Skip to content
Zyberum Cyber Security Firm
Menu
For your industryOT

Cybersecurity for Machine Builders: Machinery Regulation, CRA and IEC 62443

What machine builders must do for cybersecurity: Machinery Regulation 2027, Cyber Resilience Act, IEC 62443, the typical attack surface and a sensible first project.

Updated This page as Markdown

In short

Machine builders face three sets of cybersecurity requirements at once: the EU Machinery Regulation (applies from 20 January 2027) makes protection against corruption a health and safety requirement, the Cyber Resilience Act (full application 11 December 2027) covers the digital components you sell, and operators ask for IEC 62443 conformity. In tests of machines we most often find open engineering ports, flat networks between HMI, PLC and remote access, default credentials and unsigned firmware. A sensible first project is a security assessment of one machine type with a gap analysis against IEC 62443-4-2.

Which rules apply to you

Three sets of requirements reach machine builders in the next two years.

Machinery Regulation (EU) 2023/1230 applies from 20 January 2027 and replaces the Machinery Directive. Annex III makes “protection against corruption” an essential health and safety requirement: the control system must not be put into a hazardous state by an accidental or intentional attack, and the machine must collect evidence of a legitimate or illegitimate intervention when relevant for safety. Software and data affecting safety behaviour must be identified and protected against alteration. This is checked in the conformity assessment of the machine.

Cyber Resilience Act (EU) 2024/2847 applies to products with digital elements you place on the market: controllers, HMIs, gateways, drives with network interfaces, and the software that runs or configures them. Reporting duties for actively exploited vulnerabilities apply from 11 September 2026, the full requirements including CE marking from 11 December 2027. Industrial controllers and remote-access products are listed as important products, which changes how you prove conformity.

IEC 62443 is not law but is what operators demand and what both regulations treat as state of the art. 62443-4-1 describes a secure development process, 62443-4-2 the technical requirements for components per security level, 62443-3-3 the requirements for the system a machine becomes when integrated.

Where attackers start

A machine is a small network with a long service life. The attack surface we see in practice:

  • Engineering and service ports: Ethernet or USB ports for the programming tool, often with the PLC in a mode that accepts program downloads without authentication.
  • Remote access: a cellular router or VPN box installed for service, with a shared password that every service technician knows and that never changes.
  • Flat networks: HMI, PLC, drives and the IT uplink in one subnet; whoever reaches the HMI reaches the controller.
  • Default and hard-coded credentials in HMIs, web interfaces of drives and gateways, and in your own service tools.
  • Unsigned firmware and projects: anyone with network access can load a modified program; the machine has no way to tell.
  • Protocols without authentication: Modbus TCP, PROFINET, EtherNet/IP and most fieldbuses were designed for closed networks.

What assessments typically find

Typical findings from security assessments of machines and their controllers, anonymised: a service VPN whose credentials were printed in the machine manual; a web HMI that allowed changing safety-relevant parameters without login after a session on a different page; a PLC that accepted a stop command from any host on the network; a firmware update mechanism that checked a checksum but no signature; and configuration backups containing the plant’s Wi-Fi password in clear text.

None of these needs an expert attacker. All of them would fail the Machinery Regulation’s protection against corruption and several 62443-4-2 requirements at security level 1.

A sensible first project

Start with one machine type, ideally the one you sell most or the one going through conformity assessment first.

  1. Asset and interface inventory: every component with software, every port, every protocol, every remote path. Half a day with your controls engineers.
  2. Security assessment of a test machine or a twin in our lab: network, controller, HMI, remote access, firmware and update path, service tools. One to two weeks.
  3. Gap analysis of the results against IEC 62443-4-2 at the security level your customers ask for, and against the Machinery Regulation’s protection against corruption and the CRA’s essential requirements. Delivered as a prioritised list your engineers can work through.
  4. Fix and retest, then reuse the result: the same architecture decisions apply to your other machines.

Typical effort for steps 1 to 3 is 10 to 15 person-days, which is 12,000 to 25,000 euros at market rates. Treat it as part of the conformity assessment budget, not as an extra.

What Zyberum does and does not do here

We test machines, controllers and remote access, do the gap analyses, help your engineers specify and implement the fixes and prepare the technical documentation for the conformity assessment. We train controls engineers in secure design and secure PLC programming. We are not a notified body and do not issue certificates; we prepare you so that the assessment goes through at the first attempt.

FAQ

Frequently asked questions

Does the Machinery Regulation replace the Cyber Resilience Act for machines?

No, they apply in parallel. The Machinery Regulation treats cybersecurity as a safety matter for the machine as a whole: a manipulated control must not create a hazard. The Cyber Resilience Act applies to the products with digital elements in and around the machine, for example the controller, the HMI, the remote-access gateway and the software you supply. Where the Machinery Regulation already covers a risk, the CRA defers to it for that risk; the vulnerability handling and reporting duties of the CRA remain.

Is IEC 62443 certification mandatory?

Not by law. It is what operators of plants, especially in energy, water, pharma and automotive, ask their suppliers for, and it is the state of the art that both regulations point to. A conformity statement against 62443-4-2 for a component, or a 62443-4-1 process certificate for your development, answers most customer questionnaires at once.

Can you test a machine without stopping production?

On the customer’s plant floor, only within narrow limits. We test on your test machine, a spare controller or a twin setup in our lab, where we can be as aggressive as needed. Passive analysis of a running machine, network captures and configuration reviews work without downtime.

Sources

Related pages

Get started

What does this mean for your product?

In a free one-hour consultation we go through your product or plant, the regulations that apply and the first steps that bring the most security for the money.

  • Applicable regulations and deadlines for your case
  • Where attackers would start
  • A first project with a fixed price
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usDiscuss your situation

Pick a time that suits you

Open in a new tab