# Cyber Resilience Act for machine builders – reporting, support period and user information

> The Cyber Resilience Act, Regulation (EU) 2024/2847, applies to products with digital elements – including machines and components with software and a data connection. Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents within 24 hours (early warning), 72 hours (notification) and later with a final report via ENISA's Single Reporting Platform. From 11 December 2027, all requirements apply: cybersecurity under Annex I, a support period of generally at least five years with its end date shown at purchase, a single point of contact for vulnerability reports and user information under Annex II that remains available for at least ten years.

Source: https://manualpass.eu/en/guides/cyber-resilience-act-machinery/ · Updated: 07/10/2026 · ManualPass (https://manualpass.eu)

After the Machinery Regulation comes the next deadline: the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, sets cybersecurity requirements for all products with digital elements. For machine builders this is no side issue – almost every modern machine has a controller, a network interface, remote maintenance or a USB port for updates.

Part of the CRA already applies: since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents. This guide shows what applies when and what you should prepare now.

## Which machines does the CRA apply to?

The CRA applies to products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect, logical or physical data connection to a device or network (Article 2). This covers:

- machines with controls and network connection, remote maintenance or cloud connectivity,
- machines whose software can be changed via an update interface or storage medium,
- purchased components such as controllers, operator panels, routers or drives with a data connection – here their manufacturer is responsible first.

Machinery is not excluded. The CRA applies **in addition** to the Machinery Regulation: the Machinery Regulation requires, among other things, protection against corruption and safe control systems, while the CRA governs the cybersecurity of the product over its entire life cycle.

!!! fakt "Two deadlines"
    11 September 2026: reporting obligations under Article 14. 11 December 2027: all other obligations, including CE marking under the CRA.

## Since 11 September 2026: reporting vulnerabilities and incidents

If a manufacturer becomes aware of an **actively exploited vulnerability** in its product or of a **severe security incident** affecting the security of the product, it must report it – via ENISA's Single Reporting Platform to the competent CSIRT (Article 14). The obligation also applies to products placed on the market before that date.

| Step | Deadline | Content |
|---|---|---|
| Early warning | 24 hours after becoming aware | affected product, first assessment |
| Notification | 72 hours after becoming aware | general information, measures taken or recommended |
| Final report | vulnerability: no later than 14 days after a corrective measure is available; incident: within one month of the notification | description, root cause, remedy |

You must also inform the affected users – about the vulnerability or incident and, where necessary, about risk mitigation measures.

!!! achtung "Common misconception"
    “The deadline starts when we know the cause.” It starts when you become aware of the actively exploited vulnerability or the incident. Whoever first searches internally for who is responsible loses the first day.

## From 11 December 2027: all manufacturer obligations

From this date, products with digital elements may only be placed on the market if they meet the essential cybersecurity requirements of Annex I and the CE marking also covers the CRA. For machine builders this means above all:

- **Develop and ship securely:** secure default configuration, protection against unauthorised access, minimal attack surface, data protection.
- **Handle vulnerabilities:** keep a software bill of materials (SBOM), fix vulnerabilities without delay, provide security updates free of charge and disclose fixed vulnerabilities.
- **Single point of contact:** a contact address for vulnerability reports and a coordinated vulnerability disclosure policy.
- **Set a support period** and provide security updates during it.
- **Provide user information under Annex II.**

For most products an internal conformity assessment is sufficient. Stricter procedures apply to “important” and “critical” products under Annexes III and IV – mainly purchased components such as routers, firewalls or certain microcontrollers. Infringements of the essential requirements and the obligations under Articles 13 and 14 can be fined up to EUR 15 million or 2.5 % of worldwide annual turnover.

## Support period: at least five years, end date at purchase

The manufacturer determines the support period so that it reflects the expected time of use – generally **at least five years** (Article 13). For machines that often run for 15 years or more, it will tend to be longer. Important for documentation:

- The **end date** of the support period, at least month and year, must be **clearly visible at the time of purchase**.
- Each security update remains available after release for at least ten years or for the remainder of the support period, whichever is longer.

!!! tipp "Practical tip"
    Set the support period per machine type and show it where the customer looks anyway: on the scan page at the QR code, next to the instructions for use and the EU declaration of conformity.

