June 24, 2026
5 MIN.
CRA Update for Machine Manufacturers: What’s Due Now

In our article from June 2025, we described what the Cyber Resilience Act (CRA) requires of manufacturers, and recommended three measures to make use of the transition period. A year later, the pressure to act has become tangible. The first deadlines are no longer abstract, they are now.
This article on the CRA update focuses specifically on machine manufacturers. For machine OEMs, there is a different calculation at play, one that often gets lost in the general CRA discourse.
Two dates that count
September 11, 2026
In ~80 daysReporting obligations begin (Art. 14 CRA)
Manufacturers must report exploited vulnerabilities and severe security incidents to ENISA and the national CSIRT within 24 hours and communicate a complete analysis and risk mitigation within 72 hours. Now required: clear criteria, processing channels, and responsibilities – including on public holidays.
December 11, 2027
18 monthsFull CRA compliance
CE marking, compliant products, completed conformity assessment. Eighteen months sounds comfortable – for machine manufacturers with multiple product generations in scope, they are tight. Security-by-design cannot be retrofitted.
Why machine manufacturers face a different calculation
Manufacturers of consumer products are already familiar with many of the procedural CRA obligations: reporting channels, recall structures, and market surveillance are established through the General Product Safety Regulation (GPSR). For pure B2B manufacturers, this is new territory; defined reporting processes, accountability to authorities, and documented response chains must be built from scratch.
The second difference carries more weight: the CRA requires manufacturers to supply their products with security updates throughout the entire expected support period (Art. 13(8) CRA). Industrial machines run for decades: according to German AfA tables, the tax-based use for special-purpose machinery is up to 13 years, with actual operational lifespans often exceeding this. A machine placed on the market today must therefore receive security patches for well over a decade, for every software version that is running in the field.
The three concrete drivers for action

Market access – an existential board-level decision
From December 2027, machines without CRA-compliant CE marking will have no access to the EU market. This is not a compliance question – it is a strategic decision at board level. Violations can cost up to 15 million euros or 2.5 percent of global annual revenue.

Retrofit revenue – blocked without compliance
Machine manufacturers don’t live on new business alone. Service updates, feature expansions, and retrofits for existing customers are a significant revenue stream. Material changes to installed machines will require a fully CRA-compliant product going forward. Failing to ensure this blocks your own retrofit channel – and with it, a central source of revenue.

Engineering capacity – patch debt vs. roadmap
Dozens of active software versions run in parallel in the field. Critical vulnerabilities must be assessed, prioritized, and resolved without delay. For engineering teams simultaneously driving product development, this is a structural resource conflict. Estimates suggest an additional 10–20 percent of annual development budget across the entire lifecycle.
A different model is possible
The question we hear increasingly often from development managers in mechanical engineering: How can CRA compliance be implemented without redirecting the entire engineering capacity toward security?
The answer lies in a different architecture: a security component delivered as an inseparable part of the machine, taking over full vulnerability management, while leaving the machine software untouched. With edge.PSL, TRIOVEGA has developed precisely this approach, as a Protective Security Layer for machine manufacturers. What this means in practice and how the model works will be covered in the next article in this series.
Taking the first step now
Don’t want to wait for the next article? If you want to know now how edge.PSL makes your machines CRA-compliant – without any changes to your machine software – book a consultation call with us. We’ll address your open questions and explore together what a deployment could look like for you.
By the way: for plant operators. the other side of the supply chain, we address the security question with edge.SHIELDOR.
For more on the CRA and the requirements for connected products, see our earlier articles: Cyber Resilience Act – new challenges in the development of connected products and Mastering CRA compliance: How industry is demonstrating strength now. If you’d like to know where your company stands today, schedule a consultation call with our team.

Author: Dr. Madline Kniebusch
Madline Kniebusch has been working as a Data Scientist at TRIOVEGA GmbH since 2021, brings experience from project management, and has been responsible for the implementation of the Cyber Resilience Act since 2026.
You want to know more about our products
and solutions?
edge.SHIELDOR
Holistic OT security for industrial plants that enables data connectivity and sustainably reduces costs
service.factoryINSIGHTS
Discover potential and optimize production processes effectively with our data science expertise
This might also interest you:
- CRA Update for Machine Manufacturers: What’s Due NowThe first CRA deadlines are no longer abstract – they are now. Why machine manufacturers face a different calculation, and which three drivers for action matter most.
- NIS 2 Directive – Update: The reality check – What you need to do from April 2026Companies that take a structured approach will gain an edge over the many still hesitating.
- IEC 62443 – Systematic industrial cybersecurityTRIOVEGA is certified according to IEC 62443. How the norm makes industrial software components more secure, and helps customers with compliance.






