Skip to Content

Cyber Resilience Act - What Machine Builders Must Deliver to Their Customers

July 31, 2026 by
D.Hansen - Machine Insight Expert
The European Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for all products with digital elements placed on the EU market. For machine builders and system integrators, this means that every machine containing software — including PLC programs, libraries, and digital control components — must be delivered with defined security documentation, lifecycle information, and vulnerability management processes.

Under the CRA, manufacturers must ensure that the software integrated into a machine is developed securely, documented properly, and maintained throughout its entire lifecycle. They must provide security updates when vulnerabilities affect the confidentiality, integrity, or availability of the machine. Technical documentation describing security‑relevant properties, interfaces, and operational constraints must be available to customers and authorities. A Software Bill of Materials (SBOM) is required to show which components are included in the machine program, which versions are used, and how they depend on each other. Manufacturers must also monitor publicly known vulnerabilities that may affect their machines and take appropriate action when risks arise.

For OEMs and system integrators, these regulatory obligations translate into concrete deliverables. Customers must receive an SBOM for the machine program in a recognized format such as CycloneDX. They must also receive a risk assessment covering the software components used in the machine, along with a register of known vulnerabilities relevant to the delivered configuration. Manufacturers are expected to provide a security advisory channel through which customers can be informed about newly discovered issues. In addition, they must document the update and patch history of the machine software and provide a supplier security declaration confirming that the integrated components meet CRA requirements.

These elements become part of the machine’s technical file and must be available for audits or market surveillance. They ensure transparency, traceability, and a clear understanding of how digital components behave within the machine.

Software vendors can support manufacturers in meeting these obligations. DDAS provides SBOMs, risk assessments, vulnerability tracking, and update histories  for its library suite, helping OEMs and system integrators supply the required CRA documentation to their customers without additional complexity.

The CRA establishes a clear framework for cybersecurity in industrial products. With proper documentation, secure integration, and continuous monitoring, machine builders can meet these requirements effectively and deliver machines that comply with the new European cybersecurity standards.


In Short: What OEMs and System Integrators Must Provide Under the CRA
  • Provide a Software Bill of Materials (SBOM) for the machine program, using a recognized format such as CycloneDX.
  • Deliver a risk assessment covering all software components used in the machine.
  • Maintain and share a vulnerability register relevant to the delivered machine configuration.
  • Offer a security advisory channel to inform customers about newly discovered issues.
  • Document the update and patch history of the machine software.
  • Provide a supplier security declaration confirming CRA‑compliant development and maintenance of integrated components.
  • Ensure continuous vulnerability monitoring and take action when risks affect machine security.
  • Maintain technical documentation describing security‑relevant properties, interfaces, and operational constraints.
  • Apply security updates when vulnerabilities impact confidentiality, integrity, or availability.

DDAS can support OEMs and system integrators in fulfilling these obligations by providing SBOMs, risk assessments, vulnerability tracking, and update histories for the PLC machine program.