AdobeStock_2092281188_AdobeStock_456077484

With the Cyber Resilience Act, the European Union is establishing mandatory cybersecurity requirements for products containing digital elements. This also includes machines and automation solutions equipped with controllers, network interfaces, remote maintenance access, or cloud connections. Consequently, cybersecurity is shifting from a competitive advantage to a legal obligation.

icon_19_schnelle_installation_updates_engineering_rgb
When does the CRA take effect?
  • September 11, 2026: Mandatory reporting of actively exploited vulnerabilities and serious security incidents
  • December 11, 2027: Full implementation of the Cyber Resilience Act
icon_10_teamarbeit_rgb
Who is affected?
  • Manufacturers of machines and equipment with digital components
  • Manufacturers of software and automation solutions
  • Integrators who develop their own products based on components
icon_energy_security_rgb
What does the CRA demand?
  • Security by design and security by default
  • Risk assessment during development
  • Vulnerability management throughout the entire product lifecycle
  • Security documentation for users
  • Security updates during the defined support period
  • Documentation and verification of implemented security measures
  • Message about actively exploited vulnerabilities
icon_48_opc_ua_alarms_conditions_rgb
When does the CRA apply to me?
  • What matters is not when a product was developed, but when it is made available on the European market.
  • Even existing product lines that continue to be sold after December 11, 2027, must meet the requirements.
topology CRA Timeline

Security you can count on.

We support you on your path to CRA compliance with certified products, security features and clear processes.

icon_zertifikat_rgb
IEC 62443-4-1 certified

Secure development processes since 2024

icon_zertifikat_rgb
IEC 62443-4-2 certified

M200 automation components

icon_50_service_rgb
Over 50 years of experience

In industrial automation

globe
20 locations worldwide

Support throughout the entire life cycle

Having a secure controller does not make your machine CRA-compliant.

The use of a controller developed in accordance with IEC 62443 is an important component – but it does not constitute the entire proof of compliance. The responsibility for the end product’s compliance remains with the machine manufacturer. That is precisely why we clearly outline what we provide and what remains your responsibility.

Here's what Bachmann offers

Here's what remains your responsibility

  • Products developed in accordance with IEC 62443-4-1
  • Components certified in accordance with IEC 62443-4-2
  • Built-in security functions
  • Security updates during the defined support period
  • Documentation and evidence at the component level
  • Information about relevant vulnerabilities
  • Overall machine architecture
  • Network design and segmentation
  • Threat analysis for your machine
  • Security documentation for the end user
  • Remote maintenance concept
  • User and permissions management
  • Update management throughout the product lifecycle
  • Technical documentation and CE compliance

You don't have to start from scratch.

Those who rely on components that have already been developed in accordance with IEC 62443-4-1 and 4-2 can significantly reduce the effort required for implementation and compliance documentation.

What you can expect from us.

The CRA affects the entire supply chain. As a component manufacturer, we lay the foundation on which you can build your own compliance.

icon_energy_security_rgb
Secure Products

Our controllers are developed in accordance with established security standards. Security is an integral part of product development, not an afterthought.

icon_access_control_rgb
Security Features

Encrypted communication, role-based access rights, Secure Boot, secure updates, and end-to-end security logging – all integrated, not just tacked on.

icon_support_rgb
Updates and Support

Security updates throughout the defined support period in full accordance with CRA requirements

icon_37_keine_mehrfachen_datenpunktlisten_rgb
Documentation and Evidence

Certification records, security documentation, and information on vulnerabilities – as a basis for your own documentation.

Security at every layer – from communication to application

The CRA does not require a single security feature, but a holistic approach to protection. At Bachmann, protection is based on the principle of defense in depth: coordinated protection and hardening measures across different levels of the control system increase resilience and limit the impact of an attack.

topologie_CRA_Sicherheitsebenen_EN_rgb

Find out more

communication information security
Bachmann Security

Communication and information security. Simple. Efficient. Secure.

Security_Einbrecher_Fotolia_158269205_S_lichtpunkt_bearb
atvise® Security Check

Safe facilities are the result of many small decisions made during commissioning and operation.