Share Article
The Cyber Resilience Act (EU) 2024/2847 was published in the Official Journal of the European Union on 20 November 2024. As previously reported in our technical article on the new Cyber Resilience Act, the new regulation sets out security requirements for products. These requirements can sometimes be difficult to understand for those without prior knowledge of IT or OT security. The German Federal Office for Information Security (BSI) is offering support through a publication. In this technical article, you will find an overview of the sections of the technical guideline.
The aim of the technical guideline “TR-03183: Cyber Resilience Requirements for Manufacturers and Products’ is to provide manufacturers with advance insight into the nature of the requirements they will face under the Cyber Resilience Act (CRA). This will enable manufacturers of products containing digital elements to prepare for the implementation of Regulation 2024/2847 even before the CRA comes into force.
The first part, which sets out and explains in detail the wide range of requirements for manufacturers under the Cyber Resilience Act, was published on 31 July 2026 as a living document in version 1.0.0.
Fundamental requirements for manufacturers and products can be identified from the first part of the technical regulation in particular:
In summary, the requirements aim to ensure that products are developed securely and continuously updated to withstand potential cyber threats and keep users safe.
Download BSI TR-03183-1 (Version 1.0.0)
You can open and download version 1.0.0 of BSI TR-03183-1: Cyber Resilience Requirements – Part 1: General requirements via the following link.
BSI TR-03183-1
Further parts of the Directive
Part 2 (Software Bill of Materials – SBOM) describes what the CRA's requirements regarding the verification of software supply chains might look like. The final version of part 2 was published in a new edition in September 2024.
Part 3, entitled ‘Vulnerability Reports and Notifications’, provides recommendations on how to deal with incoming vulnerability reports and was made available by the BSI in its first final edition at the end of August 2025.
The full texts of the two technical guidelines can be accessed via the respective links:
Part 2: Software Bill of Materials (SBOM)
Part 3: Vulnerability Reports and Notifications
Conclusion and further information
In our view, the BSI’s work makes a very valuable contribution to making the cyber security requirements for manufacturers of machinery, plant and electrical equipment much more tangible. You can find further information on the BSI’s website.
Posted on: 2026-08-11 (last amendment)
Johannes Windeler-Frick, MSc ETH Member of the IBF management board. Specialist in CE marking and Safexpert. Presentations, podcasts and publications on various CE topics, in particular CE organisation and efficient CE management. Management of the further development of the Safexpert software system. Degree in electrical engineering from ETH Zurich (MSc) with a focus on energy technology and specialisation in the field of machine tools.
Email: johannes.windeler-frick@ibf-solutions.com | www.ibf-solutions.com
CE software for systematic and professional safety engineering
Practical seminars on aspects of risk assessment and ce marking
With the CE InfoService you stay informed about important developments in the field of product safety.