CRA in 2026: What Does it Mean for Suppliers of Digital Control Equipment

Author photo: Thomas Menze
ByThomas Menze
Category:
Industry Best Practice

Starting in 2026, companies that deliver digital control equipment—like programmable controllers, connected sensors, industrial gateways, and related software—will need to follow new, stricter rules set by the EU Cyber Resilience Act (CRA). Instead of just getting ready, they will be required to fully comply with the CRAs cybersecurity requirements.

From June 2026, conformity assessment bodies will become operational, enabling suppliers to begin formal compliance evaluations. Manufacturers and importers of digital control systems will be required to prove that their products meet the CRA’s essential cybersecurity requirements, such as secure-by-design development, vulnerability management, and mechanisms for timely software and firmware updates. Depending on the product’s criticality or potential impact, suppliers may need to undergo third-party assessments rather than relying on self-certification.

A major shift will occur in September 2026, when mandatory vulnerability and incident reporting obligations take effect. Suppliers will need to report actively exploited vulnerabilities and significant cybersecurity incidents to designated authorities within prescribed timeframes. This requirement will demand mature internal processes for vulnerability disclosure, incident response, and customer communication. Companies that have relied on ad hoc or informal practices will need to establish structured procedures and designate responsible teams to meet these new obligations.

Beyond product-level obligations, the CRA places strong emphasis on documentation and supply-chain security. Suppliers must maintain detailed technical files that demonstrate compliance, including design records, risk assessments, test results, and vulnerability management evidence. Moreover, they must manage cybersecurity risks throughout their supply chain, ensuring that third-party components and software also meet CRA requirements. The growing expectation for transparency may also lead to the adoption of Software Bills of Materials (SBOMs) to track dependencies and vulnerabilities.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients