Resilience Act: Recommendations for the trilogue — ZVEI, 5 October 2023
Review log and changes
Every context card is checked against its sources before it is published, and again whenever it changes; the date under the byline is the last review. Corrections (something was wrong) and additions (something was missing) are logged below with date and time (Berlin time). Typos, formatting and link fixes are not listed.
Reviewed
No corrections or additions since publication.