Design Engineering

Cyber Resilience Act readiness guide for machine builders released by ei3

July 8, 2026 
By Jared Dodds

General

New guide helps OEMs prepare for CRA vulnerability handling, asset visibility, SBOM and lifecycle cybersecurity requirements.

Talking Points

ei3, a provider of industrial connectivity and IoT solutions, has launched an educational guide to assist machine builders in complying with the European Union’s Cyber Resilience Act (CRA). The guide, titled Preparing for the Cyber Resilience Act: A Guide for Machine Builders, outlines the implications of the CRA for original equipment manufacturers (OEMs) and automation suppliers as cybersecurity becomes critical for connected machinery.

  • The CRA emphasizes security for products with digital components.
  • Key topics include vulnerability handling, software updates, and asset visibility.
  • The guide provides practical steps for meeting CRA deadlines in September 2026 and December 2027.

This guide is essential for machine builders to enhance customer trust and ensure responsible support for connected machines throughout their lifecycle.

July 8, 2026, New York — Industrial connectivity and IoT solutions provider ei3 has released a new educational guide to help industrial machine builders prepare for the European Union’s Cyber Resilience Act (CRA).

The guide, Preparing for the Cyber Resilience Act: A Guide for Machine Builders, explains how the CRA may impact OEMs and industrial automation suppliers as connected machines, gateways, embedded software, remote access systems and cloud-connected applications become part of the cybersecurity attack surface.

Advertisement

Because the CRA places new emphasis on the security of products with digital elements, there are important implications for product design, vulnerability handling, software updates, asset visibility, customer communication and lifecycle support.

“Connected machinery is no longer static equipment once it leaves the factory,” said Adam Griffen, cybersecurity and compliance subject matter expert at ei³ and author of the guide, in a media release. “As machines become more connected and software-driven, machine builders need repeatable processes for identifying vulnerabilities, assessing impact, communicating with customers, and supporting remediation throughout the product lifecycle.”

The new guide outlines practical considerations for OEMs preparing for CRA-related obligations, including:

  • How the CRA applies to connected industrial machinery and automation systems.
  • Why vulnerability handling must become a structured lifecycle process.
  • The role of international cybersecurity standards such as IEC 62443 and the NIST Cybersecurity Framework.
  • Why asset management and Software Bills of Materials (SBOMs) are becoming essential.
  • How secure remote service can help machine builders support remediation in the field.
  • Practical steps to prepare for the September 2026 and December 2027 CRA milestones.

“The CRA is an important signal that cybersecurity is becoming a fundamental product responsibility,” said Spencer Cramer, chief executive officer of ei³, in a press statement. “For machine builders, this is not only about compliance. It is about customer trust, service readiness, and the ability to support connected machines responsibly across their operational life.”

Advertisement

The full guide is available on the ei³ website.

Advertisement

Stories continue below