Ostfildern , Nov 20, 2024

Legally binding – Pilz provides information and implementation tips: How companies can prepare now for the Cyber Resilience Act

The Cyber Resilience Act (CRA) was published recently in the Official Journal of the EU. The regulation contains specifications for the cybersecurity of products with digital elements. Affected companies now have 36 months to implement the requirements contained in the CRA. Certain reporting obligations must be fulfilled within the next 21 months. Who exactly is responsible? And what does the CRA require?

EU legal act on cyber resilience: The aim of the CRA is to provide better protection from cyber attacks for consumers and businesses. The CRA contains a variety of specifications for manufacturers, importers and distributors of products with digital elements, which are capable of communicating with other products. This includes hardware and software products. In other words, products from the B2C segment such as smartphones or robotic vacuum cleaners are affected by this, as are those from the B2B segment such as controllers and sensors, as well as pure software products such as operating systems. The CRA was published in the Official Journal of the European Union on 20.11.2024. As a regulation, this law applies immediately in EU member states.


The key requirements for machine manufacturers

  • Risk assessment and guarantee: Manufacturers must design and develop products in such a way that an appropriate level of cybersecurity is guaranteed during the whole product lifecycle.
  • Vulnerability management: The manufacturer should eliminate known vulnerabilities through free security updates, unless otherwise agreed between the manufacturer and commercial user.
  • Documentation: Manufacturers must identify and document vulnerabilities and components in their products.
  • Reporting obligations: Within 24 hours of becoming aware of an exploited vulnerability, the manufacturer must report it via the ENISA (European Union Agency for Cybersecurity) reporting platform.

What machine manufacturers can do now

As an expert in Safe and Secure automation, Pilz recommends that all machine manufacturers address the requirements of the CRA promptly, and work with component manufacturers and operators to develop cooperation concepts. In which network zone should a machine be operated? How should software updates be handled? If questions like these are clarified in advance, each economic operator can fulfil its new organisational and technical obligations. For decades, Pilz has been supporting machine builders and users with the Safety of their plant and machinery – including with the new requirements for Industrial Security. Because without Security, a machine with all its Safety measures is vulnerable and unprotected. Precautionary measures are a must.

2 practical tips for implementing CRA specifications

  1. Always keep up to date: Subscriptions to newsletters and RSS feeds on eur-lex.europa.eu will keep you informed about legislative changes at EU level.
  2. The Common Security Advisory Framework (CSAF) is a standardised, open source framework for communication and automated distribution of machine-processable vulnerability and mitigation information, so-called Security Advisories.
Even as machine manufacturers are designing, developing and manufacturing their products, they must meet basic specifications of the CRA – and guarantee them for the expected service life of the products. Pilz provides support during implementation. (Photo: © Westend61/[westend61] via Getty Images, © Pilz GmbH & Co. KG)
Even as machine manufacturers are designing, developing and manufacturing their products, they must meet basic specifications of the CRA – and guarantee them for the expected service life of the products. Pilz provides support during implementation. (Photo: © Westend61/[westend61] via Getty Images, © Pilz GmbH & Co. KG)

Even as machine manufacturers are designing, developing and manufacturing their products, they must meet basic specifications of the CRA – and guarantee them for the expected service life of the products. Pilz provides support during implementation. (Photo: © Westend61/[westend61] via Getty Images, © Pilz GmbH & Co. KG)

Top
Headoffice

Pilz GmbH & Co. KG
Felix-Wankel-Straße 2
73760 Ostfildern
Germany

Telephone: +49 711 3409-0
E-Mail: info@pilz.de

Corporate and Technical Press

Telephone: +49 711 3409 - 0
E-Mail: publicrelations@pilz.com

Americas

  • United States (toll-free): +1 877-PILZUSA (745-9872)
  • Mexico: +52 55 5572 1300
  • Brazil: + 55 11 4942-7032
  • Canada: +1 888-315-PILZ (315-7459)

Europe

  • Austria: +43 1 7986263-444
  • Turkey: +90 216 577 55 52
  • Russia: +7 495 6654993
  • Belgium: +32 9 321 75 70
  • United Kingdom: +44 1536 460866
  • France (toll-free): +33 3 88104000
  • Finland: +358 10 3224030 / +45 74436332
  • Netherlands: +31 347 320477
  • Italy: +39 0362 1826711
  • Ireland: +353 21 4804983
  • Portugal: +351 229 407 594
  • Denmark: +45 74436332
  • Spain: +34 938497433
  • Switzerland: +41 62 889 79 32
  • Germany: +49 711 3409 444
  • Sweden: +46 300 13990 / +45 74436332

Asia Pacific

  • Thailand: +66 210 54613
  • Japan: +81 45 471 2281
  • Singapore: +65 6829 2920
  • New Zealand: +64 9 6345350
  • China: +86 400-088-3566
  • Australia (toll-free): +61 3 9560 0621 / 1300 723 334
  • Taiwan: +886 70 1015 0068 (當地網路電話)
  • South Korea: +82 31 778 3390
Open contact form
Telephone:+49 711 3409-0
Mail: info@pilz.de

What can we do for you?


I understand that, unless I give my consent, any personal data collected will only be used for processing orders and dealing with my enquiries. Further information on data protection and contact details for our data protection officer are available here: Pilz data protection
Consent can be withdrawn at any time (E-Mail will suffice).

* Mandatory field