1. Three sets of rules, two roles, one company
A machinery manufacturer that ships connected machines is caught by three European sets of rules at the same time - but in two different roles. As an entity with its own IT and production it falls under the NIS2 Directive, transposed in Germany through the new BSI Act since 6 December 2025. As a manufacturer of connected products it falls under the Cyber Resilience Act, whose reporting obligations have applied since 11 September 2026, and from 20 January 2027 under the Machinery Regulation, which for the first time makes cybersecurity a condition for CE marking. The three texts have different addressees, deadlines and supervisory routes - and they barely refer to one another.
| Legal act | Role | Applies since / from | Core obligation |
|---|---|---|---|
| NIS2, transposed in the German BSI Act (NIS2UmsuCG) | Entity (own IT and OT) | 6 December 2025 | Registration, risk management in ten areas, reporting of own incidents, duties of management |
| Cyber Resilience Act (Regulation (EU) 2024/2847) | Manufacturer (products with digital elements) | Reporting obligations 11 September 2026; all other obligations 11 December 2027 | Reporting of exploited vulnerabilities, security by design, software bill of materials, security updates over the support period, CE marking |
| Machinery Regulation (Regulation (EU) 2023/1230) | Manufacturer (machinery safety) | 20 January 2027 | Protection against corruption (Annex III 1.1.9), safety and reliability of control systems (1.2.1) |
State of the legal texts on 11 September 2026. Following the corrigendum in the Official Journal, the Machinery Regulation applies from 20 January 2027; the uncorrected version names 14 January.
How wide the gap between the legal position and preparation is, the Bitkom survey of 10 September 2026 shows (1,003 German companies with ten or more employees, surveyed April to June 2026): 67 percent know the Cyber Resilience Act by name, but only 29 percent know what it means for their own company; 28 percent have never heard of it. NIS2 fares no better: in the cybersecurity study of the TÜV association (Ipsos, 506 companies, February to March 2025, that is before the act entered into force) half of the respondents did not know the directive. And a study by VDMA and Fraunhofer AISEC (2025) found that around two thirds of the industrial companies surveyed are directly affected by the CRA and NIS2 - while about a quarter assumed they did not fall under NIS2.
2. The reporting obligation since 11 September 2026 - and why it hits the installed base
The Cyber Resilience Act as a whole applies only from 11 December 2027. Article 71, however, carves out the reporting obligations of Article 14 and sets them at 11 September 2026. Since that day, every manufacturer of a product with digital elements must report two kinds of events: actively exploited vulnerabilities in its product and severe incidents having an impact on the security of the product. The report goes simultaneously to the coordinating CSIRT of the Member State where the manufacturer has its main establishment and to ENISA - through a single platform.
The sentence missing from many summaries is in Article 69(3): by way of derogation from the transitional rule for existing products, the obligations laid down in Article 14 apply to all products with digital elements placed on the market before 11 December 2027. The product requirements - security by design, software bill of materials, updates - hit existing products only upon a substantial modification. The reporting obligation hits the entire installed base, including the 2014 line with the remote maintenance box that has been running at the customer for years. Whoever has 800 machines in the field has had a 24-hour clock for 800 machines since 11 September 2026.
| Stage | Actively exploited vulnerability (Article 14(2)) | Severe incident (Article 14(4)) |
|---|---|---|
| Early warning | within 24 hours of becoming aware: that a vulnerability is being exploited, which Member States are affected | within 24 hours of becoming aware: that an incident has occurred, whether unlawful or malicious acts are suspected |
| Notification | within 72 hours of becoming aware: nature of the vulnerability, affected products, mitigation measures taken | within 72 hours of becoming aware: nature of the incident, initial assessment, mitigation measures |
| Final report | no later than 14 days after a corrective or mitigating measure is available | no later than one month after submission of the notification |
| Users | Article 14(8): affected users must be informed about the vulnerability or incident and about corrective measures - where appropriate in a structured, machine-readable format | |
Deadlines under Article 14 of the Cyber Resilience Act. The 14 days for the final report run from the availability of the corrective measure, not from awareness - the most frequently misquoted detail in summaries. An intermediate report is owed only at the request of the CSIRT.
