← Insights

    Cybersecurity roadmap for machine and plant builders: what has to be ready by when

    In brief

    Three cut-off dates structure the work: 11 Sep 2026 (CRA reporting obligation, including systems already in the field), 20 Jan 2027 (Machinery Regulation) and 11 Dec 2027 (CRA in full, CE marking). Reporting comes first. Three things have to be in place by then: a register of the systems shipped with their firmware versions, a named responsibility that can actually be reached, and one channel where supplier advisories converge. The Machinery Regulation risk assessment, SBOM capture as a standard step and technical documentation build on that.

    „I don't even know yet what I need, or by when." That sentence comes up in almost every first conversation with a machine or plant builder. The deadlines themselves are usually known; the three dates appear in every industry association circular. What is unclear is the inverse – what has to be finished in-house, and by when, for those dates to be met. No regulation provides that mapping, because it depends on where the individual company starts from.

    This article sets out the roadmap: for each cut-off date, the work packages that must be completed before it. The legal groundwork – when a plant builder becomes a manufacturer at all, how the CRA and the Machinery Regulation interlock – is covered in the article on the CRA and the Machinery Regulation.

    The roadmap: what has to be ready by when

    The three dates sit closer together than the years suggest. For each one, the timeline below shows what applies from then on, on what basis, and what has to be finished in-house before that:

    Today
    11 Sep 2026first deadline
    What appliesCRA reporting obligation under Art. 14: actively exploited vulnerabilities within 24 h (early warning), 72 h (notification) and 14 days (final report) to the CSIRT and ENISA – including systems already in the field.Basis: CRA, Art. 14
    Ready by then
    Installation register: which shipped system contains which component at which firmware version
    Named responsibility that can be reached – the 24-hour clock runs over public holidays too
    One channel where all supplier advisories arrive – inbox, ticket queue or tool
    Internal reporting form and one dry run of a real case
    20 Jan 2027just over 4 months later
    What appliesThe EU Machinery Regulation becomes mandatory. New machinery requires a traceable risk assessment of safety-relevant cybersecurity.Basis: Regulation (EU) 2023/1230
    Ready by then
    Cyber risk assessment as a fixed step in the design process, not an annex at the end of the project
    Evidence for Annex III 1.1.9 and 1.2.1: protecting control systems and software against corruption
    Tamper-evident logging of safety-relevant interventions for at least five years
    Interfaces and remote access documented per product line
    11 Dec 2027almost 11 months later
    What appliesCRA fully applicable: CE marking, technical documentation, declaration of conformity and all product and vulnerability-handling obligations.Basis: CRA, full application
    Ready by then
    SBOM capture at factory acceptance belongs to the standard scope of every project
    Framework contracts guarantee a machine-readable CSAF or VEX per release within a defined period
    Support period defined per system and communicated to the operator
    Patch delivery governed by the service contract, including effort and remuneration
    CRA and Machinery Regulation roadmap for machine and plant builders.

    The 2026 reporting duty is the hardest deadline, not the 2027 CE duty

    The reporting obligation takes effect more than a year before the CE obligation, and it covers systems that are running today. For the installed base there is no cut-off rule of the kind earlier regulations provided. Anyone planning towards 11 December 2027 has already missed the first date.

    The length of the deadlines makes this harder still. Twenty-four hours is not a window in which responsibilities can be clarified, an installation register assembled or a reporting channel found for the first time. Those things have to exist beforehand, or the deadline expires while the company is still working out who is in charge. What exactly has to be reported – and what expressly does not – is covered in the article on the reporting obligation and the ENISA reporting platform.

    What the Machinery Regulation additionally requires

    The Machinery Regulation is regularly overlooked in the CRA discussion, even though its date falls between the two CRA deadlines. It treats cybersecurity as a safety question: Annex III requires that control systems and software cannot be corrupted in a way that causes a safety function to fail.

    Two differences to the CRA follow from that. The threshold shifts: a residual risk that would be acceptable under the CRA has to be eliminated by design under the Machinery Regulation as soon as it could defeat a safety function. And one Machinery Regulation duty has no CRA counterpart at all – tamper-evident logging of safety-relevant interventions such as firmware updates and configuration changes for at least five years. Discovering that requirement during the conformity procedure means reworking the system architecture after the fact.

    Installation register first, then reporting capability, then documentation

    The three blocks in the roadmap build on one another. The foundation is the mapping of which system contains which component at which version. Without it a supplier advisory cannot be projected onto the installed base – all that remains is the statement that a product might be affected, not that a particular installation is. That satisfies neither the report nor the technical documentation.

    This mapping is also the item with the longest lead time, because it cannot be procured, only recorded: system by system, at acceptance tests and service visits. It therefore has to start first, even though it cannot be completed within weeks. The short-term items – a named responsibility and the supplier list – run alongside it. How that data comes about when there is no source code and no supplier SBOM is described in the article on creating an SBOM in plant engineering. The practical entry point is small: add a scan step to the next scheduled acceptance test. Every system that leaves the works before then without a recorded as-delivered state is one more reconstruction case.

    Four questions from practice

    Where to start when none of this exists in-house?

    With recording the installation register, starting at the next acceptance test. Because that recording runs for months, two short-term items belong alongside it: a named responsibility that can be reached, and a list of direct suppliers together with the question of where their security advisories are published. Both can be done in weeks, independently of how good the master data is, and both are prerequisites for the September date as well. A concept covering the entire installed base does not work as an entry point.

    Does a system from 2019 still count?

    For the reporting obligation, yes – as long as it is within its support period and the plant builder placed it on the market under its own name. For CE marking and technical documentation, no: those apply to systems placed on the market from 11 December 2027. When a modification amounts to a substantial modification and thereby brings the system back into scope is covered in the article on the manufacturer role.

    How much effort is this realistically?

    Mapping systems to component versions costs a one-off recording effort; after that, the ongoing comparison against supplier advisories is routine. The mistake to avoid is conducting one's own deep analysis of purchased firmware – that is neither feasible nor necessary, because the only lever is the supplier's firmware release anyway.

    What if the dates cannot be met?

    Then reporting capability takes priority. Full implementation by September 2026 is unrealistic for many companies. A company that knows which systems may be affected and has a reporting channel can still meet the deadline while the SBOM and technical documentation are unfinished.

    Where a company stands on this timeline depends above all on how well the as-delivered state of the systems shipped so far is documented. Clarify in a call where your company stands on this timeline.

    Werkspilot monitors supplier advisories automatically and matches them against the field baseline of plant builders and integrators. This article reflects Werkspilot's assessment and does not constitute legal advice.