Cyber Resilience Act: New Obligations for Products with Digital Elements from 11 September 2026

Cybersecurity is becoming an increasingly integral part of the design of industrial and off-highway machinery. With the first obligations under the Cyber Resilience Act becoming applicable, a new phase in cybersecurity management is beginning for manufacturers and developers of products with digital elements.

Cyber Resilience Act: New Obligations for Products with Digital Elements from 11 September 2026
11 Sep 2026
5 minutes

Cybersecurity is becoming an increasingly integral part of the design of industrial and off-highway machinery. With the first obligations under the Cyber Resilience Act becoming applicable, a new phase in cybersecurity management is beginning for manufacturers and developers of products with digital elements.

From 11 September 2026, Article 14 of the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, becomes applicable, introducing specific reporting obligations for manufacturers of products with digital elements.

The Regulation will become fully applicable on 11 December 2027, but the European Union has brought forward certain obligations relating to the management and reporting of cybersecurity vulnerabilities and incidents.

What changes from 11 September 2026

From this date, manufacturers subject to the CRA must report actively exploited vulnerabilities that they become aware of, as well as severe incidents affecting the security of products with digital elements.

For actively exploited vulnerabilities, the Regulation requires an initial early warning within 24 hours of becoming aware of the vulnerability, followed by a more detailed notification within 72 hours. A final report is also required within 14 days after a corrective or mitigating measure becomes available.

Reports are managed through the European Single Reporting Platform, developed by ENISA, and are submitted to the competent CSIRT and ENISA.

The CRA also requires manufacturers, after becoming aware of an actively exploited vulnerability or a severe incident, to inform affected users and, where necessary, communicate the corrective or mitigating measures that can be taken.

Why the Cyber Resilience Act also matters for industrial machinery

Increasing digitalisation is also transforming the industrial, mobile and off-highway machinery sector.

Electronic control units, HMIs, IoT gateways, control devices and communication systems are part of architectures in which hardware, software and connectivity are increasingly integrated.

A connected machine can communicate with other devices, exchange information over CAN or Ethernet networks, send data to cloud platforms, receive software updates and enable remote diagnostics and maintenance activities.

This evolution creates new opportunities for monitoring, diagnostics, fleet management, maintenance and performance optimisation, while at the same time expanding the digital attack surface that needs to be protected.

For this reason, cybersecurity must increasingly be considered from the earliest stages of the machine’s electronic architecture development.

From product security to vulnerability management

The Cyber Resilience Act introduces an important shift in perspective: manufacturers must be able to manage vulnerabilities throughout the defined support period of the product.

This means establishing processes capable of identifying and analysing vulnerabilities, taking action when necessary, providing updates or corrective measures, and communicating the information required by the Regulation.

For the industrial sector, this means paying increasing attention to aspects such as:

  • security of communications and access;

  • software and firmware protection;

  • update management;

  • device authentication;

  • access control for machine functions;

  • software version traceability;

  • vulnerability monitoring and management;

  • protection of communications between the machine, gateways and digital infrastructures.

Cybersecurity therefore becomes a key component of the entire product lifecycle, from design through to operation.

Increasingly connected machines require an integrated approach

For ALMEC, designing a machine’s electronics means considering both the functionalities required by the application and the way in which different devices communicate, as well as how the machine interacts with external systems.

From ECUs and HMIs to IoT gateways such as NEXUS, designing connected systems requires an approach that integrates hardware, software, communications and data management.

With NEXUS and the Diaboard platform, data generated by the machine can be collected and used for remote monitoring, diagnostics, fleet management and maintenance applications.

Cybersecurity by design: designing today with the machine lifecycle in mind

The path outlined by the Cyber Resilience Act reinforces a principle that is set to become increasingly important in the industrial sector: cybersecurity must be considered by design.

For machine manufacturers, this means working with technology partners capable of understanding the interaction between the different electronic components that make up the overall system.

This is precisely the direction of ALMEC’s approach: working alongside customers from the earliest stages of the design process to develop integrated and customised electronic solutions, considering functionality, connectivity, data management and security requirements within the same architecture.

11 September 2026 is only the first step

The reporting obligations represent an initial milestone of the Cyber Resilience Act, which will become fully applicable from 11 December 2027.

For the industrial and off-highway machinery sector, connectivity, digitalisation and cybersecurity must evolve together to enable the development of machines that are increasingly connected, high-performing and secure throughout their lifecycle.

Book an appointment with our technical team to find out how to align your machine system with the new regulatory requirements. Contact us at info@almec.net.

You might also be interested in

Subscribe our newsletter

Discover our news
before everyone else

Get monthly technical updates and product releases.

Newsletter
Thank you for subscribing to our newsletter!
Check your inbox so you don't miss the latest news on our products and services, our events and much more...