EU Cyber Resilience Act for Steel: Compliance Requirements

By Michael Finn on February 23, 2026

eu-cra-compliance-steel

The European Union's Cyber Resilience Act entered into force in 2024 and begins phased enforcement in 2027, creating the most comprehensive cybersecurity regulatory framework ever applied to products with digital elements—including the industrial control systems, networked sensors, SCADA platforms, and connected equipment that steel manufacturers both use and, in many cases, supply to other industries. For steel producers operating in or selling into the EU market, the CRA isn't a distant regulatory possibility—it's an active compliance obligation with a defined timeline, specific technical requirements, and penalties that reach €15 million or 2.5% of global annual turnover, whichever is higher. The Act fundamentally changes how steel companies must think about cybersecurity. It's not just about protecting your own networks anymore. If your company manufactures or supplies products with digital elements—programmable logic controllers, smart sensors, connected drives, industrial software, or any equipment with embedded firmware that connects to a network—those products must meet CRA cybersecurity requirements before they can carry the CE marking and be sold in the EU. And if you're a steel producer using these products, the CRA's vulnerability handling and incident reporting requirements create new obligations for how you manage, monitor, and report on the cybersecurity of your operational technology environment. The compliance window is measured in months, not years, and the technical, procedural, and documentation requirements are substantial. Steel companies that begin compliance preparation now will be positioned to meet the 2027 enforcement deadlines. Those that wait will face rushed implementations, potential market access disruptions, and regulatory exposure that dwarfs any previous industrial cybersecurity requirement.  

EU Cyber Resilience Act — Enforcement Timeline

2024
Act Enters Into Force
Published in EU Official Journal. Compliance preparation period begins for all manufacturers and importers of products with digital elements.


September 2026
Reporting Obligations Active
Manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA within 24 hours of discovery. Coordinated vulnerability disclosure processes must be operational.


December 2027
Full Enforcement Begins
All products with digital elements placed on the EU market must meet CRA essential cybersecurity requirements. CE marking requires demonstrated conformity. Market surveillance authorities begin enforcement.


Ongoing
Continuous Compliance Obligation
Manufacturers must provide security updates for the expected product lifetime (minimum 5 years). Vulnerability monitoring and incident reporting are permanent obligations.
Maximum Penalty
€15 million or 2.5% of global annual turnover

Who in the Steel Industry Is Affected

The CRA's scope is broader than many steel companies initially expect. It applies not only to dedicated technology manufacturers but to any entity that places products with digital elements on the EU market—including steel companies that manufacture connected equipment, integrate digital components into their products, or supply digitally-enabled industrial systems. Facilities that sign up to centralize their OT asset management on a compliant digital platform build the documentation and monitoring infrastructure the CRA demands.

Directly Regulated
Steel Equipment Manufacturers
Companies that manufacture and sell industrial equipment with embedded digital elements — PLCs, smart sensors, connected drives, furnace control systems, quality inspection systems, or any product with firmware that connects to a network. These products must carry CE marking demonstrating CRA conformity.
Examples: Proprietary rolling mill control systems, in-house designed sensor packages, custom automation solutions sold to other steel producers or downstream customers
Directly Regulated
Industrial Software Developers
Companies that develop and distribute software used in steel manufacturing — process control software, Level 2 automation packages, quality management systems, MES platforms, or maintenance management software. Commercial software is a "product with digital elements" under the CRA.
Examples: Proprietary Level 2 models sold to other producers, process optimization software, custom SCADA applications
Indirectly Affected
Steel Producers as End Users
Steel mills that use products with digital elements are not directly regulated as manufacturers under the CRA. However, they are indirectly affected through new requirements on their suppliers and through the CRA's interaction with existing directives (NIS2, Machinery Regulation) that create cybersecurity obligations for critical infrastructure operators.
Examples: Procurement specifications must require CRA-compliant products; vulnerability notifications from suppliers must be managed; OT asset inventories must track product security status
Directly Regulated
Importers & Distributors
Any entity that imports products with digital elements into the EU market or distributes them within the EU bears responsibility for verifying CRA conformity. Steel trading companies, equipment resellers, and system integrators that place third-party products on the EU market have specific due diligence obligations.
Examples: Steel companies importing automation equipment from non-EU suppliers, system integrators assembling control solutions from multiple component manufacturers

The Essential Cybersecurity Requirements

The CRA defines specific cybersecurity requirements that products with digital elements must meet to be placed on the EU market. These requirements apply throughout the product lifecycle—from design through end-of-support—and must be demonstrated through conformity assessment before CE marking.

