Technical article

Cyber Resilience Act: Guidance for manufacturers of products with digital elements

What requirements does the CRA impose on manufacturers?

Guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act)


Share Article
Share Button Linkedin Share Button Xing Share Button X Share Button Email

The CRA aims to create a uniform EU-wide regulatory framework for cybersecurity requirements for products with digital elements – across the entire product life cycle.

According to Article 26 of Regulation (EU) 2024/2847, the European Commission is obliged to publish guidelines to assist economic operators in applying the Regulation. The final version of this guidance has now been published by the EU Commission on 27 July 2026.

This technical article focuses on explaining the contents of the guidance to manufacturers of machinery, equipment and electrical equipment (IoT devices) and supporting them in complying with the new requirements.

CRA Guidance 2026: What does the final version clarify for machinery manufacturers?

With the publication of the official CRA Guide in July 2026, the European Commission has clarified numerous issues relating to the practical implementation of the Cyber Resilience Act. The new guidance is particularly relevant for manufacturers of machinery, plant, robotic systems and industrial automation solutions. The Guide confirms a risk-based approach and provides greater legal certainty regarding the handling of existing systems, spare parts, software updates and modernisation projects.
 

What exactly does “placing on the market” mean, and what clarifications are needed in this regard?

Here, the guidance refers to the Blue Guide and also clarifies that the terms ‘placing on the market’ and ‘making available’ are to be understood as referring ‘to each individual productand not to a product type, regardless of whether it was manufactured as a single item or in series.

For standalone software that is made available digitally, the terms within the meaning of Regulation (EU) 2024/2847 are considered to have been placed on the market as soon as its development is complete and it is offered for the first time within the framework of a commercial activity for distribution or use on the EU market.

Since digital software can be reproduced without physical production or storage limits, this initial offer means that a virtually unlimited number of identical copies are considered to be placed on the market simultaneously. Subsequent downloads or accesses are merely considered to be the provision of the same product already placed on the market, even if they occur at different times.

New versions of the software are only considered to be placed on the market again if they constitute a substantial modification. Minor updates or iterations without substantial modification do not require a new conformity assessment and do not change the original date of placing on the market.

This interpretation applies only to standalone software that is digitally provided. It does not apply if:

  • Software is delivered on physical data carriers (e.g. USB stick) or
  • Software is distributed together with hardware as a product.
     

How is CRA applied when hardware and software are combined to form a product?

Regulation (EU) 2024/2847 applies to products with digital elements, i.e. hardware or software products and their remote processing solutions, provided they have a direct or indirect data connection to devices or networks.

The scope of application includes, among other things:

  • Standalone software (e.g. apps or computer programmes)
  • Hardware with embedded software (e.g. IoT devices)
  • Standalone hardware (e.g. chips or motherboards)
  • Combinations of hardware and software, even if they are provided separately

The decisive factor is not how or when software is provided, but whether it is necessary for the intended functions of the product. If a hardware device can only perform its functions in conjunction with specific software, the hardware and software are jointly considered a single product with digital elements.

This also applies if the software is only provided after the hardware has been sold through other channels (e.g. website, app store, download). Examples include device drivers for printers or apps for controlling a fitness tracker, which are necessary for the operation or use of the device.

How does the CRA guidance interpret the term ‘data link’?

Regulation (EU) 2024/2847 applies to products with digital elements if their intended or foreseeable purpose involves a direct or indirect data connection to a device or network.

The definition of the term ‘product with digital elements’ is ultimately based on the definition of the term ‘electronic information system’, i.e. ‘a system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data’ (Article 3(7), CRA). The scope of the CRA is therefore not linked to the mere presence of electronics, but to the ability of a product to exchange digital information.

A data connection within the meaning of the CRA only exists if information can be deliberately digitally encoded (e.g. in binary form) and sent and interpreted as data by a recipient. Pure electrical signals that merely trigger a function (e.g. on/off signals without information transmission) are not considered data connections and therefore do not fall under this aspect of the CRA's scope.
 

How should the CRA be applied to machinery and plant classified as ‘complex systems’ in the guidance?

Regulation (EU) 2024/2847 also applies to ‘complex systems’ consisting of several hardware and software components, provided they are made available on the market as a single product.

The final CRA Guidance devotes a separate chapter to complex systems (Chapter 2.6 ‘Complex systems’, paragraphs 29 to 32). In this chapter, the European Commission expressly acknowledges that industrial machinery, production lines and automation solutions often consist of a multitude of hardware and software components, have long life cycles and are dependent on existing architectures, interfaces and interoperability requirements.