The reporting route is new and has three peculiarities that the BSI, Germany’s Federal Office for Information Security, names clearly on its page about the platform. First: reporting runs exclusively through ENISA’s Single Reporting Platform, not through the BSI portal - the BSI, with CERT-Bund, is the coordinating CSIRT for Germany and receives the report from there. Second: reports must be written in English. Third: no prior registration on the platform is required, an EU Login is enough. ENISA put the platform into operation on 11 September 2026 itself and speaks of an initial operating capability; anyone who takes the 24-hour deadline seriously should not set up access only when the emergency arrives.
What missed deadlines cost is governed by Article 64: infringements of the reporting and manufacturer obligations in Articles 13 and 14 carry fines of up to 15 million euros or 2.5 percent of worldwide annual turnover, whichever is higher. Under Article 64(10), micro and small enterprises are exempt only from the fine for missing the 24-hour deadline - not from the obligation itself, and small here means under 50 employees. For the typical machinery manufacturer the exemption does not apply.
3. What the CRA requires of every connected product from December 2027
Under Article 2, the CRA covers every product with digital elements whose intended purpose or reasonably foreseeable use includes a direct or indirect data connection to a device or network. A machine with a networked controller, an HMI on the network or a remote maintenance interface is therefore a product with digital elements; a connection through a cell controller counts as an indirect connection as well. The recitals name industrial control systems expressly as an example of products with long lifetimes. Medical devices, vehicles, aviation and marine equipment are excluded - machinery is not. The exemption for spare parts in Article 2(6) is narrow: it applies only to identical components manufactured to the same specifications, not to a modernised replacement controller.
For all products placed on the market from 11 December 2027, the essential requirements of Annex I apply. Part I describes the product: without known exploitable vulnerabilities, with a secure default configuration, with protection against unauthorised access, with security updates that can be installed. Part II describes the process behind it, and there sits the requirement everyone talks about: the manufacturer must document vulnerabilities and components of its product, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at least the top-level dependencies. Two clarifications that save a lot of anxiety: the obligation starts at the top-level dependencies, not at every library on the third level. And according to the BSI the bill of materials does not have to be published - it belongs in the technical documentation and is provided to market surveillance on request.
Then there is the support period. Article 13(8) requires the manufacturer to determine it so that it reflects the expected period of use of the product - and that it is at least five years. For machines that run for 15 to 25 years, five years is therefore the floor, not the target. During this period, security updates must be provided without delay and, unless otherwise agreed for a tailor-made product, free of charge; under Article 13(9) every update must remain available for at least ten years. The end date of the support period belongs in the user information and must be visible at the time of purchase. Whoever writes quotations today is, from December 2027, writing a commitment spanning years.
The good news lies in the classification. Annex III lists important products of classes I and II - routers, switches, operating systems, firewalls, microcontrollers with security-related functionalities and the like - and Annex IV critical products such as smart meter gateways. Controllers and industrial automation systems are not among them. A machine with a networked controller is a default product for which self-assessment under Article 32(1) is sufficient; and Article 7(1) makes clear that integrating a component from Annex III does not make the machine itself an important product. The position differs only for anyone who places a listed product on the market under their own name - an own-brand industrial firewall, say, or an own gateway.
What is missing is standards and experience. No harmonised standards for the CRA have been cited in the Official Journal so far; the standardisation work runs under the Commission’s request in the EN 40000 series, and the widespread assumption that EN 18031 is the CRA standard is wrong - it belongs to the Radio Equipment Directive. The Commission’s guidance on applying the CRA appeared on 27 July 2026, seven weeks before the first hard deadline. For costs there is only the Commission’s impact assessment of 2022, which puts self-assessment at an average of 18,400 euros per company - a model assumption from before adoption, not a measurement.
4. NIS2: the obligations as an entity
The second layer concerns the company itself. The German NIS2 implementation act entered into force on 6 December 2025 and completely recast the BSI Act. Who is covered is governed by section 28: an important entity is anyone assigned to a type of entity in Annexes 1 and 2 who has at least 50 employees or more than 10 million euros in both annual turnover and balance sheet total. Mechanical engineering is in Annex 2 literally: sector manufacturing, branch mechanical engineering, companies with economic activities under NACE division 28. Two consequences are often overlooked: a pure machinery manufacturer can only ever be an important entity, never a particularly important one, because manufacturing does not appear in Annex 1. And the thresholds apply to the company, not the group - under section 28(4), affiliated companies are not added where the IT is genuinely operated independently.
