COMPARISON · CRA
CRA vs the Machinery Regulation
Machine builders adding connectivity or software-defined safety functions need to know which requirements sit under machinery safety law and which sit under the CRA.
LAST REVIEWED
What is different
- Primary concern: the Machinery Regulation is about physical safety — the machine must not injure people; the CRA is about cybersecurity — the product's digital elements must resist compromise.
- Scope of subject matter: the Machinery Regulation covers machinery and related products as defined in its annexes; the CRA covers products with digital elements broadly, machinery or not.
- Historical basis: the Machinery Regulation replaces and updates the Machinery Directive 2006/42/EC, extending it to address digital risks explicitly for the first time; the CRA is new horizontal cybersecurity legislation.
- Conformity route: machinery conformity assessment follows established Notified Body and self-certification routes tied to machinery categories in the annexes; CRA conformity assessment routes depend on the product's risk classification under the CRA.
What overlaps
The Machinery Regulation was updated specifically to recognise that a cybersecurity compromise of a safety-related control system can create a physical safety hazard — for example, a manipulated sensor signal disabling a guard interlock. Where a cybersecurity vulnerability could lead to a hazardous situation, machinery safety requirements and CRA-relevant secure-design practice converge on the same root cause: the integrity of the safety-related control function.
Both frameworks expect a documented risk assessment, a technical file, and a declaration of conformity supported by evidence. Where a machine's safety function depends on software or network communication, the risk assessment, secure architecture and verification evidence built for CRA purposes should feed directly into the machinery risk assessment rather than being produced twice.
Which applies to you
- You build machinery with no meaningful digital elements affecting safety: the Machinery Regulation applies; CRA relevance is limited or absent.
- You build machinery with connectivity, remote monitoring or software-based safety functions: both apply, and the interaction between cybersecurity risk and safety risk should be assessed together, not as separate silos.
- You supply a connected component (a sensor, drive or controller) into someone else's machine: you may have CRA obligations as a manufacturer of a product with digital elements, while your customer carries the machinery-level obligations for the finished machine.
- You are updating an existing machine design to add connectivity: treat this as triggering both a machinery risk re-assessment and a CRA scoping exercise, since either can change your conformity route.
Frequently asked questions
Does the Machinery Regulation replace the need for CRA compliance?
No. The Machinery Regulation addresses safety risks, including those introduced by cybersecurity weaknesses in safety functions, but it does not replace the CRA's broader requirements on secure development, vulnerability handling and reporting for the product's digital elements generally.
When did the new Machinery Regulation start applying?
Regulation (EU) 2023/1230 entered into force in 2023 and applies from 20 January 2027, replacing the Machinery Directive 2006/42/EC. Manufacturers should plan transition alongside CRA timelines, since both mature around similar dates.
Can one risk assessment cover both safety and cybersecurity?
Not as a single generic document, but the underlying hazard identification, architecture and verification work can and should be integrated so that a cybersecurity weakness affecting a safety function is visible in both the machinery risk assessment and the CRA-relevant security risk assessment.
Who carries the CRA obligation for a machine built from third-party components?
The manufacturer that places the finished machine on the market generally carries the primary obligations for the machine as a whole, while component suppliers carry their own manufacturer obligations for the components they place on the market, including providing the information the machine builder needs.