


For many packaging machinery companies, cybersecurity has traditionally been something associated with the customer's IT department. That is changing quickly. Machinery sold into the European market frequently contains digital elements, so cybersecurity has become part of the product-compliance conversation.
A modern packaging machine includes software and controllers, digital components, interfaces, dependencies and connections. The manufacturer therefore needs to understand the cybersecurity risks associated with the machine and its digital components rather than treating cybersecurity as someone else's responsibility.
A new EU regulation has significant implications for PMMI members selling machinery in the EU market. PMMI members selling machinery into the EU market must CE mark their machines. CE marking indicates compliance with the Machinery Regulation and now the CRA (and potentially other requirements). Members cannot sell to European markets without meeting these legal requirements. The General Provisions of the CRA include:

One important change is that cybersecurity is becoming part of the product itself. Due to this change, the manufacturer needs to understand the cybersecurity risks associated with the machinery and its digital elements.
One significant challenge remains that there is insufficient understanding and access to information to make informed decisions on the CRA and its application(s). In certain respects, the regulation is coming into effect while the EU continues to build the necessary supporting content. This is hardly an ideal situation but one everyone faces.
Why?
The CRA Preamble explains that cyberattacks are a matter of public interest, including the areas of “economy, democracy and consumer safety and health.” The CRA was written to address these concerns. Some of the requirements make sense from the perspective of consumer products; for example, we all have mobile phones and have certain expectations that the manufacturers will address cybersecurity risks. Because there can be widespread vulnerabilities as well as insufficient and inconsistent provision of security updates, people can be put at risk for cybersecurity attacks. However, the CRA also applies to machinery and this has created some significant challenges for industrial machinery manufacturers.
What should a PMMI member consider?
The starting point is to identify the digital elements of the machine. For a packaging machinery builder, that means looking at the machine as a system. Members should consider the machine together with its software and controllers, digital components, and the interfaces, dependencies and connections that allow those elements to communicate and operate. All the digital components and connected elements need to be considered as part of the product's cybersecurity footprint. A immediate first step is to create a Software Bill of Materials (SBOM) that lists all the digital elements of a machine.
The manufacturer's responsibility starts with cybersecurity risk
Manufacturers are expected to ensure that products with digital elements are designed, developed and produced in accordance with the essential cybersecurity requirements. They are also expected to assess the cybersecurity risks associated with the product, with the goal of minimizing those risks, preventing incidents and minimizing their impact both when built and over the life of the machinery.
For a machine builder, this means cybersecurity needs to be considered during product development. It should be part of the way the machine and its digital elements are designed rather than something added only after the machine is finished.
This also means understanding how the different digital components interact. A vulnerability in one component can impact the security of the overall machine.
Security updates become part of the product's life
A machine manufacturer’s cybersecurity responsibilities do not end when the machine is shipped. Security updates need to remain available after the machine is shipped for no less than 10 years or for the remainder of the machine life, whichever is longer. For many packaging machines, this is a very challenging requirement given the equipment can remain in service for many years.
Manufacturers therefore need to think about and plan for cybersecurity support alongside the other long-term responsibilities that come with industrial equipment: service, spare parts, software changes and product support.
Suppliers must become part of the conversation
Packaging machinery builders do not develop every controller, sensor, software package or digital component used in the equipment. OEMs should actively engage with controls and sensor suppliers to understand and track the components used in their equipment. The goal is to know what is in the machine and to be able to respond when a vulnerability affects one of those components.
Supplier relationships therefore need to support more than the original purchase. Manufacturers need a way to stay informed about the digital components they use and the vulnerabilities that may affect them.
How to address this requirement is still unclear and evolving. Many suppliers of digital components are posting information on their website, with the expectation that the purchaser of the component will periodically check for updated information about the components. This is not a particularly user-friendly solution, but it is a start at making the information available. Every supplier in the machine supply chain faces challenges of knowing who or where their machine or component is being used, and how to notify them of a future cybersecurity concern.
When do the requirements take effect?
The reporting requirements begin September 11, 2026.
The full requirements of the CRA apply December 11, 2027.
The reporting requirements include short timelines on notifications to authorities. The CRA imposes obligations on manufacturers to report incidents and vulnerabilities in products with digital elements. That means manufacturers must detect vulnerabilities, evaluate the potential impacts of the vulnerabilities, and report to authorities and customers in a timely manner. “Timely” means really quite quickly. There are reporting requirements for
Companies need to understand their products, suppliers, digital components, support commitments and vulnerability processes before the full requirements apply in December 2027.
What happens if a company does not comply?
The CRA includes penalties intended to be “effective, proportionate and dissuasive.” The consequences are significant enough that manufacturers should not treat the CRA as an optional cybersecurity initiative, or something to be addressed later. The penalties are still somewhat unclear, but the CRA explicitly intends to prompt manufacturers to address cybersecurity risks. The focus should be on building a reasonable process now rather than waiting for a problem to force action.
What should a PMMI member do now?
Companies do not need to have all the answers immediately, but doing something to prepare for the CRA is necessary. Doing something is better than nothing, and ignorance of or ignoring the requirements is not an excuse. A reasonable place to begin is to understand the digital side of the products being sold into Europe. Steps members can do now include:
The bottom line for PMMI members
The CRA is a significant regulation, and it will require effort from packaging machinery manufacturers selling into Europe. The most important first step is to understand the digital elements in the products you make and the responsibilities that come with them.
Manufacturers do not need to be perfect, but they do need to be responding. The companies that begin understanding the cybersecurity aspects of their machines, engaging their controls and sensor suppliers, tracking digital components and establishing a vulnerability-response process will be better prepared for the requirements ahead.
Relevant documentation
Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (the Cyber Resilience Act)
Download Communication on Cyber Resilience Act
Download Commission guidance on the application of the Cyber Resilience Act (CRA)