The first obligation is registration. Section 33 requires it no later than three months after a company first qualifies as an entity - for everyone already covered on 6 December 2025 that was 6 March 2026, with no general transition period. According to the BSI, 17,729 entities were recorded in the registration portal as at 30 June 2026, 11,501 of them as important entities; 4,095 were in the manufacturing sector. The BSI provides an applicability check, but itself points out that it offers orientation only and does not replace self-assessment; anyone who does not register can be registered by the BSI and sits in the fine bracket of up to 500,000 euros.
The core is the measures under section 30: risk analysis and security concepts, incident handling, business continuity with backup and crisis management, supply chain security, security in acquisition, development and maintenance including vulnerability management and disclosure, effectiveness assessment, training, cryptography, personnel security and access control, multi-factor authentication - each according to the state of the art and proportionate to size. That there is work to do is shown by the DIHK digitalisation survey 2026 (4,686 companies, November 2025): only 40 percent operate an information security management system, 30 percent have an emergency plan, 13 percent rehearse it. Among companies with 1,000 or more employees, every second one was affected by at least one significant cybersecurity incident in the past year.
Two provisions address management directly. Section 32 requires significant security incidents to be reported to the BSI in the same stages as under the CRA - initial report within 24 hours, report within 72 hours, final report within one month - but through the BSI portal and for incidents in the company’s own systems. And section 38 obliges management personally to implement the risk management measures and monitor their implementation, to attend training regularly, and to be liable to their own entity for culpably caused damage under the rules of company law. The fines under section 65 reach up to 7 million euros for important entities; the frequently quoted percentages of turnover only apply from 500 million euros of group turnover. Supervision of important entities is event-driven - the BSI examines when there is a reason, and a reported incident is one.
5. Machinery Regulation: cybersecurity becomes product safety
The third layer arrives on 20 January 2027 with the Machinery Regulation, which we have already covered in detail in the article on digital instructions for use. For cybersecurity, two sections of Annex III are new. Section 1.1.9, protection against corruption, requires that software and data critical to the machine’s compliance are identified as such and protected against accidental or intentional corruption, that the machine identifies the installed software necessary for safe operation, and that it collects evidence of legitimate or illegitimate intervention in the software. Section 1.2.1 requires control systems to withstand reasonably foreseeable malicious attempts by third parties and to keep a log of interventions and of the versions of the safety software accessible for up to five years after upload.
The relationship with the CRA is frequently misrepresented. The CRA grants no presumption of conformity for the Machinery Regulation. Its recital 53 only says that compliance with the CRA requirements could facilitate compliance with sections 1.1.9 and 1.2.1 - and that such synergies must be demonstrated by the manufacturer, who must follow both conformity assessment procedures. The only genuine presumption is in Article 20(9) of the Machinery Regulation and runs through certificates under the Cybersecurity Act, that is, through European certification schemes that do not yet exist for machinery. In practice this means one security concept, two sets of evidence, and the mapping of which measure satisfies which requirement must be documented by the manufacturer itself.
6. Report twice, organise once
The most uncomfortable consequence of the three sets of rules is double reporting. If a vulnerability in a machine’s remote maintenance software is actively exploited and the attack also hits the company’s own service network, the same incident has to be reported once under the CRA through the ENISA platform and once under the BSI Act through the BSI portal. The BSI answers the question of whether this can happen with a clear yes on its page about the platform. There is no rule under which one report replaces the other. In November 2025, as part of the Digital Omnibus, the Commission proposed a single entry point at ENISA for all reporting obligations; on 11 September 2026 that part of the package was still in the Council and not adopted - unlike the AI part, which entered into force in July 2026.
