Does the Cyber Resilience Act Apply to Your PLC, HMI or IIoT Gateway?
The EU Cyber Resilience Act regulates products with digital elements. That phrase is deliberately wide, and it is wider than most industrial vendors assume. It is not a list of consumer gadgets. A programmable logic controller, a human machine interface, a protocol gateway, a remote terminal unit and the engineering software that configures them are all products with digital elements, and all of them can fall inside scope when they reach the European market.
For US and Canadian manufacturers the question is rarely whether the regulation exists. It is whether it reaches a specific product, through a specific route to market, and what conformity route follows. That answer determines whether you self-declare or pay for a third-party assessment, and the cost difference between those two outcomes is substantial. Getting it wrong in either direction is expensive, which is why scope work belongs early in your OT cybersecurity program.
The first test is route to market, not geography
The regulation attaches to placing a product on the EU market. You can trigger it without ever shipping to Europe yourself. Common routes that catch North American vendors by surprise:
- Your controller is embedded in an OEM skid or packaged unit that is sold into the EU.
- A system integrator in Europe buys your hardware and resells it as part of a plant delivery.
- Your configuration software is downloadable without geographic restriction.
- A distributor stocks your product in the EU without a territory restriction in the contract.
If any of those apply, the next question is which role you hold. The regulation distributes duties across the supply chain and they are not equivalent.
Who carries which obligation
|
Role |
Core duties |
|
Manufacturer |
The heavy end. Secure design and development against the essential requirements, technical documentation, conformity assessment and CE marking, vulnerability handling across the support period, and the Article 14 reporting duty. |
|
Importer |
Verify that the manufacturer has done the work before placing the product on the EU market. An importer who ships a non-conforming product is not shielded by the manufacturer's failure. |
|
Distributor |
Due care. Check that CE marking and the required documentation are present, and act if they are not. |
|
Authorised representative |
Non-EU manufacturers are generally expected to appoint one in the EU to hold documentation and act as the contact point for authorities. |
One trap worth naming: if you substantially modify a product, or place it on the market under your own name, you can become the manufacturer in regulatory terms even if someone else built it. Integrators who rebadge hardware should read that sentence carefully.
Product classes and what they cost you
The regulation sorts products into four tiers, and the tier decides the conformity route.
|
Tier |
Conformity route |
Published examples |
|
Default |
Self-assessment |
The majority of products with digital elements |
|
Important, Class I |
Harmonized standards or third-party assessment |
Password managers, network management tools, VPNs |
|
Important, Class II |
Third-party assessment required |
Operating systems, firewalls, microprocessors |
|
Critical |
Mandatory EU certification |
Smart meters, smart cards, secure elements |
|
Why the class lists do not name your PLC Industrial control equipment is not called out by name in the important or critical class lists, which leads vendors to assume they are out of scope. They are not. Most industrial products land in the default tier, which still carries the full essential requirements and vulnerability handling duties. It simply allows self-assessment rather than a notified body. The exception matters: a product whose core function is network security or system management can escalate into Class I or II, and smart meters sit in the critical tier outright. |
How to classify a product without guessing
Classification follows the product's core functionality, not every feature it happens to include. A controller with an embedded firewall is still a controller. Where more than one category genuinely applies, the stricter one wins. Working through it in order keeps the answer defensible:
- 1. Define the product boundary. Firmware, hardware and the software that configures it may or may not be one product. Document the choice.
- 2. State the core function in one sentence. If that sentence needs an "and", you probably have two products.
- 3. Test against the important and critical lists. Look for a match on core function, not on a feature.
- 4. Apply the stricter tier where several fit.
- 5. Record the reasoning. Your classification is part of your technical documentation, and an authority can ask you to justify it.
Exclusions, and the ones that do not help
The regulation carves out products already covered by equivalent sectoral regimes, which is why medical devices, civil aviation and certain automotive products are treated separately. Spare parts and products developed exclusively for national security or defense are handled differently too. What is not excluded is the large middle ground of general industrial automation, and that is where most of our clients sit. Free and open source software supplied outside a commercial activity is also treated differently, which matters if your firmware carries open components. Our SBOM guidance for OT procurement covers how to establish what is actually in your build.
Why Choose Arista Cyber
Scope work on industrial products needs someone who understands both the regulation and the equipment. We assess control systems in the field, we work to IEC 62443 on product and system security, and we do functional safety assessment on the same assets, which means a scope opinion from us accounts for how a product behaves on a plant rather than how it reads on a datasheet. Our supply chain cyber risk assessment playbook sets out the method we use on vendor and product reviews.
Next Steps
If you build or rebadge industrial equipment and any of it may reach Europe, a scope and classification review is the cheapest work you will do on the CRA. It tells you which products need a conformity route, which need a notified body, and where you hold manufacturer duties you did not realize you had. Full application arrives 11 December 2027, and third-party assessment capacity will tighten well before that date.
Common Questions
Is a PLC an important or critical product under the CRA?
Usually neither. Most industrial controllers fall in the default tier, which permits self-assessment but still carries the full essential requirements. Products whose core function is network security or system management, and smart meters, are the ones that escalate.
Does the CRA apply if we only sell to a US OEM who then exports?
It can. The duty attaches when the product is placed on the EU market. If your component travels inside their machine, you should establish contractually who holds which role and make sure documentation exists to support it.
What about our configuration software?
Software is a product with digital elements in its own right. If it is downloadable without territory restriction or shipped with hardware into the EU, treat it as in scope and classify it separately from the hardware.
Do we need an authorised representative in the EU?
Non-EU manufacturers are generally expected to appoint one to hold documentation and act as the contact point for authorities. Confirm the specific requirement for your product and route to market rather than assuming your importer covers it.
Can we rely on CE marking we already hold?
No. CE marking under the Machinery Regulation or the EMC Directive does not discharge CRA obligations. The CRA adds its own essential cybersecurity requirements and its own conformity assessment.
|
Not sure which of your products are in scope? Arista Cyber delivers CRA scope and classification reviews for industrial equipment manufacturers and integrators across the US and Canada, covering product boundaries, supply chain roles, tier classification and the documentation an authority can ask to see. |