INDUSTRY · Industrial automation
Industrial automation: IEC 62443, machinery safety and CRA
Industrial automation carries the heaviest overlap of any sector: functional safety, cybersecurity and product regulation all apply simultaneously with no broad exclusions.
LAST REVIEWED
Regulatory picture
Unlike defence, automotive or medical devices, industrial automation has no equivalent CRA exclusion for its core products. PLCs, industrial gateways, HMIs, drives, sensors and controllers with digital elements fall within the CRA as products with digital elements, and some categories intersect with the CRA's Annex III 'important' classification for industrial control systems. Functional safety follows IEC 61508 directly or through sector derivatives such as IEC 61511 (process industry safety instrumented systems) and IEC 62061 (machinery safety-related control systems). Cybersecurity follows the IEC 62443 series, addressing asset owners, system integrators and component/product suppliers separately. Machinery incorporating these components additionally falls under the Machinery Regulation (EU) 2023/1230, applicable from 20 January 2027, which explicitly recognises cybersecurity risk to safety functions. NIS2 also applies to operators of critical infrastructure using industrial automation, layering operator-level obligations on top of the equipment manufacturer's CRA obligations.
Typical engineering challenges
- Integrating IEC 61508/61511-based functional safety analysis with IEC 62443 cybersecurity risk assessment for the same safety-related control system.
- Determining CRA classification for control system components that may qualify as 'important' products under Annex III, changing the available conformity assessment route.
- Coordinating machinery-level risk assessment under the Machinery Regulation with component-level CRA and IEC 62443 evidence from multiple suppliers.
- Managing long asset lifecycles, often 15–25 years, against CRA support period definitions and evolving vulnerability landscapes.
- Retrofitting cybersecurity practice into brownfield installations designed before network connectivity was assumed.
How CRA interacts with sector rules
For a component manufacturer, the CRA sets the baseline product-level obligations, IEC 62443-4-x provides a credible technical basis for demonstrating the secure development and technical requirements, and the manufacturer must separately determine whether its product falls under Annex III's 'important' classification. For a system integrator or machine builder assembling components into a finished machine, the Machinery Regulation's safety risk assessment must incorporate the cybersecurity risk profile of the integrated components, which in turn depends on the CRA and IEC 62443 evidence each component supplier provides. For the asset owner operating the finished system, NIS2 (where applicable) drives operational risk management that depends on the same underlying inventory and vulnerability handling data.
What a typical engagement covers
- CRA classification and conformity route determination for control system product lines, including Annex III assessment.
- Integrated functional safety and IEC 62443 cybersecurity risk assessment for safety-related control systems.
- Machinery Regulation readiness for machine builders integrating third-party connected components.
- Long-lifecycle vulnerability handling and support period planning for industrial asset owners and manufacturers.
Frequently asked questions
Is industrial control system equipment excluded from the CRA?
No. Unlike defence, automotive or medical devices, there is no sector-wide CRA exclusion for industrial automation and control system equipment. Most such products fall within full CRA scope, and some categories may additionally qualify as 'important' products under Annex III.
How does IEC 62443 relate to CRA conformity?
IEC 62443, particularly the 4-1 and 4-2 parts addressing secure product development and technical security requirements, provides a credible, widely recognised technical basis that manufacturers can use to structure the evidence needed for CRA conformity assessment, though it is not automatically a harmonised standard conferring presumption of conformity.
Does the Machinery Regulation replace IEC 62061 or IEC 61508 for machinery safety?
No. The Machinery Regulation sets the legal essential health and safety requirements; IEC 62061 and IEC 61508 remain the technical standards used to design and demonstrate the safety-related control functions that satisfy those legal requirements, now with explicit attention to cybersecurity risk affecting safety.
How should a long-lifecycle industrial asset handle CRA support period requirements?
Manufacturers must define and communicate a support period for vulnerability handling. For assets with a much longer physical service life than the defined digital support period, asset owners need a clear plan for the gap, including compensating controls, network segmentation or planned replacement.