"Our robot is certified under the Machinery Regulation, so the CRA does not concern us." This sentence comes up surprisingly often in conversations with machinery manufacturers lately. It sounds plausible, but it is a dangerous misconception, and one that can become expensive.

What does "product with digital elements" mean in the CRA?
The Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) applies to all "products with digital elements", meaning products that contain software or firmware and can be connected directly or indirectly to a network or another device. Robots, cobots, and automated production systems generally fall under this definition as soon as they carry their own control software or communicate through interfaces.
The classification as a "product with digital elements" is independent of which other EU regulations apply to the device. The CRA creates no exclusion for products already covered by other frameworks. This is not an oversight by the legislator, it is deliberate. For the basic scope of the CRA, see our CRA overview.
Why the Machinery Regulation alone is not enough
The Machinery Regulation (EU) 2023/1230, which replaces the previous Machinery Directive 2006/42/EC, governs the functional and physical safety of machinery. It sets requirements on safeguards, emergency stops, ergonomic design, and the reliability of safety-relevant control systems. That is important, but it is not the same as cybersecurity.
The CRA addresses a different threat dimension. What happens if someone manipulates the robot's software from the outside? What if a vulnerability in an open-source library used inside it is exploited to compromise the motion control system? What if the manufacturer no longer provides security updates after placing the product on the market?
These questions are not answered by the Machinery Regulation. But they are central to the safety of systems operated in connected production environments. Anyone who believes that CE marking under the Machinery Regulation closes the compliance task underestimates the scope of their obligations. For more on the risks of non-compliance, see: CRA penalties and fines.
For a cobot manufacturer this means: The Machinery Regulation checks whether force limitation works correctly and whether collision detection is reliable. The CRA additionally checks whether the software steering these functions is hardened against cyberattacks, and whether the manufacturer has processes to report and remediate vulnerabilities.
Myth vs. fact
Myth: Anyone whose robot is certified under the Machinery Regulation (EU) 2023/1230 also meets the requirements of the Cyber Resilience Act.
Fact: The Machinery Regulation and the CRA are two independent frameworks with different protection goals. Both must be met cumulatively. CE marking under the Machinery Regulation does not protect against fines for CRA breaches. The reverse holds as well.
Concrete consequences for manufacturers
1. Dual conformity assessment with a shared documentation basis. Manufacturers of machinery with digital elements must carry out a conformity assessment for both regulations and issue a declaration of conformity. That sounds like double effort, and initially it is. However, documentation can be cleverly interleaved. Safety requirements from Annex I of the Machinery Regulation that address protecting control systems from corruption overlap substantively with CRA requirements for protection against unauthorised access. Anyone who documents their measures this way from the start can use the same evidence for both regulations.
2. SBOM duty for machinery components, too. The CRA obliges manufacturers to create and maintain an SBOM, a Software Bill of Materials, a complete inventory of all software components used. This also applies to a robot's control software, even if it is already documented as part of the machinery in the technical file under the Machinery Regulation. The CRA SBOM goes further: it must capture all third-party components, open-source libraries, and their versions, as the basis for ongoing vulnerability monitoring. For more, see the vulnerability management guide.
3. Lifecycle duties do not begin at placing on the market, and they do not end there. The Machinery Regulation primarily sets requirements on the product at the moment of placing on the market. The CRA thinks further. Manufacturers must provide security updates for the entire expected service life, at minimum for five years. That means robot manufacturers must establish processes for vulnerability reporting, patch management, and customer communication that extend beyond the point of sale. Anyone who does not violates the CRA, regardless of how flawless the Machinery Regulation documentation is.
What does this mean for your CRA roadmap?
The two central deadlines should be on your planning radar.
From 11 September 2026, the CRA reporting duties apply. Manufacturers must report actively exploited vulnerabilities within 24 hours to ENISA, the EU Agency for Cybersecurity. This deadline is closer than many think, and the processes for it cannot be set up at short notice.
From 20 January 2027, the new Machinery Regulation (EU) 2023/1230 becomes binding. From that date it fully replaces the old Machinery Directive 2006/42/EC. Anyone placing machinery on the EU market must comply with the new regulation from that point on. This date lies only about eleven months before the next important date.
From 11 December 2027, the CRA applies in full. Products placed on the market after that date must meet all requirements, including conformity assessment, technical documentation, CE marking under the CRA, and SBOM.
The deadlines for the Machinery Regulation and the CRA are therefore only about one year apart. Manufacturers that plan both frameworks in parallel avoid duplicate work and ensure there is no compliance gap between the two deadlines. If you do not yet have an integrated roadmap, you should start. A structured compliance roadmap helps work through the requirements of both regulations systematically.
Frequently asked questions
Do I need two separate CE markings for Machinery Regulation and CRA? No, there is only one CE marking per product. It signals that all applicable EU regulations are met. The declaration of conformity, however, must list all applicable legal acts, so both the Machinery Regulation and the CRA. For more, see our article on CE marking and CRA conformity assessment.
Does the CRA also apply to robots used exclusively internally within a company and not sold? The CRA applies to placing on the market in the EU. Products manufactured exclusively for internal use and never passed on to third parties do not fall under the CRA. As soon as a machine is sold, leased, or otherwise transferred to third parties, including within a corporate group, the regulation kicks in.
What happens if my robot was sold before the CRA fully applies? Products placed on the market before 11 December 2027 are exempt from the CRA conformity obligations. The reporting duties for actively exploited vulnerabilities, however, apply from 11 September 2026, including for products already sold, if the manufacturer becomes aware of them.
Can I leverage cybersecurity measures I implement for the CRA for the Machinery Regulation as well? Yes, and that is the real opportunity. Requirements from Annex I of the Machinery Regulation on protecting control systems from corruption and on the reliability of safety-relevant software overlap substantively with CRA requirements. Anyone building documentation cleverly can use the same evidence for both regulations.
Which CRA category applies to robots, standard products or critical products? It depends on the actual functionality. Robots with safety functions used in safety-critical environments may be classified as important products class I or class II, with correspondingly stricter requirements for conformity assessment. The exact classification follows from Annex III and IV of the CRA.
Conclusion
The Machinery Regulation and the Cyber Resilience Act are not alternatives, they are complements. Anyone who manufactures machinery with control software and network interfaces must meet both frameworks. Period. The good news is that there are real synergies. Anyone who tackles their CRA compliance work in a structured way from the start can use the same documentation for requirements in both regulations and save significant effort.
The first step is an honest inventory. Which of my products fall under the CRA? What have I already done, what is still missing? A structured CRA compliance assessment helps answer these questions systematically, before the deadline tips from theory into practice.
Every Friday I debunk a CRA myth here.