EU Cyber Resilience Act
CRA compliance for industrial automation
Industrial automation and OT products with digital elements fall under the Cyber Resilience Act. Category depends on the product; many are default-category, while some controllers may be treated as important.
Default category is still the common case
Most industrial automation and OT products with digital elements are default category, despite the sector's reputation for heavier regulation. The CRA's important-products list (Annex III) names specific functions — operating systems, network management systems, physical/virtual network interfaces, and microprocessors or microcontrollers with security-related functionality — some of which can apply to industrial controllers depending on their actual function. There's no blanket “industrial equipment” category, so classify the specific product rather than assuming your sector is exempt or automatically important.
Long lifecycles change the evidence problem
Industrial equipment is often supported for a decade or more, which makes the CRA's support-period and ongoing vulnerability-monitoring obligations (Annex I, Part II) harder in practice than for consumer software: you need to track CVEs against components for years, and provide a secure-update path for hardware that may not have shipped with over-the-air update capability in the first place.
Retrofitting legacy protocols
Many industrial protocols predate modern authentication and encryption norms. Meeting the Annex I access-control and confidentiality requirements ((2)(d) and (2)(e)) sometimes means adding a security layer around a protocol that wasn't designed for it, rather than changing the protocol itself — document whatever compensating control you actually use.
What to focus on
- Classify the specific controller — a few functions (network management, OS, security-relevant chips) can be important; most industrial products are default.
- Plan vulnerability monitoring for a support period measured in years, not months.
- Document compensating controls where legacy protocols predate modern authentication.
- Produce the Annex VII dossier and Declaration of Conformity.
Frequently asked questions
- Are PLCs and industrial controllers in scope for the CRA?
- Industrial products with digital elements are generally in scope; some may be classified as important (Annex III), which changes the conformity route. Classify the specific product.
- Does the CRA replace IEC 62443 or existing OT security standards?
- No — the CRA sets essential requirements and a conformity route. Applying a relevant harmonised standard, once one is designated for your product, is one way to demonstrate you meet them, not a separate obligation layered on top.
General information about the EU Cyber Resilience Act — not legal advice. Normproof provides tooling and audit-ready evidence; the manufacturer self-declares conformity. For your specific product, run the free readiness check or consult a qualified advisor.