The guidance confirms that such technical constraints may be taken into account. Where certain cybersecurity measures cannot be fully implemented due to technical limitations or existing system architectures, alternative or compensatory measures may be used. The prerequisite remains that the associated risks are documented in a transparent manner and assessed as part of the cybersecurity risk assessment.

Such systems may be difficult to adapt to new security requirements due to long development cycles, existing architectures or necessary interoperability. Nevertheless, they do not automatically fall outside the scope of the CRA. Instead, a risk-based approach applies.

Manufacturers must:

  • carry out a cybersecurity risk evaluation,
  • identify and document technical limitations,
  • implement alternative or compensatory security measures if certain requirements cannot be fully met.

These limitations, risks and measures must be described transparently in the technical documentation and user information and must be reviewed regularly and updated where necessary during the support period.

 

Will older components and existing interfaces become a problem under the CRA?

Many machinery manufacturers use communication protocols, fieldbus systems or control components that have been in use for many years. The final guidance explicitly recognises that modern safety measures cannot always be fully implemented due to interoperability requirements or technical constraints.

In such cases, manufacturers may employ alternative or compensatory protective measures, provided that the risks are documented in a transparent manner as part of the cybersecurity risk assessment. This clarification is of particular practical importance for manufacturers and operators of existing production facilities.
 

How should products that were developed before the CRA came into force be treated?

Products that were developed before Regulation (EU) 2024/2847 came into force may continue to be placed on the market without the need for redesign.

The final CRA Guidance (Chapter 2.7 ‘Products with digital elements designed before the CRA came into force’, paragraphs 33 to 39) provides further clarification on this point. For many machinery manufacturers, this is undoubtedly one of the most important clarifications in the guidance. The European Commission expressly clarifies that products with digital elements that were developed before the CRA came into force do not automatically have to be completely redesigned or re-engineered.

Manufacturers may continue to use existing designs, provided they can demonstrate, on the basis of a cybersecurity risk assessment, that the essential cybersecurity requirements are met. Furthermore, the Commission makes it clear that historical development and test documentation does not necessarily have to be fully reconstructed. Instead, existing evidence and current risk assessments may be used to demonstrate compliance with the requirements of the CRA.

This is subject to the manufacturer:

  • carries out a cybersecurity risk evaluation,
  • demonstrates that the product already incorporates appropriate and effective security measures,
  • and thus meets the essential cybersecurity requirements.

However, even without design changes, all CRA obligations must be complied with, in particular:

  • carrying out a conformity assessment,
  • drawing up the EU Declaration of Conformity,
  • affixing the CE marking,
  • documentation and risk assessment, as well as technical files.

If no original security assessment from the development phase is available, the manufacturer must carry out and document an up-to-date risk evaluation, showing how existing measures mitigate the identified risks. In addition, processes for managing vulnerabilities must be established and the risk assessment must be regularly updated during the support period. 
 

How should a ‘substantial modification’ to products within the scope of the CRA be assessed?

Regulation (EU) 2024/ 2847, Article 3(30), defines a ‘substantial modification’ a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed.

Under the CRA, any person or company is regarded as a manufacturer if they carry out a substantial modification to a product and subsequently make it available on the market.

This applies in particular to:

  • importers or distributors who make a substantial modification to a product,
  • any other natural or legal person who carries out such a modification,
  • modifications to products placed on the market before 11 December 2027, if they are substantially modified thereafter.

Regulation (EU) 2024/2847 distinguishes between “modifications”, “repairs”, “spare parts” and “software updates” to determine whether a substantial modification of a product has taken place.

Physical modifications/repairs

Maintenance, repair or replacement of components does not automatically constitute a substantial modification. The decisive factor is whether:

  • the intended use of the product changes, or
  • the cybersecurity risk increases.

The replacement of defective parts with equivalent or better components is not generally considered a substantial modification, provided that the function and risk remain unchanged.

Spare parts

  • Identical spare parts manufactured to the same specifications do not fall under the CRA.
  • Non-identical spare parts are regarded as separate products and are subject to the CRA.

Nevertheless, their installation does not normally constitute a substantial modification of the original product if the intended use and risk profile remain the same.

The final guide contains much more detailed explanations on the subject of spare parts (Chapter 4.2 ‘Spare parts’, sections 96 to 102).

