Cyber compliance for CE marking - Advanced
Machine cybersecurity beyond the requirements of Regulation (EU) 2023/1230
Anticipating future cyber requirements costs less than adapting at the last minute
In industrial machinery, cybersecurity is not limited to the minimum requirements needed for CE marking. Digital components, extended OT systems and complex architectures can introduce technical exposures that affect the manageability, reliability and evolution of the machine over time. The Cyber Compliance for CE Marking — Advanced service extends the analysis beyond what is strictly required by Regulation (EU) 2023/1230, supporting manufacturers and integrators in adopting a more comprehensive and engineering-based approach to machine cybersecurity.
When is it needed
The service is indicated when:
- The aim is to strengthen cybersecurity beyond the minimum requirements for CE marking;
- The machine integrates an extended OT ecosystem, with components not directly involved in safety functions;
- It is necessary to manage cybersecurity throughout the entire machine lifecycle;
- The aim is to anticipate the impact of future regulatory requirements in the cyber domain;
How the assessment is carried out
The service includes all activities provided for under the Cyber Compliance for CE Marking and extends them to the entire OT context of the machine. The activity covers:
- Extended analysis of the OT context, with definition of the overall perimeter;
- Mapping of OT assets, including components not directly relevant to functional safety;
- Analysis of the OT architecture, encompassing networks, operational interfaces and connections with external systems;
- Identification of technical weaknesses and plausible exposures, without penetration testing or exploitation activities;
- Engineering definition of cybersecurity measures applicable to the entire OT ecosystem, covering access and identity management, logical separation of functions, software and critical parameter integrity, communications management, and operational and maintenance aspects;
- Framing with respect to the Cyber Resilience Act (CRA), aimed at supporting future technical planning.
NOTE: The activity does not include regulatory compliance checks, structured risk analysis, vulnerability assessment, penetration testing or Security Level determination in accordance with IEC 62443.
What we deliver
At the end of the assessment, we provide:
- CE compliance report, prepared in accordance with the Cyber Compliance for CE Marking service;
- Machine cybersecurity technical specification, describing the OT architecture analysed, the cybersecurity measures defined, the technical requirements and operational guidelines for long-term management.