What can be organised is the process behind it. A single workflow for security incidents - detection, assessment, containment, communication - with two outputs: one for the company’s own entity under section 32 of the BSI Act, one for the product under Article 14 of the CRA. The same logic carries the measures: whoever builds vulnerability management, supply chain security and secure development according to IEC 62443 serves the ten areas of section 30, the process requirements of Annex I Part II and sections 1.1.9 and 1.2.1 of the Machinery Regulation with the same system. The VDMA, the German mechanical engineering association, has published a supplier self-assessment whose questions are expressly mapped to the CRA, NIS2 and the Machinery Regulation at once - a usable starting point, because the supply chain appears in all three texts.
7. The knowledge problem behind the 24 hours
The deadline is not the real problem. The real problem is the question that must be answered in the first hours: Which of our products, in which versions, at which customers are affected? The early warning requires the affected Member States, the notification the affected products, the user information under Article 14(8) the specific customers. Whoever has to piece that answer together from service reports, delivery lists, firmware versions in spreadsheets and the memory of the service technician has used up the 24 hours before the report begins.
In our view the CRA is therefore above all a data problem disguised as a security problem. Three sets of records must fit together for every machine: the software bill of materials per product version, the installed base with serial number, configuration level and customer, and the technical documentation containing the mitigation measure for exactly this configuration. These are the same three records that speed up service when no vulnerability is involved - where AI demonstrably works in after-sales and what it requires hinges on exactly this data basis. A knowledge system that answers in seconds which machines at customer X carry controller version Y with remote maintenance component Z is a productivity tool for service and, for the reporting obligation, the difference between a reliable and a guessed early warning. The regulations supply the budget argument that data projects in service otherwise lack.
8. Six steps to take now
- Set up access to the reporting platform and rehearse the reporting process. Create an EU Login, name the people responsible for the 24-hour early warning - including at weekends - and prepare an English reporting template. Do the same for the BSI portal for your own entity, if registration is still outstanding.
- Record the installed base with software versions. Which machine stands where, with which controller, which firmware, which remote maintenance component? Without this list no early warning is reliable. It is also the first step towards the software bill of materials that becomes mandatory for new products from December 2027.
- Check and document NIS2 applicability. Record employees, turnover, balance sheet total and NACE classification, catch up on registration if it is missing, and brief management on section 38 - including the training obligation.
- Set up an incident process with two outputs. One detection and assessment chain, at the end two reporting routes: BSI portal for the entity, ENISA platform for the product. Who decides in the first hour whether an incident is reportable, and by which criteria?
- Define the support period and update process for new products. For everything shipped from December 2027: how long are security updates provided, who builds them, how do they get onto the machine at the customer, and how does the end date appear in the quotation? This commitment shapes product planning, not just documentation.
- Write one security concept mapped to all three texts. Describe each measure once, then map it: section 30 of the BSI Act, Annex I of the CRA, Annex III of the Machinery Regulation. That table is the evidence recital 53 demands from the manufacturer - and the key to keeping three sets of rules from becoming three projects.
9. When you are under (almost) no pressure to act
Honesty is part of it, so here is the other direction. Three situations in which the three sets of rules demand little today:
- Your machines have no data connection - not even an indirect one. Purely mechanical or electrical machines without a network connection, without remote maintenance and without a data interface are not products with digital elements. Then the CRA does not affect you, and the cybersecurity sections of the Machinery Regulation are largely empty for you. Check this honestly: a USB port for diagnostics and a fieldbus into the customer network are data connections.
- You are below the NIS2 thresholds and stay there. Under 50 employees and under 10 million euros in turnover or balance sheet total, you are not an important entity. The customers you supply may well be, though - and their supply chain obligation under section 30 will arrive at your door as a questionnaire.
- You have already organised product security according to IEC 62443. Whoever has introduced secure development, vulnerability management and supplier assessment mainly needs to map and document for the CRA and the Machinery Regulation, not rebuild. What remains is the reporting organisation - IEC 62443 did not know it in this form.
For everyone else: the reporting obligation is live, the platform is up, and the clock starts with awareness - not with the end of the project that builds the data basis. According to Bitkom (Wirtschaftsschutz 2026, 1,003 companies), 23 percent of companies report physical sabotage of production facilities or operational processes. The awareness that starts the clock often comes not from inside the company, but from the customer whose line is down.
10. Frequently asked questions
Does the CRA reporting obligation also cover machines we shipped years ago?
