Cybersecurity for Machine Builders: Machinery Regulation, CRA and IEC 62443
What machine builders must do for cybersecurity: Machinery Regulation 2027, Cyber Resilience Act, IEC 62443, the typical attack surface and a sensible first project.
Updated This page as Markdown
In short
Machine builders face three sets of cybersecurity requirements at once: the EU Machinery Regulation (applies from 20 January 2027) makes protection against corruption a health and safety requirement, the Cyber Resilience Act (full application 11 December 2027) covers the digital components you sell, and operators ask for IEC 62443 conformity. In tests of machines we most often find open engineering ports, flat networks between HMI, PLC and remote access, default credentials and unsigned firmware. A sensible first project is a security assessment of one machine type with a gap analysis against IEC 62443-4-2.
Which rules apply to you
Three sets of requirements reach machine builders in the next two years.
Machinery Regulation (EU) 2023/1230 applies from 20 January 2027 and replaces the Machinery Directive. Annex III makes “protection against corruption” an essential health and safety requirement: the control system must not be put into a hazardous state by an accidental or intentional attack, and the machine must collect evidence of a legitimate or illegitimate intervention when relevant for safety. Software and data affecting safety behaviour must be identified and protected against alteration. This is checked in the conformity assessment of the machine.
Cyber Resilience Act (EU) 2024/2847 applies to products with digital elements you place on the market: controllers, HMIs, gateways, drives with network interfaces, and the software that runs or configures them. Reporting duties for actively exploited vulnerabilities apply from 11 September 2026, the full requirements including CE marking from 11 December 2027. Industrial controllers and remote-access products are listed as important products, which changes how you prove conformity.
IEC 62443 is not law but is what operators demand and what both regulations treat as state of the art. 62443-4-1 describes a secure development process, 62443-4-2 the technical requirements for components per security level, 62443-3-3 the requirements for the system a machine becomes when integrated.
Where attackers start
A machine is a small network with a long service life. The attack surface we see in practice:
- Engineering and service ports: Ethernet or USB ports for the programming tool, often with the PLC in a mode that accepts program downloads without authentication.
- Remote access: a cellular router or VPN box installed for service, with a shared password that every service technician knows and that never changes.
- Flat networks: HMI, PLC, drives and the IT uplink in one subnet; whoever reaches the HMI reaches the controller.
- Default and hard-coded credentials in HMIs, web interfaces of drives and gateways, and in your own service tools.
- Unsigned firmware and projects: anyone with network access can load a modified program; the machine has no way to tell.
- Protocols without authentication: Modbus TCP, PROFINET, EtherNet/IP and most fieldbuses were designed for closed networks.
What assessments typically find
Typical findings from security assessments of machines and their controllers, anonymised: a service VPN whose credentials were printed in the machine manual; a web HMI that allowed changing safety-relevant parameters without login after a session on a different page; a PLC that accepted a stop command from any host on the network; a firmware update mechanism that checked a checksum but no signature; and configuration backups containing the plant’s Wi-Fi password in clear text.
None of these needs an expert attacker. All of them would fail the Machinery Regulation’s protection against corruption and several 62443-4-2 requirements at security level 1.
A sensible first project
Start with one machine type, ideally the one you sell most or the one going through conformity assessment first.
- Asset and interface inventory: every component with software, every port, every protocol, every remote path. Half a day with your controls engineers.
- Security assessment of a test machine or a twin in our lab: network, controller, HMI, remote access, firmware and update path, service tools. One to two weeks.
- Gap analysis of the results against IEC 62443-4-2 at the security level your customers ask for, and against the Machinery Regulation’s protection against corruption and the CRA’s essential requirements. Delivered as a prioritised list your engineers can work through.
- Fix and retest, then reuse the result: the same architecture decisions apply to your other machines.
Typical effort for steps 1 to 3 is 10 to 15 person-days, which is 12,000 to 25,000 euros at market rates. Treat it as part of the conformity assessment budget, not as an extra.
What Zyberum does and does not do here
We test machines, controllers and remote access, do the gap analyses, help your engineers specify and implement the fixes and prepare the technical documentation for the conformity assessment. We train controls engineers in secure design and secure PLC programming. We are not a notified body and do not issue certificates; we prepare you so that the assessment goes through at the first attempt.
FAQ
Frequently asked questions
Does the Machinery Regulation replace the Cyber Resilience Act for machines?
No, they apply in parallel. The Machinery Regulation treats cybersecurity as a safety matter for the machine as a whole: a manipulated control must not create a hazard. The Cyber Resilience Act applies to the products with digital elements in and around the machine, for example the controller, the HMI, the remote-access gateway and the software you supply. Where the Machinery Regulation already covers a risk, the CRA defers to it for that risk; the vulnerability handling and reporting duties of the CRA remain.
Is IEC 62443 certification mandatory?
Not by law. It is what operators of plants, especially in energy, water, pharma and automotive, ask their suppliers for, and it is the state of the art that both regulations point to. A conformity statement against 62443-4-2 for a component, or a 62443-4-1 process certificate for your development, answers most customer questionnaires at once.
Can you test a machine without stopping production?
On the customer’s plant floor, only within narrow limits. We test on your test machine, a spare controller or a twin setup in our lab, where we can be as aggressive as needed. Passive analysis of a running machine, network captures and configuration reviews work without downtime.
Sources
Related pages
- ServicesKeep production running when IT and OT converge.Security assessments, pentests and IEC 62443 consulting for PLC, SCADA and DCS. Protect production and critical infrastructure against cyberattacks.
- ServicesIEC 62443 for plants that must keep running.IEC 62443 for operators and manufacturers: risk assessment with zones and conduits, security levels, component tests to 62443-4-2 and secure development.
- ServicesMake your products CRA-compliant, without slowing development.Get CRA-ready: gap analysis, secure development lifecycle, vulnerability handling, SBOM and penetration testing for products with digital elements.
- GlossaryIEC 62443IEC 62443 is the standard series for the cybersecurity of industrial automation and control systems (IACS). Parts, the three roles, and how it is used in practice.
- GlossaryPLC (Programmable Logic Controller)A PLC is the industrial computer that runs the control logic of a machine or process. How PLCs work, which standards apply and where their security typically fails.
- ComparisonsIEC 62443 vs ISO 27001: Plant Security or Information Security Management?ISO 27001 certifies an organisation's security management system. IEC 62443 secures industrial automation, from plant to PLC. Where they overlap and who needs which.
