Hi Dirk-Willem,
This was actually an interesting point during the CRA negotiations, and I think the machinery case is particularly interesting in this context.
The Commission has already used Article 2(5) of the CRA in the vehicle sector through Commission Delegated Regulation (EU) 2025/1535. This concerns certain products with digital elements covered by Regulation (EU) No 168/2013, the EU type-approval framework for two- and three-wheel vehicles and quadricycles. The Commission therefore used the Article 2(5) mechanism to establish a targeted exclusion from the CRA.
I think this is relevant to the machinery discussion because machinery products with digital elements are currently within the scope of the CRA; there is no general machinery exclusion in Article 2.
However, Article 2(5) provides a possible route where sectoral legislation addresses the same cybersecurity risks and achieves the same or a higher level of protection as the CRA. In that case, the Commission can determine, through a delegated act, whether the application of the CRA should be limited or excluded, and for which products and requirements.
For machinery, the relevant legislation is now Regulation (EU) 2023/1230 on machinery, rather than the old Machinery Directive 2006/42/EC. The Machinery Regulation will apply from 20 January 2027.
It is particularly interesting because the new Machinery Regulation contains a number of cybersecurity-related requirements, including:
- protection against corruption of hardware and software relevant to safety;
- protection of safety-critical software and data against accidental or intentional corruption;
- identification of software necessary for the safe operation of machinery;
- evidence of legitimate or illegitimate intervention in relevant hardware/software;
- protection of control systems against reasonably foreseeable malicious attempts where these could lead to a hazardous situation; and
- requirements concerning the safety and reliability of control systems.
So, once the Machinery Regulation applies in 2027, machinery could potentially be assessed under the same Article 2(5) mechanism, provided that it can be demonstrated that the relevant Machinery Regulation requirements provide the same or a higher level of protection for the cybersecurity risks covered by the CRA.
I would still distinguish this from saying that the Machinery Regulation is automatically lex specialis to the CRA. The exclusion would require Commission action through a delegated act, defining the products, sectoral rules and scope of any limitation or exclusion.
So I think the vehicle case is an interesting precedent from the CRA negotiations and implementation perspective, and it could be relevant when considering whether a similar approach could be pursued for machinery once Regulation (EU) 2023/1230 applies.
I hope this can be useful
Best,
Marta