## User information under Annex II

The CRA requires its own information and instructions for users. They may be provided **in paper or electronic form** and must remain available for at least **ten years** after placing on the market or for the support period, whichever is longer. Annex II includes, among other things:

| Item | Example |
|---|---|
| Manufacturer with address and digital contact | company, address, e-mail, website |
| Single point of contact for vulnerabilities and link to disclosure policy | security@your-company.com, policy link |
| Unique product identification | name, type, serial number |
| Intended purpose and security properties | operating environment, essential functions |
| Known risks, including foreseeable misuse | e.g. unprotected remote access |
| Address of the EU declaration of conformity | link to the declaration |
| Type of security support and end of support period | “Firmware updates until 12/2032” |
| Instructions for secure commissioning, updates and decommissioning | incl. secure deletion of user data |
| Where to find the SBOM, if you share it | optional |

This fits what you are building for the Machinery Regulation anyway: [digital instructions for use](https://manualpass.eu/en/digital-instructions-for-use/) at the QR code that remain available for at least ten years.

## What machine builders should do now

- ☐ Check which machine types and components are products with digital elements.
- ☐ Define a reporting process for actively exploited vulnerabilities: who decides, who reports, who stands in during holidays?
- ☐ Set up access to ENISA's Single Reporting Platform.
- ☐ Set up a central address for security reports and publish a coordinated vulnerability disclosure policy.
- ☐ Set the support period per machine type and make it visible to customers.
- ☐ Request CRA information and SBOMs for controllers and components from suppliers.
- ☐ Decide how customers are informed about security updates and vulnerabilities.
- ☐ Add the user information under Annex II to your documentation.

Only the text published in the Official Journal of the EU is legally binding. This guide is general information and not legal advice.

## How to implement this with ManualPass

With [Security & Support](https://manualpass.eu/en/features/security-support/), the scan page of every machine with digital elements shows the support period, your security contact, the disclosure policy and all published security advisories. Security researchers and customers report vulnerabilities directly to you via a form; if you mark a report as actively exploited, ManualPass tracks the 24- and 72-hour deadlines and sends e-mail reminders. With [safety notices](https://manualpass.eu/en/features/safety-notices/), you inform everyone who scans the QR code and your operators by e-mail – with read confirmation. You store the user information under Annex II as a document next to the instructions for use and the EU declaration of conformity.

## Frequently asked questions

**Does the Cyber Resilience Act apply to machinery?**
Yes, if the machine is a product with digital elements: software or hardware with a direct or indirect, logical or physical data connection to a device or network. Typical examples are machines with controls, network connections, remote maintenance or an update interface. Machinery is not excluded from the CRA; it applies in addition to the Machinery Regulation.

**When do the CRA obligations apply?**
The reporting obligations under Article 14 have applied since 11 September 2026 – also for products placed on the market before that date. All other requirements, including cybersecurity, support period, user information and CE marking under the CRA, apply from 11 December 2027.

**What are the reporting deadlines?**
For actively exploited vulnerabilities and severe incidents: early warning within 24 hours of becoming aware, notification within 72 hours and a final report – for vulnerabilities no later than 14 days after a corrective measure is available, for incidents within one month of the notification. Reports are made via ENISA's Single Reporting Platform.

**How long must the support period be?**
It should reflect the expected time of use and is generally at least five years – shorter only if the product is expected to be used for a shorter time. The end date, at least month and year, must be clearly visible at the time of purchase.

**May user information under the CRA be provided digitally?**
Yes. The information and instructions under Annex II may be provided in paper or electronic form. They must be understandable and remain available for at least ten years after placing on the market or for the support period, whichever is longer.

## Sources

- [Regulation (EU) 2024/2847 – Cyber Resilience Act (EUR-Lex)](https://eur-lex.europa.eu/eli/reg/2024/2847/oj)
- [European Commission: Cyber Resilience Act](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act)
- [ENISA: Single Reporting Platform – FAQ](https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions)
- [Regulation (EU) 2023/1230 – Machinery Regulation (EUR-Lex)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R1230)

---
Note: general information, not legal advice.
