< Back to situation

[REVISION HISTORY]

EU digital and mechanical product regulations

Updated 2 times since CLSTR started tracking revisions of this situation.

What changed

2026-08-25 08:56 UTC → 2026-09-08 07:23 UTC · added removed

The European Union is implementing new regulatory frameworks to enhance the safety and security of digital and mechanical products. The EU Machine Regulation (EU) 2023/1230, set to become mandatory on January 20, 2027, establishes safety requirements for machines and their components. This regulation introduces complex requirements for risk assessment and cybersecurity, notably through the concept of “essential change,” which can shift manufacturer responsibilities to operators if hardware or software is altered. Complementing these measures, the Cyber Resilience Act (CRA), officially Regulation (EU) 2024/2847, mandates cybersecurity requirements for products with digital elements. Having entered into force on December 10, 2024, the CRA requires a ‘Security by Design’ approach, ensuring cybersecurity is integrated from the initial stages of development. The regulation covers hardware and software with network connectivity, regardless of whether they connect via the public internet. Obligations span the entire product lifecycle, including secure development, providing security updates, maintaining technical documentation, and managing a Software Bill of Materials (SBOM). While the NIS-2 directive focuses on organizational operations in critical sectors, the CRA specifically regulates the digital products themselves. Key milestones include the start of reporting requirements for actively exploited vulnerabilities and serious security incidents on September 11, 2026. Under the CRA, companies must adhere to strict reporting timelines, including early warnings within 24 hours and full reports within 72 hours. Full applicability, including CE marking requirements, is expected by December 11, 2027. To support compliance, Germany’s BSI has released technical guideline TR-03183, which provides practical guidance on IT security processes and SBOM formats like SPDX and CycloneDX, intended to be gradually replaced by harmonized European standards. The implementation of the CRA is shifting corporate security toward continuous vulnerability management, as AI-driven security tools increase the number of identified vulnerabilities, placing higher administrative burdens on IT departments to manage digital supply chains.

Versions

  1. 2026-09-08 07:23 UTC EU digital and mechanical product regulations
  2. 2026-08-25 08:56 UTC EU digital and mechanical product regulations
  3. 2026-08-14 10:32 UTC EU digital and mechanical product regulations

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.