Yes. Article 69(3) of the Cyber Resilience Act makes clear that the reporting obligations under Article 14 apply to all products with digital elements placed on the market before 11 December 2027. The other product requirements apply to existing products only after a substantial modification - the reporting obligation applies to the entire installed base, since 11 September 2026.
Do we have to report an actively exploited vulnerability in full within 24 hours?
No. Within 24 hours of becoming aware, an early warning is due that essentially says a vulnerability is being exploited and which Member States are affected. Within 72 hours follows the actual vulnerability notification with general information and mitigation measures. The final report is due no later than 14 days after a corrective measure is available - not 14 days after awareness.
Is reporting to the BSI enough?
Not for the CRA. The report is submitted through ENISA's Single Reporting Platform, in English, and reaches the BSI from there as the coordinating CSIRT. If the company is also covered by NIS2 as an entity and the incident affects its own systems, it must additionally be reported under the German BSI Act through the BSI portal. The BSI confirms expressly that both reports can be due side by side.
Does a machinery manufacturer with 80 employees fall under NIS2?
Very probably yes. Annex 2 to the German BSI Act names mechanical engineering (NACE division 28) explicitly; the threshold for an important entity is at least 50 employees or more than 10 million euros in both annual turnover and balance sheet total. A machinery manufacturer can only ever be an important entity, never a particularly important one, because manufacturing is not listed in Annex 1. Registration with the BSI was due within three months of the act entering into force.
Is a programmable logic controller an important product under Annex III of the CRA?
No. Annex III lists routers, switches, operating systems and microcontrollers with security-related functionalities, among others, but no controllers and no industrial automation systems. A machine with a networked controller is a default product for which self-assessment is sufficient - and under Article 7(1), integrating a component listed in Annex III does not make the machine itself an important product.
11. Sources
Legal texts in their consolidated versions, official information and studies with survey data. Studies by associations and vendors with an interest of their own are marked as such. Several sources are in German; the English article cites them because they are the actual evidence.
- Cyber Resilience Act: Regulation (EU) 2024/2847, consolidated version with corrigenda (Articles 2, 3, 7, 13, 14, 32, 64, 69, 71; Annexes I, III, IV; recitals 53 and 57).
- Machinery Regulation: Regulation (EU) 2023/1230, consolidated version (Article 20(9), Article 54; Annex III sections 1.1.9 and 1.2.1).
- NIS2 transposition: German BSI Act as amended by the NIS2 implementation act of 2 December 2025 (Federal Law Gazette 2025 I No. 301), in force since 6 December 2025 (sections 28, 30, 32, 33, 38, 65; Annex 2). In German.
- BSI, press release on the start of the CRA reporting obligation (11 September 2026); information on the Single Reporting Platform; NIS-2 in figures (registration status 30 June 2026); NIS-2 applicability check. In German.
- ENISA, launch of the Single Reporting Platform (11 September 2026); European Commission, reporting obligations under the CRA, guidance on applying the CRA (27 July 2026) and impact assessment SWD(2022) 282 (September 2022): cost estimates.
- Bitkom, press release on the Cyber Resilience Act (10 September 2026; industry association; 1,003 companies with ten or more employees, April to June 2026): awareness and preparation; Wirtschaftsschutz 2026 (26 August 2026, same sample): sabotage of production facilities. In German.
- DIHK, digitalisation survey 2026 (PDF, 4,686 companies, surveyed November 2025): information security management, emergency preparedness, incidents. In German.
- TÜV association, cybersecurity study 2025 (PDF; Ipsos, 506 companies, February to March 2025; association of testing organisations): awareness of NIS2. In German.
- Fraunhofer AISEC and VDMA, study Industrial Security (press release, April 2025; association and research institute, sample size not stated in the release): companies affected by the CRA and NIS2; VDMA, topic page Cyber Resilience Act with supplier self-assessment. In German.
Three sets of rules that barely mention each other meet in the same control cabinet in machinery manufacturing. Whoever treats them as three projects will document three times and report late once. Whoever treats them as one question - which machine, which software, which customer, which measure - ends up with one incident process, one security concept and one data basis that earns money even if no vulnerability is ever exploited. The 24 hours have been real since 11 September 2026. What is possible within them is decided beforehand.



