ei³ releases Cyber Resilience Act guide for machine builders
ei3 released an educational guide on July 8 to help machine builders deal with European Union’s Cyber Resilience Act (CRA). The guide, “Preparing for the Cyber Resilience Act: a guide for machine builders”, explains how CRA may affect OEMs and industrial automation suppliers as connected machines, gateways, embedded software, remote access systems, and cloud-connected applications become part of the cybersecurity attack surface.
Unlike many cybersecurity requirements that mostly focus on how technology is operated, CRA emphasizes the security of products with digital elements. For industrial machinery builders, this creates important implications for product design, vulnerability handling, software updates, asset visibility, customer communication, and lifecycle support.
“Connected machinery is no longer static equipment once it leaves the factory,” says the guide’s author, Adam Griffen, cybersecurity and compliance subject matter expert at ei3. “As machines become more connected and software-driven, machine builders need repeatable processes for identifying vulnerabilities, assessing impact, communicating with customers, and supporting remediation throughout the product lifecycle.”
The guide outlines practical considerations for OEMs preparing for CRA-related obligations, including:
- How CRA applies to connected industrial machinery and automation systems;
- Why vulnerability handling must become a structured lifecycle process;
- The role of international cybersecurity standards such as IEC 62443 and the NIST Cybersecurity Framework;
- Why asset management and software bills of materials (SBOM) are becoming essential;
- How secure remote service can help machine builders support remediation in the field; and
- Practical steps to prepare for CRA’s September 2026 and December 2027 milestones.
For many industrial OEMs, CRA readiness will require more than a one-time compliance review. Machines often remain in service for 10, 15 or even 20 years, and vulnerabilities may emerge long after initial deployment. The guide emphasizes that machine builders need visibility into deployed assets, a clear understanding of software and firmware components, and secure ways to support customers when updates or mitigations are required.
“CRA is an important signal that cybersecurity is becoming a fundamental product responsibility,” adds Spencer Cramer, CEO of ei3. “For machine builders, this is not only about compliance. It’s about customer trust, service readiness, and the ability to support connected machines responsibly across their operational life.”
The guide also highlights the growing importance of secure remote service as a practical method for vulnerability remediation. In industrial environments, ei3 adds that updates can’t always be deployed immediately or handled like traditional IT patches. Production schedules, safety requirements, customer access policies, and machine availability all affect how remediation is performed. Secure remote service can help OEMs assess issues, coordinate with customers, apply updates, verify changes, and document activity without requiring unnecessary site visits.

