THE #1 AV NEWS PUBLICATION. PERIOD.

How the Cyber Resilience Act Reshapes Industrial Automation Compliance

mitsubishi eu cyber resilience act

By Stefan Knauf
Division Manager, Mitsubishi Electric Europe B.V., Industrial Automation

The European Union’s Cyber Resilience Act (CRA) is set to redefine cybersecurity requirements for products with digital components, making cyber resilience a formal requirement for CE marking.

Regulation (EU) 2024/2847, published Nov. 20, 2024, requires manufacturers, importers and distributors to implement cybersecurity measures throughout the lifecycle of products containing digital elements. Reporting obligations for actively exploited vulnerabilities take effect Sept. 11, 2026, and full compliance will be required beginning Dec. 11, 2027.

For industrial automation, the regulation formalizes “secure by design” and “secure by default” principles. Products must be developed with built-in security features, delivered with protective configurations enabled and supported with vulnerability management and free security updates throughout their defined lifecycle.

For operators of networked production facilities, the CRA introduces structured update and reporting requirements intended to increase predictability and reduce supply chain risk. Controllers, human-machine interfaces and network components must now meet defined expectations for auditability and cyber resilience.

Mitsubishi Electric has aligned its development, operational and support processes with CRA requirements through structured vulnerability management and documented security controls. A dedicated Product Security Incident Response Team coordinates disclosure and remediation activities, while the company’s status as a CVE Numbering Authority enables direct identification and communication of vulnerabilities.

Security measures include signed firmware updates, role-based access controls and monitoring frameworks aligned with IEC 62443-4-2. These controls are designed to support auditability and demonstrate conformity with emerging CE cybersecurity requirements.

Technical Measures From HMI to PLC

Human-machine interfaces such as the GOT3000 series incorporate signed firmware updates, restrictive default configurations and role-based user management. MELSEC platforms use separate engineering and operational networks, encrypted remote access and defined update processes.

Supporting documentation typically includes a software bill of materials, patch management records, log export functionality and clearly defined support periods. Similar principles apply across drives, robotics systems and engineering software, including secure communication channels and disclosure of known Common Vulnerabilities and Exposures.

Such documentation is expected to play an increasingly important role in CE marking processes as cybersecurity becomes a measurable compliance factor.

Rising Threat Landscape and Regulatory Pressure

The CRA arrives amid increased cyber activity targeting industrial organizations. The Dragos 2024 report indicates ransomware attacks on industrial entities increased by more than 87 percent compared with 2023, alongside the identification of new industrial control system-specific malware families.

At the same time, Germany’s NIS-2 Implementation Act expands cybersecurity and reporting obligations for an estimated 29,000 companies beginning in late 2025. The law defines cybersecurity as a management responsibility, increasing accountability across supply chains.

Together, these regulatory measures elevate cybersecurity from an operational concern to a strategic compliance requirement for manufacturers and operators.

Toward Greater Transparency

The CRA standardizes expectations around vulnerability disclosure, lifecycle support and secure development practices. For automation providers, this requires aligning technical safeguards, documentation and response processes with regulatory timelines.

As enforcement deadlines approach, cybersecurity is becoming a core component of CE conformity, shaping procurement, development and lifecycle management decisions across Europe’s industrial sector.

Top