Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [open-regulatory-compliance] Machine directive and the CRA

On 30 Sep 2026, at 13:56, Olle E. Johansson via open-regulatory-compliance <open-regulatory-compliance@xxxxxxxxxxx> wrote:

On 30 Sep 2026, at 13:04, Dirk-Willem van Gulik via open-regulatory-compliance <open-regulatory-compliance@xxxxxxxxxxx> wrote:

So perhaps it is useful to add this to our FAQ; including a reference to the commissions FAQ entry on this in section 2.4. First stab:

 interplay between the CRA and the Machinery Regulation

First - there is no general machinery exclusion in the scope of the CRA (as there is for, for example Marine, Medical and Aerospace). 

Article 2(5) allows for the commission, via a delegated act, to implicitly add such an exclusion provided that a standard provides the same or better protection than the CRA. It has not yet done so.

However; the (new) machine directive (Regulation (EU) 2023/1230) that comes into effect on the 20th of January 2027 contains a number of cybersecurity-related requirements, including:
  • protection against corruption of hardware and software relevant to safety;
  • protection of safety-critical software and data against accidental or intentional corruption;
  • identification of software necessary for the safe operation of machinery;
  • evidence of legitimate or illegitimate intervention in relevant hardware/software;
  • protection of control systems against reasonably foreseeable malicious attempts where these could lead to a hazardous situation; and
  • requirements concerning the safety and reliability of control systems.
That are very much in line, or go a step further, than the CRA when it comes to safety (as opposed to security). 

However until a delegated act is passed - Manufacturers and open source stewards should assume that both the CRA and the machine directive apply.

Would that be helpful ?

I think so. Maybe we should add something about DORA and NIS2 too. Like - if you’re regulated under another cybersecurity-regulated regulation like DORA and NIS2 this does not mean that PDE’s you place on the market is not regulated by CRA. If the PDE has a backend (remote data processing) this backend will likely be regulated under multiple regulations.

The backend situation is a question I’ve gotten a number of times. From a lawyer standpoint it can be an interesting discussion if there’s a border between DORA and CRA in the backend. From a cybersecurity standpoint. I think it’s quite boring, since the requirements are mostly the same. 

Very much agreed for NIS2, DORA, the CRA, etc.

I think with the machine directive there is a small twist - and that is that this `mostly the same' sort of smudges over the safety v.s. security issue. If they are aligned - agreed. But if they are conflicting (i.e. locking a fire-exit/safety door as that makes the building more secure) - then it is not. Which is why it is so nice to have automotive/aerospace/etc to be exempted - as there you too have that conflict.

Dw.

On 30 Sep 2026, at 12:45, Marta Garcia via open-regulatory-compliance <open-regulatory-compliance@xxxxxxxxxxx> wrote:

Hi Dirk-Willem,

This was actually an interesting point during the CRA negotiations, and I think the machinery case is particularly interesting in this context.

The Commission has already used Article 2(5) of the CRA in the vehicle sector through Commission Delegated Regulation (EU) 2025/1535. This concerns certain products with digital elements covered by Regulation (EU) No 168/2013, the EU type-approval framework for two- and three-wheel vehicles and quadricycles. The Commission therefore used the Article 2(5) mechanism to establish a targeted exclusion from the CRA.

I think this is relevant to the machinery discussion because machinery products with digital elements are currently within the scope of the CRA; there is no general machinery exclusion in Article 2.

However, Article 2(5) provides a possible route where sectoral legislation addresses the same cybersecurity risks and achieves the same or a higher level of protection as the CRA. In that case, the Commission can determine, through a delegated act, whether the application of the CRA should be limited or excluded, and for which products and requirements.

For machinery, the relevant legislation is now Regulation (EU) 2023/1230 on machinery, rather than the old Machinery Directive 2006/42/EC. The Machinery Regulation will apply from 20 January 2027.

It is particularly interesting because the new Machinery Regulation contains a number of cybersecurity-related requirements, including:

  • protection against corruption of hardware and software relevant to safety;
  • protection of safety-critical software and data against accidental or intentional corruption;
  • identification of software necessary for the safe operation of machinery;
  • evidence of legitimate or illegitimate intervention in relevant hardware/software;
  • protection of control systems against reasonably foreseeable malicious attempts where these could lead to a hazardous situation; and
  • requirements concerning the safety and reliability of control systems.

So, once the Machinery Regulation applies in 2027, machinery could potentially be assessed under the same Article 2(5) mechanism, provided that it can be demonstrated that the relevant Machinery Regulation requirements provide the same or a higher level of protection for the cybersecurity risks covered by the CRA.

I would still distinguish this from saying that the Machinery Regulation is automatically lex specialis to the CRA. The exclusion would require Commission action through a delegated act, defining the products, sectoral rules and scope of any limitation or exclusion.

So I think the vehicle case is an interesting precedent from the CRA negotiations and implementation perspective, and it could be relevant when considering whether a similar approach could be pursued for machinery once Regulation (EU) 2023/1230 applies.

I hope this can be useful

Best,
Marta

Marta García
Research Project Manager | Eclipse Foundation Europe GmbH

 

Berliner Allee 47, 64295 Darmstadt
Handelsregister: Darmstadt HRB 92821
Managing Directors: Gaël Blondelle, Mike Milinkovich, Michael Plagge



On Wed, Sep 30, 2026 at 12:25 PM Dirk-Willem van Gulik via open-regulatory-compliance <open-regulatory-compliance@xxxxxxxxxxx> wrote:
We have, in the scope (Art.2) quite clear defintions for regulations that are lex specialis/trump the CRA for medical, in vitro, normalish cars, aero space and maritime. But it does not mention the Machine directive.

Do we know why -- or is/was the assumption that 2.5.b:

        The application of this Regulation to products with digital elements covered by other Union rules laying down requirements that address all or some of the risks covered by the essential cybersecurity requirements set out in Annex I may be limited or excluded where:
        (b)the sectoral rules achieve the same or a higher level of protection as that provided for by this Regulation.

WOuld kick in ?

Dw      
_______________________________________________
open-regulatory-compliance mailing list
open-regulatory-compliance@xxxxxxxxxxx
To unsubscribe from this list, visit https://accounts.eclipse.org
_______________________________________________
open-regulatory-compliance mailing list
open-regulatory-compliance@xxxxxxxxxxx
To unsubscribe from this list, visit https://accounts.eclipse.org

_______________________________________________
open-regulatory-compliance mailing list
open-regulatory-compliance@xxxxxxxxxxx
To unsubscribe from this list, visit https://accounts.eclipse.org

_______________________________________________
open-regulatory-compliance mailing list
open-regulatory-compliance@xxxxxxxxxxx
To unsubscribe from this list, visit https://accounts.eclipse.org


Back to the top