When a plant builder or integrator becomes a CRA manufacturer
In brief · As of June 2026
Under the Cyber Resilience Act (CRA), a plant builder or integrator becomes the manufacturer as soon as a system is placed on the market under their own name (Art. 3(13)) – or an existing installation is substantially modified (Art. 22). What matters is not the technical novelty of the integration, but a simple question: is a defined machine, line or system delivered under one's own nameplate and declaration of conformity? With the manufacturer role comes full responsibility for the vulnerability management of the overall product – bounded by a layered model in which the bought-in components keep their own manufacturers.
Many plant builders consider the Cyber Resilience Act (CRA) not to apply to them because they build machines rather than develop software. The CRA, however, measures its obligations against a regulatory role – that of the manufacturer – regardless of how much a company develops itself. The real question is therefore when a company that primarily integrates grows into that role.
The CRA ties the obligations to the manufacturer role
A manufacturer within the meaning of the CRA is anyone who places a product with digital elements on the market under their own name or trademark (Art. 3(13)). Integrators regularly fall into this role, because combining individual components into a delivered system is precisely this act. Whoever places a product on the market under their own name is the manufacturer and therefore affixes the CE marking and signs the declaration of conformity; the CE marking follows from the manufacturer role.
For the classification, the technical novelty of the integration is irrelevant. The common argument that one „only puts together a PLC with sensors and actuators" changes nothing: as soon as the result is delivered as one's own machine under one's own name, it is a CRA product of the plant builder. What matters is a simple, practical question – is a defined machine, line or system delivered under one's own nameplate and declaration of conformity? Anyone who already signs a declaration of conformity for the overall system, for instance as the manufacturer of an „assembly of machinery" under the Machinery Regulation, has already assumed the manufacturer role for that product. Where the system contains digital elements, the CRA obligations are added to those that already apply to that role.
The Commission's guidelines, adopted in July 2026, confirm this reading explicitly: anyone who assembles components into a new product with digital elements and places it on the market under their own name is not modifying someone else's product but placing a new one of their own on the market – and must comply with the CRA for the product as a whole. They may rely on the compliance activities of the component manufacturers in doing so (para. 120, Example 51).
Substantial modification as a second trigger
Besides the initial placing on the market, an intervention in an existing installation can also trigger the manufacturer obligations. A substantial modification (Art. 22) means the modified product is treated, in regulatory terms, like a new one. The distinction follows a comprehensible pattern:
- A pure security bugfix is generally not a substantial modification – it restores the original security state.
- A new function or a clearly enlarged attack surface, by contrast, tends to be substantial.
- Whether the threshold is crossed depends on the individual case and is to be assessed by reference to the effect on cybersecurity, not as a blanket rule.
One-offs and custom builds do not change the obligation
A widespread misconception is that one-offs or custom builds are exempt. They are not: the manufacturer obligation applies per product, not only above a certain unit count. Even a one-off special line is a product with digital elements placed on the market. The consequence is the full manufacturer obligations for the overall product, including the bought-in third-party and open-source components.
The boundary runs along placing on the market and putting into service
There is, nonetheless, a boundary. Anyone who, as a pure installer, merely wires up individually CE-marked devices at the customer's site without combining them into their own product delivered under their name is not the manufacturer of a new product. This boundary runs along the concepts of placing on the market and putting into service. In reality, however, it becomes blurred above all for very large complete installations erected only on the customer's premises. According to the Commission's guidelines, adopted in July 2026, complex systems do not automatically fall outside the scope either, but must be assessed on a risk basis. For a defined machine or a delimited line, the installer caveat therefore does not apply.
Helpful here is the example, cited by the European Commission, of a food-packaging machine: it can be both a machine within the meaning of the Machinery Regulation and a product with digital elements within the meaning of the CRA. Both sets of requirements then have to be assessed, and both conformity assessments carried out separately; satisfying one does not replace the other.
The layered model bounds your own effort
The manufacturer role does not imply that every third-party component must be analysed in detail oneself. The CRA is designed as a layered model: every CRA-regulated component has its own manufacturer who is liable for its advisories and updates. The integrator may rely on their CE marking and vendor advisories; the duty of care during integration remains (Art. 13(5)). What stays with the plant builder is responsibility for the product in its entirety: vulnerability management and the declaration of conformity for the overall system rest with them (Art. 13(1)), including all integrated components.
For plant builders, this layering means in practice that the effort can be kept proportionate: instead of conducting one's own deep analyses, it is enough to rely on the curated advisories of the direct suppliers, secure these contractually, map them onto one's own system and assess only the integration delta. The real work then lies in collecting the supplier information – a problem that arises above all with suppliers without machine-readable CSAF.
For plant builders, the manufacturer role means these obligations in concrete terms
With the classification as manufacturer, the CRA's catalogue of obligations becomes applicable. For planning, the following points are particularly relevant:
- Continuous vulnerability management across the entire support period, not only at the time of placing on the market.
- 24-hour reporting obligation for actively exploited vulnerabilities to ENISA – from 11 September 2026 and expressly also for existing installations.
- An SBOM (software bill of materials) with CVE-capable component IDs as the basis for matching.
- Technical documentation, CE marking and declaration of conformity, fully applicable from 11 December 2027.
The time-critical first step is therefore robust supplier monitoring – covered in detail in the guide to the CRA and the Machinery Regulation for plant builders.
Werkspilot automates exactly this part: continuously capturing supplier vulnerabilities from CSAF to email, matching them against the installations in the field and meeting the CRA reporting obligation across the entire supply chain on time. Clarify in a call from when the CRA affects your installations.
This article summarises the state of the regulation at the time of publication and does not constitute legal advice. The regulatory texts themselves are authoritative.
