Cyber Resilience Act (CRA)

The Cyber Resilience Act

With the Cyber Resilience Act (CRA), the European Union (EU) is establishing a uniform legal framework for the cybersecurity of products with digital elements. The implementation of these requirements affects the entire value chain. For this reason, EUCHNER is committed to close collaboration with customers, partners, and suppliers to jointly develop safe and future-proof solutions.

Cybersecurity and functional safety

Cybersecurity complements functional safety and is based on three protection objectives:

  • Availability – Systems and components must remain functional even under attack
  • Integrity – Data must not be altered without detection
  • Confidentiality – Sensitive information must be protected

While functional safety primarily focuses on integrity, cybersecurity takes all three protection objectives into account equally.

Scope of the CRA

The CRA applies to all products with digital elements that can process data or communicate with other systems. These include, for example:

  • Control systems
  • Safety components
  • Software
  • Connected devices
  • Machines and industrial plants

The CRA affects three key groups along the value chain:

Check status
View the current CRA status of EUCHNER products.
Get your questions answered
Our CRA team is happy to assist you at cra@euchner.de.
View certificate
Download the certificate for our Secure Development Lifecycle.
Component manufacturers

Component manufacturers

e.g., EUCHNER

  • Integration of cybersecurity into product design and development
  • Provision of cybersecurity-compliant products and documentation
  • Delivery of security updates throughout the defined product lifecycle
Machine manufacturers (Integrators)

Machine manufacturers (Integrators)

 

  • Selection of suitable, cybersecurity-compliant components
  • Cybersecure system integration
  • Complete documentation of the entire machine
Operators / Users

Operators / Users

 

  • Assessment of cybersecurity risks
  • Implementation of recommendations and updates
  • Cybersecure operation throughout the entire lifecycle

Implementation of the CRA at EUCHNER

EUCHNER took early steps to implement the CRA.

“We took the right steps early on: Since the beginning of the year, our development process has been certified according to IEC 62443-4-1, making EUCHNER CRA-ready. At the same time, we have established a Product Security Incident Response Team (PSIRT) and entered a partnership with the VDE’s Cyber Emergency Response Team (CERT@VDE). This reinforces our commitment to delivering products that are consistently safe and robust in accordance with the Cyber Resilience Act,” explains Bernd Hermann, Head of Development at EUCHNER.

CRA product status at EUCHNER

The assessment of existing products is carried out individually and results in a CRA status for a product or product series. To ensure transparent communication, CRA progress is described using the defined status.

CRA-compliant
The product already meets the CRA requirements and will be CRA-compliant as of December 11, 2027.
CRA-ready
The product will be CRA-compliant as of December 11, 2027. Measures are required to achieve compliance.
Not CRA-compliant
The product does not meet the CRA requirements and will continue to be offered as a replacement part within the EU as of the effective date of December 11, 2027.
Pending
The CRA status will be available soon.
Not CRA-relevant
The device is not affected by the CRA.

CRA-ready! With EUCHNER.