CRA, CE, and asset discovery for machinery
The main CRA obligations apply from 11 December 2027 to new products with digital elements. Where their product falls within scope, machine builders need to assess cybersecurity risks, maintain technical evidence, handle vulnerabilities throughout the support period, and declare conformity before placing the product on the market. The CRA does not literally mandate an automated inventory of every network device. A current OT asset inventory does, however, provide operational data for checking product scope, firmware states, and change.
Read the guide
