Under the CRA, manufacturers must ensure that the software integrated into a machine is developed securely, documented properly, and maintained throughout its entire lifecycle. They must provide security updates when vulnerabilities affect the confidentiality, integrity, or availability of the machine. Technical documentation describing security‑relevant properties, interfaces, and operational constraints must be available to customers and authorities. A Software Bill of Materials (SBOM) is required to show which components are included in the machine program, which versions are used, and how they depend on each other. Manufacturers must also monitor publicly known vulnerabilities that may affect their machines and take appropriate action when risks arise.
The CRA establishes a clear framework for cybersecurity in industrial products. With proper documentation, secure integration, and continuous monitoring, machine builders can meet these requirements effectively and deliver machines that comply with the new European cybersecurity standards.
In Short: What OEMs and System Integrators Must Provide Under the CRA
- Provide a Software Bill of Materials (SBOM) for the machine program, using a recognized format such as CycloneDX.
- Deliver a risk assessment covering all software components used in the machine.
- Maintain and share a vulnerability register relevant to the delivered machine configuration.
- Offer a security advisory channel to inform customers about newly discovered issues.
- Document the update and patch history of the machine software.
- Provide a supplier security declaration confirming CRA‑compliant development and maintenance of integrated components.
- Ensure continuous vulnerability monitoring and take action when risks affect machine security.
- Maintain technical documentation describing security‑relevant properties, interfaces, and operational constraints.
- Apply security updates when vulnerabilities impact confidentiality, integrity, or availability.
DDAS can support OEMs and system integrators in fulfilling these obligations by providing SBOMs, risk assessments, vulnerability tracking, and update histories for the PLC machine program.