Product Security Requirements
01
Security by Design & Default
Products must be designed with cybersecurity integrated from the start—not bolted on afterward. Default configurations must be secure: no default passwords, minimal attack surface, encryption enabled by default, and unnecessary services disabled out of the box.
Steel impact: Every PLC, sensor, drive, and control system shipped with default credentials or open telnet ports fails this requirement
02
Access Control & Authentication
Products must implement appropriate authentication and access control mechanisms. User identity must be verified before access is granted. Administrative functions must require elevated authentication. Access control policies must be configurable by the end user.
Steel impact: Industrial controllers must support role-based access, individual user accounts, and configurable authentication — shared/default credentials are non-compliant
03
Data Protection & Integrity
Products must protect the confidentiality and integrity of data they process, store, and transmit. This includes encryption of data in transit, integrity verification of firmware and configuration data, and protection of stored credentials and sensitive parameters.
Steel impact: Process data, control commands, and configuration transfers between SCADA/HMI and field devices must use encrypted, authenticated protocols
04
Resilience & Availability
Products must be designed to maintain essential functions under adverse conditions including cyber attacks. They must be resilient against denial-of-service attacks, network disruptions, and malformed inputs without failing in an unsafe manner.
Steel impact: Safety-critical controllers must demonstrate they maintain safe operation even when subjected to network-based attacks or corrupted inputs
05
Logging & Monitoring
Products must provide security-relevant logging capabilities—recording access attempts, configuration changes, authentication events, and anomalous behavior. Logs must be accessible to the end user and protected against tampering.
Steel impact: Industrial devices must generate audit trails for all security-relevant events — a capability most legacy OT equipment entirely lacks
06
Secure Update Mechanism
Products must support secure, authenticated software and firmware updates. Updates must be delivered through verified channels with integrity verification. Users must be notified of available security updates. Update capability must persist for the expected product lifetime.
Steel impact: Equipment vendors must commit to security patching for 5+ years and provide a mechanism for authenticated, verifiable firmware delivery
Vulnerability Handling Requirements
07
Coordinated Vulnerability Disclosure
Manufacturers must establish and publish a coordinated vulnerability disclosure policy. They must provide a mechanism for external parties to report vulnerabilities. Reported vulnerabilities must be addressed without undue delay with remediation provided to users.
Steel impact: Equipment manufacturers must create public vulnerability reporting channels and commit to timely remediation processes
08
Incident & Vulnerability Reporting to ENISA
Actively exploited vulnerabilities must be reported to ENISA within 24 hours. Severe incidents affecting product security must be reported within 72 hours. A detailed follow-up report must be submitted within 14 days including remediation measures.
Steel impact: Steel companies must build internal processes to detect, assess, and report cybersecurity incidents within extremely tight timelines
CRA Compliance Starts with Knowing What You Have
OxMaint provides the digital asset registry, maintenance history, and configuration management that CRA compliance requires — a complete inventory of every connected device in your operation with documented security status, update history, and vendor accountability.

Product Classification: Default vs. Critical Categories

The CRA establishes different conformity assessment paths based on product criticality. Products used in industrial control systems—a core category for steel manufacturing—face the most rigorous assessment requirements. Understanding which classification applies to your products determines the compliance pathway and associated effort.

CRA Product Classification for Steel-Relevant Products
Scroll horizontally on mobile
Dimension Default Category Important (Class I) Important (Class II) / Critical
Steel examples Environmental sensors, basic HMI displays, non-networked tools Network management software, industrial IoT gateways, SCADA systems Industrial automation controllers, safety systems, PLC platforms, ICS components
Conformity assessment Self-assessment against essential requirements Harmonized standards or third-party assessment Mandatory third-party conformity assessment by notified body
Documentation Technical documentation and EU declaration of conformity Comprehensive technical file with security testing evidence Full technical file reviewed by notified body with formal certification
Security testing Internal testing against CRA requirements Testing against harmonized standards (EN IEC 62443 series) Independent penetration testing, formal verification, notified body audit
Vulnerability management Internal vulnerability handling process Documented CVD policy, coordinated disclosure, ENISA reporting All Class I requirements plus continuous monitoring and proactive threat assessment
Typical compliance cost €50K–€150K per product family €150K–€500K per product family €500K–€2M+ per product family

CRA and NIS2: The Combined Compliance Landscape

Steel producers face a dual regulatory requirement. The CRA governs the cybersecurity of products with digital elements, while the NIS2 Directive governs the cybersecurity of essential and important entities—including steel manufacturers classified as critical infrastructure. Understanding how these regulations interact prevents duplication of effort and ensures no compliance gap falls between them.

Cyber Resilience Act (CRA)
Focus: Products with digital elements
Who: Manufacturers, importers, distributors
Requires: Secure product design, vulnerability handling, CE marking
Reports to: ENISA (vulnerabilities & incidents)
Penalty: €15M or 2.5% global turnover
Overlap Zone
Asset inventory, vulnerability management, incident response, supply chain security, security monitoring
NIS2 Directive
Focus: Organizational cybersecurity posture
Who: Essential/important entities (steel = essential)
Requires: Risk management, incident handling, supply chain security
Reports to: National CSIRT (incidents)
Penalty: €10M or 2% global turnover

Compliance Roadmap: From Assessment to Certification

CRA compliance is a structured process that builds from gap assessment through remediation to formal conformity assessment. Starting the process 18–24 months before the December 2027 enforcement deadline provides adequate time for product modifications, testing, and certification.