The European Commission makes it clear that not every technical change automatically leads to a reassessment under the CRA. The decisive factor is, in particular, whether a product’s cyber-relevant characteristics are altered. These include, for example, cryptographic functions, authentication mechanisms, communication protocols or other security-related characteristics.

At the same time, the guide specifies the conditions under which a spare part can still be regarded as ‘identical’. Provided that the function, security profile and intended use remain unchanged, the replacement of a spare part does not, as a rule, give rise to new CRA obligations for the overall system.

Software updates

A software update is regarded as a substantial modification if it:

  • affects compliance with cybersecurity requirements or
  • alters the product’s original intended use or
  • introduces new or increased cybersecurity risks that were not taken into account in the original risk assessment.

Normal security updates or updates that were already anticipated in the original risk assessment are generally not considered a substantial change.

In the mechanical and plant engineering sector in particular, products are modernised, expanded and adapted to new requirements over many years.

The final CRA Guidance (Chapter 4.3 ‘Software updates as substantial modifications’, paragraphs 103 to 112) makes it clear that not every functional enhancement is automatically to be classified as a substantial modification. Rather, the decisive factor is whether the original intended use has changed or whether new or increased cybersecurity risks have arisen.

The European Commission cites the transition from a purely monitoring solution to an actively controlling solution as an example. This clarification provides additional legal certainty, particularly for retrofit projects.
 

What are the consequences of a substantial modification to a product?

If a substantial change is made:

  • the product is regarded as being placed on the market for the first time,
  • the natural or legal person making the change is regarded as the manufacturer,
  • a new conformity assessment in accordance with the CRA is required

With regard to documentation following a substantial change, reference is made to section 2.1 of the Blue Guide, which clarifies that the technical documentation must be updated where the change affects the requirements of the applicable legislation. It is not necessary to repeat tests or draw up new documentation relating to aspects that are not affected by the change. It is the responsibility of the natural or legal person who makes, or has made, the changes to the product to demonstrate that not all elements of the technical documentation need to be updated. The natural or legal person who makes, or has made, the changes to the product is responsible for the conformity of the modified product and must issue a declaration of conformity, even if they use existing tests and technical files.

Products placed on the market before 11 December 2027 are only subject to the CRA if they are substantially modified and placed on the market after that date.

The final CRA Guidance provides important clarity on this point (Chapters 4.4.1 and 4.4.2 ‘Consequences of a substantial modification’, paragraphs 117 to 124).

Even where a substantial modification has taken place, the entire product does not necessarily have to be re-assessed. Provided that the modification does not adversely affect the cybersecurity of the overall system and can be clearly delineated, the CRA obligations may be limited to the modified components and functions.

This clarification is of particular practical relevance for retrofit projects and the retrofitting of industrial machinery and plants.
 

How long will machinery manufacturers be required to provide security updates in future?

The guidance explicitly states that the frequently cited five-year period represents merely the statutory minimum requirement – in other words, the lower limit. It should not be regarded as a standard value or the norm for all products. Rather, the manufacturer must determine the support period on the basis of the product’s actual expected useful life (‘expected use time’). For products that are expected to be used for longer than five years, a significantly longer support period may therefore be required. (Chapter 5 ‘Support period’, sections 125–126). 

When determining the support period, manufacturers must take the following factors into account in particular:

  • the user expectations that can reasonably be anticipated regarding the product’s service life 
  • the nature and intended use of the product 
  • relevant European legislation affecting the service life of certain products 
  • the availability of the necessary operating and system environment 
  • the support periods for safety-critical integrated components 
  • comparable market practices for similar products 
  • future guidelines from the European Commission and market surveillance authorities (Chapter 5, Section 125 and footnote 17). 

This clarification is of particular importance for the mechanical and plant engineering sectors. Whilst a support period of five years may be appropriate for certain software products or consumer devices, industrial plant, production machinery, robotic systems or automation solutions are often used for ten, fifteen or even twenty years. Manufacturers should therefore assess at an early stage whether their service, patch and vulnerability management processes are suitable for providing security updates throughout the product’s actual expected life cycle. The European Commission makes it explicitly clear that products with an expected useful life of more than five years should, as a general rule, also be supported for a correspondingly longer period. (Chapter 5, Sections 125–126).
 

Does a substantial modification automatically extend the CRA support period?

