Manipulation or unintended changes to hardware, software, or network communications must not result in the impairment of a machine’s safety functions.
The Machinery Regulation therefore addresses cybersecurity particularly where a cyberattack could have an impact on functional safety.
The CRA addresses the cybersecurity of products with digital elements throughout their lifecycle.
The Machinery Regulation, on the other hand, addresses the safety of the machine as a whole.
Cybersecurity becomes relevant where manipulation could compromise the safety of the machine.
Both pieces of legislation may therefore apply at the same time.
No. A CRA-compliant communication product can contribute to the security and safety of a machine, but it does not replace the risk assessment and conformity assessment of the machine as a whole.
As part of the risk assessment, the machine manufacturer must evaluate whether manipulation of the communication system could affect safety functions or other safety-related functions of the machine.
Helmholz products support this by providing comprehensive security features and the corresponding documentation.
Not necessarily. What matters is the component’s function within the machine and the resulting risk.
For example, a basic network component can be protected by means of network segmentation, firewalls, or other organizational and technical measures.
In principle, yes. The Machinery Regulation does not prohibit such protocols.
However, the machine manufacturer must consider the risks that may arise from manipulation or unauthorized access and, where necessary, implement appropriate protective measures.
No. The Regulation does not prescribe any specific technology.
However, depending on the risk assessment, firewalls, network segmentation, or access controls may be appropriate protective measures.
The Security Guideline can provide the machine manufacturer with information on the secure integration and configuration of the product.
Responsibility for the machine’s risk assessment, however, remains with the machine manufacturer.
The new Regulation explicitly defines the term “substantial modification”.
A physical or digital modification that was not foreseen or planned by the original manufacturer may be considered substantial if it creates a new safety hazard or increases an existing risk and, as a result, requires new significant protective measures.
The person or company carrying out such a modification may thereby assume the obligations of a manufacturer under the Machinery Regulation.
Yes. In principle, digital modifications can also be relevant. The decisive factor is whether the modification affects the safety of the machine.
A standard security update is therefore not automatically considered a substantial modification.
The assessment depends on any additional changes made to the firmware and their impact on the machine.
Normally, not solely as a result of the update. However, the machine operator or manufacturer must assess whether the firmware modification has an impact on the safety of the machine.
In particular, routine maintenance or repair measures that do not affect compliance with the applicable safety requirements are not automatically considered substantial modifications.
If a company carries out a substantial modification, it may assume the obligations of the manufacturer for the affected machine and may be required to carry out a new conformity assessment.
Remote access should be designed and operated in such a way that unauthorized access or manipulation cannot adversely affect safety-related functions.
For routers and remote maintenance solutions in particular, authentication, access restrictions, and secure configuration are therefore important measures.
Helmholz products provide the necessary functions for secure remote maintenance.
There is no general requirement to install every update immediately. However, the operator or manufacturer must ensure that the machine continues to operate safely.
A known cybersecurity issue that could potentially affect machine safety must therefore be taken into account as part of the risk assessment.
Based on this assessment, it can be determined whether the safety of the machine is affected at all and how urgently measures, such as a firmware update, need to be implemented.
If the vulnerability results in a relevant risk to machine safety, technical or organizational measures may be required. These may include, for example, additional network segmentation, access restrictions, or replacement of the affected component.
Information on the secure use and configuration of Helmholz products is documented in the respective Security Guideline.
Security advisories for Helmholz products are available from CERT@VDE:https://certvde.com/de/advisories/vendor/helmholz/
The latest firmware updates can be downloaded free of charge at any time from the respective product page on the Helmholz website.
IEC 62443 can serve as a technical framework for industrial cybersecurity, particularly with regard to defense-in-depth, secure components, and secure system architectures.
Part 3 of IEC 62443 in particular can provide guidance for machine manufacturers. However, compliance with IEC 62443 does not automatically replace the conformity assessment required under the Machinery Regulation.