Insights
CRA, the Machinery Regulation and vulnerability management for machine and plant builders and integrators.
Cybersecurity risk assessment under the CRA and the Machinery Regulation: what belongs in it – with an example
The CRA and the EU Machinery Regulation both require a documented cybersecurity risk assessment – the CRA for the product as a whole, the Machinery Regulation for the safety-relevant side. How both deliverables come out of one STRIDE threat analysis per system type, worked through on a packaging machine with remote access – with a template available on request.
SBOM tools for plant builders: capturing the bill of materials, the engineering project and the network scan
The common SBOM tools need a build – in plant engineering there is none. Which tools cover the three realistic routes: exports from ERP and EPLAN, the hardware export from the engineering system, scanning tools from PRONETA to OTbase – with a comparison of when which scanning tool is the right one.
Placing on the market in plant engineering: which date decides CRA applicability
A plant ships in partial deliveries across two years – so when is it placed on the market? What the CRA actually says, why the final delivery milestone gets used as the cut-off, and where that practice does not hold.
Cybersecurity roadmap for machine and plant builders: what has to be ready by when
The CRA and Machinery Regulation deadlines are well known – the roadmap behind them is not. What actually has to be finished by 11 Sep 2026, 20 Jan 2027 and 11 Dec 2027, in the order in which each step depends on the previous one.
Creating an SBOM in special machinery and plant engineering: where the data comes from when there is no source code
Every guide to creating an SBOM assumes your own build – a plant builder does not have one. The workable sources are the bill-of-materials export, the engineering project and a network scan at acceptance testing. What each source provides, what none can do alone, which depth the SBOM needs – and when in the project this has to happen.
CRA reporting obligation from September 2026: What must be reported for machines and plants?
On 11 September 2026 the Cyber Resilience Act's reporting obligations take effect – more than a year before the rest of the CRA. What must be reported (and what not), which deadlines apply, how ENISA's Single Reporting Platform (SRP) works, and what can be prepared today.
CRA tool selection for plant builders: four questions and one test for the demo
Most vulnerability tools are built for software vendors. In plant engineering the risk sits in third-party firmware from dozens of suppliers. Four selection questions as a checklist, a demo test, and why CPE matching does not carry.
When a plant builder or integrator becomes a CRA manufacturer
Cyber Resilience Act: when a plant builder or integrator becomes the manufacturer through system integration – placing on the market, substantial modification (Art. 22) and the layered model of supplier obligations.
CRA and the Machinery Regulation for integrators and plant builders: what applies from 2026
The Cyber Resilience Act and the EU Machinery Regulation for integrators and plant builders – deadlines, obligations and how to set up vulnerability management across the supply chain.