This frequently asked question is explicitly addressed for the first time in the final guide. A ‘substantial modification’ does not automatically result in a restart or extension of the support period. Rather, it must be assessed whether the modification alters the original assumptions regarding the product’s expected useful life. Only then may an adjustment to the support period be required. (Chapter 5.1 ‘Substantial modifications and the support period’, paragraphs 132 to 135).
 

Product note

Safexpert 9.1 - The CE software already supports the new Machinery Regulation (EU) 2023/1230


Since version 9.1, Safexpert has been providing you with targeted support when switching to the new Machinery Regulation (EU) 2023/1230. For machines with a long service life that are placed on the market from 20 January 2027, you can now use the CE guide in accordance with the new Machinery Regulation!

Conclusion

The guidance on Regulation (EU) 2024/2847 clarifies key terms and use cases under the Regulation and provides manufacturers of machinery, plant and electrical equipment with important guidance on the practical implementation of the new cybersecurity requirements. 

A key aspect is the clarification of when a product is deemed to have been placed on the market and which products actually fall within the scope of the CRA. The decisive factor is not merely the presence of electronic components, but a product’s ability to process or exchange digital data. Combinations of hardware and software are also considered to be a product with digital elements if both are necessary for the product’s functionality. 

The guidance also makes it clear that the CRA follows a risk-based approach. Manufacturers must assess and document cybersecurity risks throughout a product’s entire life cycle and implement appropriate protective measures. This also applies to complex systems such as machinery or industrial installations, where technical constraints, existing interfaces, legacy components or interoperability requirements may be taken into account. The final guidance expressly confirms that, in such cases, alternative or compensatory protective measures are permissible, provided that the risks are assessed and documented in a transparent manner. 

For products developed prior to the CRA, there is generally no obligation to redesign them. The European Commission clarifies in the final guidance that existing machine platforms may continue to be used, provided that manufacturers can demonstrate, through an up-to-date cybersecurity risk assessment, that the essential requirements are met. The guidance thus provides additional planning certainty for manufacturers with product families that have been established for many years. 

The concept of ‘substantial modification’ is also of particular importance. Only changes that alter a product’s intended use or introduce new or increased cybersecurity risks result in a product being regarded as newly placed on the market and requiring a new conformity assessment. Maintenance, repairs, identical spare parts or purely security-related updates do not, as a rule, lead to such a classification. The final guidance also provides clarity for retrofit projects and modernisations, as not every functional enhancement automatically constitutes a substantial change. 

The requirements regarding the support period have also been clarified. The frequently cited five-year period merely represents the statutory minimum requirement. Manufacturers must instead take into account the expected service life of the product. For machinery, plant, robotic systems and industrial automation solutions, this may result in significantly longer obligations to provide security updates and manage vulnerabilities. 

Overall, the final CRA Guidance shows that the CRA not only defines new security requirements but also establishes specific rules for software updates, product changes, technical documentation, support periods and responsibilities throughout the entire product lifecycle. For manufacturers, this means, above all, systematically integrating cybersecurity into development, change, service and support processes, and maintaining transparent records of the relevant evidence in the technical documentation.
 

Download of the guide

You can open and download the CRA guidance by clicking on the following link:


CRA Guidance


Posted on: 2026-08-05 (Last amendment)

Authors

Hendrik Stupin

Trained technical editor (tekom-certified) and certified CE coordinator. Previously 11 years of experience in technical communication and as a CE coordinator in the field of mechanical and plant engineering, specialising in ‘Engineered to Order (ETO)’ products.

E-Mail: hendrik.stupin@ibf-solutions.com| www.ibf-solutions.com

 

Wolfgang Reich
CE marking and safety expert HTL electrical engineering, specialising in power engineering (Dipl.-HTL-Ing.),  20 years of experience in CE marking, machine safety, conversion of machines, electrical engineering and explosion protection, 10 years of which at TÜV Austria and Intertek Deutschland GmbH. Chairman of the master craftsman examination commission in the Styrian Chamber of Commerce for mechatronics (automation technology and electronics).

E-Mail: wolfgang.reich@ibf-solutions.com


Share Article
Share Button Linkedin Share Button Xing Share Button X Share Button Email

Support by IBF

CE Software Safexpert

CE software for systematic and professional safety engineering

Seminars

Practical seminars on aspects of risk assessment and ce marking

Stay Up-to-Date!

With the CE InfoService you stay informed about important developments in the field of product safety.