EU CRA ComplianceCRA compliance software
CRA Briefings See the CRA Workbench →

Complete guideOT / ICS manufacturersRegulation (EU) 2024/2847

EU CRA compliance for OT & ICS manufacturers

Everything an industrial manufacturer needs to place a compliant product with digital elements on the EU market — and where to start.

On this page

01
Scope

Does the CRA apply to your product?

The Cyber Resilience Act — Regulation (EU) 2024/2847 — covers products with digital elements: any hardware or software placed on the EU market that has a data connection, direct or indirect. For industrial manufacturers, that captures nearly the whole catalogue — PLCs, RTUs, protocol gateways, HMIs, industrial switches, edge devices, and the firmware and software that run on them.

If a product can be networked and you sell it into the EU, assume it is in scope until you have documented otherwise. There is no size exemption and no "internal use" loophole for products placed on the market.

Not sure which class your product lands in? Start with the CRA product classifier — it walks the Annex III / IV logic in a minute.

Source: Regulation (EU) 2024/2847 — Article 3 (definitions), Article 2 (scope).

02
Obligations

The six-step obligation chain

The CRA reads as a single chain of duties. Work through it in order and the technical file assembles itself:

  • Classify — default, important (Annex III, class I & II), or critical (Annex IV). See the classifier.
  • Assess risk — the Article 13 cybersecurity risk assessment, tied to the requirements it activates.
  • Meet Annex I — Part I product properties and Part II vulnerability handling.
  • Route conformity — self-assessment or a notified body, depending on class.
  • Declare — apply the CE mark and issue the EU Declaration of Conformity.
  • Document — assemble the Annex VII technical file.

Read the plain-English walk-through of each step in the CRA Briefings.

Source: Reg (EU) 2024/2847 — Articles 13, 32; Annexes I, III, IV, VII.

03
OT / ICS

What's different for OT and ICS

Industrial products carry constraints consumer IoT does not: decade-long service lives, legacy protocols, field devices that cannot be patched on a monthly cadence, and safety functions that gate every change.

The CRA accommodates this through the support period and update obligations — but it expects a documented, product-specific rationale, not a generic policy. And for teams already running an IEC 62443-4-1 secure-development lifecycle, much of the CRA evidence already exists in a different shape.

The OT advantage: if you've done 62443, you're not starting from zero — you're re-pointing evidence at CRA articles.

See exactly how in the IEC 62443 to CRA mapping guide — including the four gaps 62443 alone doesn't close.

Source: Reg (EU) 2024/2847 — Article 13(8) support period; ENISA–JRC standards mapping.

From reading the CRA to shipping the file.

The CRA Workbench walks your OT product through all six steps and produces a reviewer-ready Annex VII package — with the 62443 bridge built in.

See the CRA Workbench →

This guide is general information about Regulation (EU) 2024/2847, not legal advice. Figures and dates are verified against primary sources, but the CRA's harmonised-standards landscape is still settling — confirm against the current official text before relying on any point. The CRA Workbench is software that produces draft documentation for expert review; it indicates the evidence needed and does not, by itself, guarantee compliance.