The evolution of OT compliance: the impact of NIS2, the Machinery Regulation, and the CRA on CE Marking
European Cybersecurity regulations have evolved significantly due to the rise in cyberattacks, including within the OT sector. In Europe, there are three regulations of major interest:
- The NIS2 Directive, focusing on critical infrastructure and security management processes;
- The Machinery Regulation 2023/1230, primarily focused on safety, but also covering protection against cyberattacks and the reporting of security incidents;
- The Cyber Resilience Act (CRA), which introduces cybersecurity requirements for products with digital elements.
Of these three pieces of legislation, the Machinery Regulation and the Cyber Resilience Act are part of the new European legislative framework linked to CE marking. This implies that for any product placed on the European market that falls within the scope of both the Machinery Regulation and the CRA, both regulations must be cited in the Declaration of Conformity.
Which products are included? The CRA applies to products with digital elements—meaning products that, by their intended purpose or reasonably foreseeable use, include a direct or indirect, logical or physical data connection. By way of example, PLCs and HMIs are considered digital products, whereas components such as cables or plugs are not classified as products with digital elements.
To provide participants with a clearer understanding of the CRA's scope, the speaker used a practical simplification, highlighting that any product containing upgradeable firmware can generally be considered a product with digital elements. This same rationale can therefore be extended to industrial machinery, systems, and complex solutions.
Focusing our attention on the machinery sector, the webinar highlighted several common technical measures for designing a secure machine, including: perimeter protection via firewalls, logging, authentication, encryption where necessary, hardening, security scanning, and the monitoring of network or programme changes.
Perimeter protection using firewalls was presented as a primary recommendation. A firewall limits the attack surface, reduces the likelihood of unauthorised access, contributes to resilience against Denial of Service (DoS) attacks, and minimises the risk of an internal machine issue propagating to other networks.
We would once again like to draw our customers' attention to the Scalance S Industrial Security Appliance, specifically designed for this purpose (https://www.siemens.com/it-it/products/scalance/s-industrial-security-appliance/), which mitigates cyber threats that could otherwise lead to production downtime, data loss, and safety risks.
Regarding system access, the device presented during the webinar to counter unauthorised access was the Siemens SIMATIC RF1000. This device becomes essential when access traceability to a machine is required, and more broadly across its entire supply chain, as detailed on the Siemens webpage: https://www.siemens.com/it-it/products/simatic-ident/simatic-rf1000/.
During the webinar, a major focus was also placed on monitoring as a key preventative element. As an example, the speaker demonstrated the capability within the TIA Portal (https://www.siemens.com/it-it/products/tia-portal/) to enable Ethernet port status monitoring on devices such as the SIMATIC ET200.
However, the core takeaway from the webinar lies in the overarching message: cybersecurity must not be treated as an isolated requirement, but rather as a product lifecycle discipline spanning all stages including design, configuration, documentation, monitoring, vulnerability management, updates, mitigations, and after-sales support.
For further information or clarification, please contact: info@faentia.com