Skip to main content Skip to search Skip to main navigation

From January 2027, the new EU Machinery Regulation (EU) 2023/1230 will apply in the European Union.

What impact will this have on machine manufacturers, and how does it relate to Helmholz products and the Cyber Resilience Act (CRA)?

FAQ - EU Machinery Regulation
What does the new Machinery Regulation have to do with cybersecurity?
Manipulation or unintended changes to hardware, software, or network communications must not result in the impairment of a machine’s safety functions. The Machinery Regulation therefore addresses cybersecurity particularly where a cyberattack could have an impact on functional safety.

What is the difference between the CRA and the Machinery Regulation?
The CRA addresses the cybersecurity of products with digital elements throughout their lifecycle. The Machinery Regulation, on the other hand, addresses the safety of the machine as a whole. Cybersecurity becomes relevant where manipulation could compromise the safety of the machine. Both pieces of legislation may therefore apply at the same time.
If a Helmholz product is CRA-compliant, does this automatically mean that the machine complies with the Machinery Regulation?
No. A CRA-compliant communication product can contribute to the security and safety of a machine, but it does not replace the risk assessment and conformity assessment of the machine as a whole.
What responsibility does the machine manufacturer have when using a router, switch, or firewall?
As part of the risk assessment, the machine manufacturer must evaluate whether manipulation of the communication system could affect safety functions or other safety-related functions of the machine. Helmholz products support this by providing comprehensive security features and the corresponding documentation.
Does every network component in a machine need specific security features?
Not necessarily. What matters is the component’s function within the machine and the resulting risk. For example, a basic network component can be protected by means of network segmentation, firewalls, or other organizational and technical measures.

Are PROFINET, Modbus TCP, or other unencrypted industrial protocols still permitted under the Machinery Regulation?
In principle, yes. The Machinery Regulation does not prohibit such protocols. However, the machine manufacturer must consider the risks that may arise from manipulation or unauthorized access and, where necessary, implement appropriate protective measures.
Will machines be required to have a firewall?
No. The Regulation does not prescribe any specific technology. However, depending on the risk assessment, firewalls, network segmentation, or access controls may be appropriate protective measures.
What role do Helmholz Security Guidelines play in machinery conformity?
The Security Guideline can provide the machine manufacturer with information on the secure integration and configuration of the product. Responsibility for the machine’s risk assessment, however, remains with the machine manufacturer.
What constitutes a “substantial modification” of a machine?
The new Regulation explicitly defines the term “substantial modification”. A physical or digital modification that was not foreseen or planned by the original manufacturer may be considered substantial if it creates a new safety hazard or increases an existing risk and, as a result, requires new significant protective measures. The person or company carrying out such a modification may thereby assume the obligations of a manufacturer under the Machinery Regulation.
Can a firmware or software update constitute a substantial modification of a machine?
Yes. In principle, digital modifications can also be relevant. The decisive factor is whether the modification affects the safety of the machine. A standard security update is therefore not automatically considered a substantial modification. The assessment depends on any additional changes made to the firmware and their impact on the machine.
Does a firmware update of a Helmholz device mean that the entire machine has to undergo a new CE conformity assessment?
Normally, not solely as a result of the update. However, the machine operator or manufacturer must assess whether the firmware modification has an impact on the safety of the machine. In particular, routine maintenance or repair measures that do not affect compliance with the applicable safety requirements are not automatically considered substantial modifications.
Who is responsible if the operator subsequently modifies a machine?
If a company carries out a substantial modification, it may assume the obligations of the manufacturer for the affected machine and may be required to carry out a new conformity assessment.
What is the significance of remote access under the Machinery Regulation?
Remote access should be designed and operated in such a way that unauthorized access or manipulation cannot adversely affect safety-related functions. For routers and remote maintenance solutions in particular, authentication, access restrictions, and secure configuration are therefore important measures. Helmholz products provide the necessary functions for secure remote maintenance.
Does the machine manufacturer have to install security updates for components?
There is no general requirement to install every update immediately. However, the operator or manufacturer must ensure that the machine continues to operate safely. A known cybersecurity issue that could potentially affect machine safety must therefore be taken into account as part of the risk assessment. Based on this assessment, it can be determined whether the safety of the machine is affected at all and how urgently measures, such as a firmware update, need to be implemented.
What happens if a known vulnerability in a component cannot be fixed?
If the vulnerability results in a relevant risk to machine safety, technical or organizational measures may be required. These may include, for example, additional network segmentation, access restrictions, or replacement of the affected component.
What information does Helmholz provide to machine manufacturers for their risk assessments?

Information on the secure use and configuration of Helmholz products is documented in the respective Security Guideline. Security advisories for Helmholz products are available from CERT@VDE:https://certvde.com/de/advisories/vendor/helmholz/

The latest firmware updates can be downloaded free of charge at any time from the respective product page on the Helmholz website.

What role does IEC 62443 play in the Machinery Regulation?
IEC 62443 can serve as a technical framework for industrial cybersecurity, particularly with regard to defense-in-depth, secure components, and secure system architectures. Part 3 of IEC 62443 in particular can provide guidance for machine manufacturers. However, compliance with IEC 62443 does not automatically replace the conformity assessment required under the Machinery Regulation.

PSIRT - Product Security Incident Response Team

The PSIRT team is your direct contact for Helmholz components.
E-mail: psirt@helmholz.de
Phone: +49 (9135) 7380-0

Contact us now

You can find further information on our page on PSIRT.

CERT@VDE is a partner for the publication of security incidents in Helmholz products. Here you will find published advisories, and via RSS feeds you can integrate messages directly into Outlook to stay up-to-date.

How Helmholz protects industrial communication.

Guide for machine manufacturers and operators on
current EU legislation.

Download Whitepaper

Subscribe to our newsletter now!

Receive regular news on products, promotions and solutions from the world of Helmholz.