Image source: © KI-generiert
The Cyber Resilience Act is coming. What are the implications for the mechanical and plant engineering sector, and how can it be successfully implemented in practice? Key takeaways from the event.
With the Cyber Resilience Act, companies will face mandatory cybersecurity requirements for products containing digital elements. This also affects the machinery and plant engineering sector. In the future, manufacturers must demonstrate that their products meet the specified security requirements throughout their entire lifecycle. Cybersecurity thus becomes a fundamental product characteristic and a strategic priority for company management.
How can companies prepare for the new requirements? What organizational, technical, and legal measures are required? The event held on September 17, 2026, at Eicherhof Castle in Leichlingen addressed these questions. ProduktionNRW and the host, @-yet, brought together experts and industry representatives for this purpose.
Cybersecurity in a Geopolitical Context
To kick things off, Steffen Zimmermann, Head of the Competence Center for Industrial Security at the VDMA, placed the Cyber Resilience Act within its economic and geopolitical context. He demonstrated that product security is closely linked to global supply chains, technological dependencies, and economic interests.
The CRA establishes a binding framework for this and can contribute to more transparent supply chains and comparable security standards. At the same time, it became clear that regulation alone prevents neither security vulnerabilities nor geopolitical dependencies. Companies should therefore continue to develop their product security independently and systematically.
From Regulation to Practical Implementation
Alexander Findeisen, Practice Lead for ISMS at @-yet, focused on implementation. His key message: CRA compliance is not merely a technical task but equally affects product management, development, procurement, legal affairs, cybersecurity, and executive management.
A structured assessment was presented as a sensible starting point. Companies should first clarify which products are affected, define responsibilities, and identify existing gaps. Building on this, a prioritized roadmap can be developed. Of particular importance here are secure development processes, the handling of vulnerabilities, transparency regarding software components and supply chains, and traceable documentation.
Cybersecurity Is Becoming a Legal Product Attribute
Franziska Tilgner, an attorney at Luther Rechtsanwaltsgesellschaft, shed light on the legal requirements. The CRA establishes cybersecurity as a mandatory characteristic of digital products. Manufacturers bear responsibility from development through placing the product on the market to updates and the handling of vulnerabilities.
To this end, companies must, among other things, determine which products fall under the regulation and what role they play within the supply chain. Security requirements must be taken into account as early as the development phase and implemented in a verifiable manner throughout the entire product lifecycle. Since responsibility cannot be fully transferred to suppliers, clear agreements and transparent supply chains are becoming even more important.
Act Early and Leverage Security as a Quality Feature
The event made it clear that the Cyber Resilience Act intertwines technical, organizational, and legal issues. Companies should therefore identify affected products early on, clarify responsibilities, and assess their current level of readiness.
Acting in a timely manner not only lays the foundation for compliance with legal requirements. Cybersecurity can also strengthen customer trust, increase product resilience, and become an important quality and competitive advantage.
Organizer
The event is presented by ProduktionNRW. ProduktionNRW is the cluster for mechanical engineering and production technology in North Rhine-Westphalia and is managed by VDMA NRW. ProduktionNRW serves as a platform to connect, inform, and promote companies, institutions, and networks with one another and along the value chain. Significant portions of the services provided by ProduktionNRW are funded by the Ministry of Economic Affairs, Industry, Climate Protection, and Energy of the State of North Rhine-Westphalia.

