Technical article

Technical Guideline for Cyber Resilience Requirements

BSI TR-03183: Requirements of the Cyber Resilience Act for manufacturers


Share Article
Share Button Linkedin Share Button Xing Share Button X Share Button Email

The Cyber Resilience Act (EU) 2024/2847 was published in the Official Journal of the European Union on 20 November 2024. As previously reported in our technical article on the new Cyber Resilience Act, the new regulation sets out security requirements for products. These requirements can sometimes be difficult to understand for those without prior knowledge of IT or OT security. The German Federal Office for Information Security (BSI) is offering support through a publication. In this technical article, you will find an overview of the sections of the technical guideline.

The aim of the technical guideline “TR-03183: Cyber Resilience Requirements for Manufacturers and Products’ is to provide manufacturers with advance insight into the nature of the requirements they will face under the Cyber Resilience Act (CRA). This will enable manufacturers of products containing digital elements to prepare for the implementation of Regulation 2024/2847 even before the CRA comes into force.

Requirements of the first part, ‘General Requirements’

The first part, which sets out and explains in detail the wide range of requirements for manufacturers under the Cyber Resilience Act, was published on 31 July 2026 as a living document in version 1.0.0.

Fundamental requirements for manufacturers and products can be identified from the first part of the technical regulation in particular:

  1. Security design: Products with digital elements must be developed, produced and updated securely. Manufacturers are obliged to implement best practices in the software development cycle and ensure security requirements such as the protection of data confidentiality and integrity.
  2. Risk assessment: Manufacturers must conduct a risk analysis over the entire life cycle of the product to identify potential threats and their impact. This analysis must be documented and regularly updated.
  3. Security updates: Products must receive regular security updates to fix vulnerabilities. Manufacturers are obliged to provide an automatic update mechanism that is activated by default. In addition, users must be informed of available updates and be able to postpone updates temporarily.
  4. Access control: Measures must be implemented to protect against unauthorised access, including strong authentication mechanisms and the ability to set individual passwords.
  5. Vulnerability management: Manufacturers must operate a system to identify, assess and remediate vulnerabilities. They must inform users of any security vulnerabilities that are discovered and provide updates in a timely manner.
  6. Documentation: Comprehensive technical documentation is required, including information on design, development processes and security risks. This documentation should also include details of tests performed and components supported.

In summary, the requirements aim to ensure that products are developed securely and continuously updated to withstand potential cyber threats and keep users safe.
 

Download BSI TR-03183-1 (Version 1.0.0)

You can open and download version 1.0.0 of BSI TR-03183-1: Cyber Resilience Requirements – Part 1: General requirements via the following link.


BSI TR-03183-1


Further parts of the Directive

Part 2 (Software Bill of Materials – SBOM) describes what the CRA's requirements regarding the verification of software supply chains might look like. The final version of part 2 was published in a new edition in September 2024.

Part 3, entitled ‘Vulnerability Reports and Notifications’, provides recommendations on how to deal with incoming vulnerability reports and was made available by the BSI in its first final edition at the end of August 2025.

The full texts of the two technical guidelines can be accessed via the respective links:

Conclusion and further information

In our view, the BSI’s work makes a very valuable contribution to making the cyber security requirements for manufacturers of machinery, plant and electrical equipment much more tangible. You can find further information on the BSI’s website.


Posted on: 2026-08-11 (last amendment)

 

Author

Johannes Windeler-Frick, MSc ETH
Member of the IBF management board. Specialist in CE marking and Safexpert. Presentations, podcasts and publications on various CE topics, in particular CE organisation and efficient CE management. Management of the further development of the Safexpert software system. Degree in electrical engineering from ETH Zurich (MSc) with a focus on energy technology and specialisation in the field of machine tools.

Email: johannes.windeler-frick@ibf-solutions.com | www.ibf-solutions.com

 


Share Article
Share Button Linkedin Share Button Xing Share Button X Share Button Email

Support by IBF

CE Software Safexpert

CE software for systematic and professional safety engineering

Seminars

Practical seminars on aspects of risk assessment and ce marking

Stay Up-to-Date!

With the CE InfoService you stay informed about important developments in the field of product safety.