Back to Publications
Regulatory Brief · CRA

Manufacturing under CRA and Machinery Regulation 2023/1230: double conformity

17 May 2026By NexCyber Editorial CRA

As the European Union continues to bolster its regulatory framework for cybersecurity and safety, manufacturers of industrial machines with digital control systems face a dual challenge. From January 2027, any connected CNC machine sold within the EU must adhere to two distinct CE conformity tracks: one under the Cyber Resilience Act (CRA) and the other under the updated Machinery Regulation 2023/1230. This dual conformity requirement necessitates a comprehensive understanding of both regulatory

As the European Union continues to bolster its regulatory framework for cybersecurity and safety, manufacturers of industrial machines with digital control systems face a dual challenge. From January 2027, any connected CNC machine sold within the EU must adhere to two distinct CE conformity tracks: one under the Cyber Resilience Act (CRA) and the other under the updated Machinery Regulation 2023/1230. This dual conformity requirement necessitates a comprehensive understanding of both regulatory landscapes to ensure compliance and maintain market access.

The Scope of the CRA for Machinery: Products with Digital Elements

The Cyber Resilience Act (CRA) aims to enhance the cybersecurity of products with digital elements sold within the EU. For manufacturers of industrial machinery, this means that any machine incorporating digital components, such as connected CNC machines, falls within the scope of the CRA. The CRA mandates that these products meet specific cybersecurity requirements to ensure they are secure by design and default.

Key CRA Requirements

Under the CRA, manufacturers must ensure that their products are designed to withstand cyber threats throughout their lifecycle. This includes implementing secure software development practices, conducting regular security testing, and providing timely security updates. The CRA also requires manufacturers to maintain a vulnerability disclosure policy, enabling the identification and remediation of potential security flaws.

Impact on Manufacturing

For industrial machinery manufacturers, the CRA introduces additional layers of complexity in product development and lifecycle management. Compliance with the CRA not only requires technical adjustments but also necessitates organizational changes to accommodate new processes for cybersecurity risk management and incident response.

Cybersecurity in Machinery Regulation 2023/1230

The updated Machinery Regulation 2023/1230 introduces specific provisions aimed at enhancing the safety and cybersecurity of machinery. While traditionally focused on physical safety, the regulation now explicitly addresses the cybersecurity risks associated with machinery that incorporates digital controls.

Cybersecurity Provisions

The Machinery Regulation 2023/1230 requires manufacturers to conduct a risk assessment that includes cybersecurity considerations. This involves identifying potential cyber threats that could impact the safety of the machinery and implementing measures to mitigate these risks. The regulation emphasizes the need for secure communication protocols, access control mechanisms, and regular software updates to maintain the safety and integrity of the machinery.

Harmonization with CRA

The cybersecurity provisions in the Machinery Regulation align with the requirements of the CRA, creating a cohesive framework for manufacturers to follow. This alignment simplifies the compliance process by providing a unified set of standards for cybersecurity across both regulatory domains.

Combined Assessment Flow: Who Issues What, and in What Sequence

Navigating the dual conformity requirements under the CRA and Machinery Regulation 2023/1230 requires a clear understanding of the conformity assessment process. Manufacturers must engage with notified bodies and other relevant entities to ensure that their products meet the necessary standards.

Conformity Assessment Process

  1. 1Initial Risk Assessment: Manufacturers must conduct a comprehensive risk assessment that addresses both cybersecurity and physical safety risks. This assessment forms the basis for the subsequent conformity evaluation.
  1. 1Cyber Resilience Act Compliance: Under the CRA, manufacturers must demonstrate compliance with cybersecurity requirements. This involves submitting technical documentation and evidence of security measures to a notified body or an equivalent entity for evaluation.
  1. 1Machinery Regulation Compliance: Simultaneously, manufacturers must ensure that their machinery complies with the safety and cybersecurity provisions of the Machinery Regulation 2023/1230. This may involve additional testing and documentation to verify that the machinery meets the required safety standards.
  1. 1Issuance of CE Marking: Upon successful completion of the conformity assessments, manufacturers can affix the CE marking to their products. This marking signifies compliance with both the CRA and Machinery Regulation, allowing the machinery to be marketed within the EU.

Sequence and Coordination

The sequence of assessments is critical to avoid delays and ensure timely market access. Manufacturers should coordinate the assessments to run concurrently, leveraging synergies between the CRA and Machinery Regulation requirements. Engaging with experienced conformity assessment bodies early in the process can facilitate smoother navigation through the regulatory landscape.

Next Step with NexCyber: Dual-Conformity Readiness for Industrial Manufacturers

Navigating the dual conformity requirements of the CRA and Machinery Regulation 2023/1230 is a complex task that demands specialized expertise. NexCyber offers tailored solutions to help industrial manufacturers achieve compliance with both regulatory frameworks. Our platform provides comprehensive assessment tools, expert guidance, and support throughout the conformity process, ensuring that your products meet the highest standards of cybersecurity and safety.

Explore how NexCyber can streamline your dual-conformity journey by visiting [NexCyber's Dual-Conformity Readiness](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=manufacturing-cra-machinery-regulation-double-conformity).