For manufacturers

If you manufacture machinery, equipment or devices that connect to the internet or other networks, the Cyber Resilience Act (CRA) applies to you directly.

Manufacturers of connected equipment — from industrial control panels and SCADA systems to IoT devices and automation equipment — have clear obligations: technical documentation, conformity assessment, extended CE marking and security incident reporting.

Concrete examples: production lines with network-connected PLCs, factory or warehouse monitoring systems, access control equipment managed via application, and any device that communicates digitally with the outside world.

CRA requires manufacturers to demonstrate that cybersecurity was built in from the design phase (security by design) and maintained throughout the product's declared lifetime. Non-compliance carries fines of up to €15 million or 2.5% of global turnover.