What is the CRA?

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is the European Union’s first regulation establishing mandatory cybersecurity requirements for products with digital elements – hardware, software, IoT devices, and OT systems placed on the EU market. It applies to any manufacturer selling into the EU, regardless of where they are headquartered or where production takes place.

For DEIF, whose control products contain embedded software, connected interfaces, and network-accessible functions, the CRA applies directly.

The CRA’s core requirements include:

  • Secure by design and by default: Products must be planned and designed with cybersecurity embedded from the outset. Default configurations must be secure.

  • Vulnerability management across the lifecycle: Manufacturers must identify, track, and remediate vulnerabilities throughout the supported life of a product – providing security updates free of charge during the defined support period.

  • Software Bill of Materials (SBOM): Manufacturers must document all software components in a machine-readable format, enabling transparent vulnerability tracking across the supply chain.

  • Incident and vulnerability reporting: Actively exploited vulnerabilities and severe security incidents must be reported to ENISA and the relevant national CSIRT via the CRA Single Reporting Platform.

  • CE marking: Products must carry CE marking demonstrating CRA conformity before they can be sold on the EU market.

What does the CRA mean for DEIF customers?

For EPC contractors and system integrators: Products incorporated into systems delivered to EU customers may need to support the wider supply-chain and conformity-assessment work. Choosing products from a manufacturer preparing for the CRA can reduce uncertainty and improve access to relevant product evidence.

For operators and asset owners: Cybersecurity requirements should increasingly be considered when specifying and procuring connected control equipment for new projects.

For marine and land customers: DEIF’s E27-certified controllers already incorporate and document several product cybersecurity capabilities that are also relevant to CRA readiness. This provides a strong foundation, while CRA conformity will require its own product-specific assessment, technical documentation and conformity process.

What is DEIF doing to prepare for the CRA?

DEIF is building the product-assurance layer required by the CRA on the foundation already established through full IACS UR E27 certification and IEC 62443-aligned cybersecurity capabilities for all variants of the iE 250, iE 350, and iE 650 PLC. These activities are being integrated into our ISO/IEC 27001-certified information security management system:

  • Secure development lifecycle: Integrating CRA-specific security-by-design and security-by-default requirements into product development processes across all relevant product lines.

  • SBOM development: Building software bill of materials transparency for product components to support both internal vulnerability tracking and external reporting.

  • Product cybersecurity risk assessments: Conducting product-level risk assessments consistent with CRA and IEC 62443 requirements.

  • Reporting process readiness: Operationalizing end-to-end vulnerability handling, disclosure, and CRA-compliant reporting processes.

  • Conformity assessment preparation: Planning the conformity assessment activities required for CE marking under the CRA ahead of the December 2027 deadline.

  • HJN

    Contact us to discuss your options

    - 90 years of energy pioneering
    - Manufactured at the highest standards
    - Superior quality
    - Unmatched service and support
    - Made in Denmark