Cyber Resilience Act (CRA)
The Cyber Resilience Act
With the Cyber Resilience Act (CRA), the European Union (EU) is establishing a uniform legal framework for the cybersecurity of products with digital elements. The implementation of these requirements affects the entire value chain. For this reason, EUCHNER is committed to close collaboration with customers, partners, and suppliers to jointly develop safe and future-proof solutions.
Cybersecurity and functional safety
Cybersecurity complements functional safety and is based on three protection objectives:
- Availability – Systems and components must remain functional even under attack
- Integrity – Data must not be altered without detection
- Confidentiality – Sensitive information must be protected
While functional safety primarily focuses on integrity, cybersecurity takes all three protection objectives into account equally.
Scope of the CRA
The CRA applies to all products with digital elements that can process data or communicate with other systems. These include, for example:
- Control systems
- Safety components
- Software
- Connected devices
- Machines and industrial plants
The CRA affects three key groups along the value chain:
View the current CRA status of EUCHNER products.
Our CRA team is happy to assist you at cra@euchner.de.
Download the certificate for our Secure Development Lifecycle.
Component manufacturers
e.g., EUCHNER
- Integration of cybersecurity into product design and development
- Provision of cybersecurity-compliant products and documentation
- Delivery of security updates throughout the defined product lifecycle
Machine manufacturers (Integrators)
- Selection of suitable, cybersecurity-compliant components
- Cybersecure system integration
- Complete documentation of the entire machine
Operators / Users
- Assessment of cybersecurity risks
- Implementation of recommendations and updates
- Cybersecure operation throughout the entire lifecycle
Product requirements
What are the requirements for the products?
- Security-oriented development (Secure Development Lifecycle)
- Protection against known vulnerabilities
- Provision of updates and cybersecurity information
- Documentation and transparency
- For certain critical products, certification by an independent third party is also required
How is the existing product portfolio being handled?
- Products may already be CRA-compliant
- Products require adjustments (e.g., documentation or firmware)
- Products are being replaced by new versions
- Products are defined as replacement parts
Implementation of the CRA at EUCHNER
EUCHNER took early steps to implement the CRA.
CRA product status at EUCHNER
The assessment of existing products is carried out individually and results in a CRA status for a product or product series. To ensure transparent communication, CRA progress is described using the defined status.
|
CRA-compliant
The product already meets the CRA requirements and will be CRA-compliant as of December 11, 2027.
|
|
CRA-ready
The product will be CRA-compliant as of December 11, 2027. Measures are required to achieve compliance.
|
|
Not CRA-compliant
The product does not meet the CRA requirements and will continue to be offered as a replacement part within the EU as of the effective date of December 11, 2027.
|
|
Pending
The CRA status will be available soon.
|
|
Not CRA-relevant
The device is not affected by the CRA.
|
