
For decades, original equipment manufacturers (OEMs) could largely view the responsibility of cybersecurity as an afterthought, with less of a formal requirement for managing security risks. The security strength of the components inside that machine, and how those components aged over years of field service, was rarely tracked consistently.
That era is ending.
The European Union's Cyber Resilience Act (CRA), which came about in December 2024, is rewriting the rules for any OEM that wants to keep selling into the EU market. With initial reporting requirements taking effect in September 2026 and full compliance mandated by December 2027, these ripple effects will be felt by manufacturers worldwide.
The CRA requires manufacturers to demonstrate the security posture of a product at the moment it ships, and then to track, monitor and report on that product's vulnerabilities for as long as it remains in service. For a machine builder, that means maintaining a detailed, verifiable record of every component, every firmware version and every hardware element built into a machine at the point of origin.
Let’s call it what it functionally is: a cybersecurity birth certificate.
Alongside the CRA, the EU's revised Machinery Regulation is reinforcing the same shift by folding cybersecurity into the essential health and safety requirements machines must meet before they can be placed on the market. Where machine safety was once assessed largely in mechanical and electrical terms, regulators now treat a machine's resistance to cyber incidents as part of its safety case.
Together, the two regulations mean OEMs will need integrated processes that bring safety, cybersecurity and regulatory documentation under one roof, rather than treating them as separate workstreams.
The Scale of this Problem is Easy to Underestimate
On paper, the birth certificate concept sounds like an extension of the bill-of-materials tracking many OEMs already perform. In practice, the scale changes the nature of the problem.
A single machine can contain anywhere from a handful to several hundred individual components, each with its own firmware and hardware revision history. Multiply that by an annual production volume in the hundreds or thousands of machines, spread across customer sites around the world, and sustained over a five- or ten-year support commitment, and the recordkeeping burden grows well beyond what spreadsheets or manual audits can reasonably manage.
That burden does not disappear once a machine leaves the factory floor. Under the CRA, OEMs are expected to monitor for newly disclosed vulnerabilities across every component they have shipped and notify affected end users when a security-relevant issue emerges. This becomes extremely challenging for manufacturers with large, geographically dispersed installed bases.
While some organizations may believe existing parts-tracking processes can simply be extended to cover this requirement, in my experience, that underestimates both the volume of exploit and advisory data involved and the speed at which it needs to be triaged and acted upon.
Building a Framework That Can Actually Scale
OEMs that are getting ahead of this requirement are generally doing three things well.
- First, they are standardizing on components with recognized security certifications, such as IEC/ISA 62443, so that a portion of the compliance case is already established before a machine is even assembled.
- Second, they are building a repeatable, automated process for capturing the exact configuration of each machine at the moment it ships, rather than relying on documentation compiled after the fact.
- Third, and most importantly, they are connecting that shipment-time snapshot to an ongoing vulnerability feed. This means new advisories are automatically matched against the components in every machine they have sold, rather than requiring someone to manually cross-reference spreadsheets.
This is where automation earns its keep. A lifecycle vulnerability management approach, built on a current and accurate inventory of what shipped and where, can flag exposure automatically when a new vulnerability is disclosed, rather than waiting for a periodic manual review. It also gives OEMs an answer, in hours rather than weeks, when a customer or regulator asks whether a specific machine is affected by a specific advisory.
That responsiveness is quickly becoming a competitive differentiator as much as a compliance requirement, particularly as more sophisticated end users begin asking OEMs to prove their security posture as part of procurement.
Bridging the Gap for the Installed Base
Of course, none of the above addresses the machines already in the field, many of which were built before this level of documentation was even contemplated. Retrofitting a birth certificate onto an existing installed base is a real and often underestimated challenge, but it is not insurmountable.
The most practical path I have seen is a risk-based one: start with the machines and components that carry the greatest exposure, whether due to age, criticality or known vulnerability history, and build the documented record outward from there rather than attempting to reconstruct everything at once.
Pairing that prioritization with tools that can inventory a machine's actual configuration, rather than relying solely on historical purchase records, closes much of the remaining gap.
The compliance timeline gives OEMs a genuine, if narrowing, window to act. Exploited vulnerability and incident reporting obligations under the CRA begin in September 2026.
The Machinery Regulation takes effect in January 2027. The CRA's broader obligations become fully enforceable in December 2027. Machine builders that treat this as a two-year sprint, rather than a distant deadline, will be the ones able to bring compliant machines to market without disruption.
Those that wait will find themselves racing to build documentation and monitoring capability for an installed base that has already shipped.
The shift underway is significant, but it is also an opportunity for OEMs to differentiate themselves on trust. Manufacturers that can show customers, clearly and quickly, exactly what is inside their machines and how those machines are being monitored for emerging risk will be well positioned.
This transparency will help manufacturers not only meet regulatory requirements but also compete for business from end users asking harder questions about the security of the equipment on their plant floors.




