Months 1–3
Scope Assessment & Product Inventory
Identify every product your company manufactures, imports, or distributes that contains digital elements. Classify each product into the appropriate CRA category (Default, Important Class I, Important Class II/Critical). Assess current security posture against CRA essential requirements. Identify gaps.
Deliverable: Complete product inventory with CRA classification, gap analysis report, and prioritized remediation plan


Months 4–9
Product Security Remediation
Address identified gaps: implement secure authentication, add encryption capabilities, harden default configurations, develop secure update mechanisms, implement logging functionality. Establish coordinated vulnerability disclosure processes. Build SBOM (Software Bill of Materials) for each product.
Deliverable: Products modified to meet essential requirements, SBOM generated, vulnerability handling process operational


Months 10–15
Testing & Documentation
Conduct security testing (internal for Default category, third-party for Important/Critical). Perform penetration testing, fuzz testing, and conformity verification. Prepare comprehensive technical documentation including risk assessment, security architecture, test results, and user security guidance.
Deliverable: Completed technical file, security test reports, user documentation with cybersecurity guidance

Months 16–20
Conformity Assessment & CE Marking
Submit to conformity assessment (self-declaration for Default, notified body for Important/Critical). Address any findings from assessment. Prepare and sign EU Declaration of Conformity. Apply CE marking to products. Establish ongoing vulnerability monitoring and update delivery processes.
Deliverable: CE-marked products with full CRA conformity, ongoing vulnerability management operational

For steel producers who are end users rather than product manufacturers, the compliance focus shifts to procurement, asset management, and incident handling. Facilities that sign up to manage their OT assets with complete lifecycle tracking build the asset inventory and configuration management infrastructure that CRA-adjacent requirements under NIS2 demand.

ROI: CRA Compliance Investment vs. Risk Exposure

Annual Value of CRA Compliance — Steel Equipment Manufacturer
€8M
EU Market Access Protection

Non-compliant products cannot carry CE marking — loss of EU market access for all digital products
€4.5M
Penalty Avoidance

Risk-adjusted exposure: €15M maximum penalty × probability of enforcement action for non-compliant products
€2.8M
Product Security Improvement

Reduced vulnerability exposure, fewer security incidents, and lower warranty/liability costs from more secure products
€1.5M
Competitive Differentiation

Early CRA compliance becomes a market differentiator — customers increasingly require demonstrated cybersecurity in procurement

Expert Perspective: Navigating CRA Compliance in Steel Manufacturing

"
The Cyber Resilience Act is the most significant regulatory shift for industrial equipment manufacturers since the original CE marking directive. For steel companies, the challenge is twofold. First, if you manufacture or sell any product with embedded digital elements—and most steel equipment companies do—you need to redesign your product development process to integrate security from the design phase, not retrofit it before shipment. This means security requirements in every product specification, threat modeling during design, secure coding practices, and security testing before release. Second, even if you're purely a steel producer and not an equipment manufacturer, the CRA changes your procurement process. You must require CRA-compliant products from your suppliers, track the cybersecurity status of every connected device in your OT environment, and manage vulnerability notifications from suppliers as part of your ongoing operations. The companies that treat CRA compliance as a strategic advantage—building more secure products, demonstrating cyber maturity to customers, and using compliance as a procurement differentiator—will outperform those that treat it as a regulatory burden to minimize.
Start product classification now — knowing which CRA category applies determines your entire compliance path
Build your SBOM capability — Software Bill of Materials will be required for every product with digital elements
Establish vulnerability disclosure before September 2026 — reporting obligations activate before full enforcement
Align CRA and NIS2 compliance — shared controls reduce duplication and total compliance cost by 30–40%

The EU Cyber Resilience Act represents a fundamental shift in how cybersecurity is regulated for industrial products and operations. Steel companies that begin compliance preparation now will meet the 2027 deadline with confidence. Those that wait risk market access disruption, regulatory penalties, and competitive disadvantage. If you need to build the OT asset management and documentation infrastructure that CRA compliance demands, book a free demo to see how a modern maintenance platform supports compliance readiness.

Compliance Starts with Visibility. Build It Now.
OxMaint provides the digital asset registry, maintenance lifecycle tracking, and documentation infrastructure that CRA and NIS2 compliance require. Know what you have, track its security posture, and demonstrate compliance with auditable records.

Frequently Asked Questions

Does the CRA apply to steel products themselves or only to digital equipment?
The CRA applies specifically to "products with digital elements"—meaning any product that includes software or connects to a network as part of its intended functionality. Raw steel products (coils, plates, bars) are not affected. However, steel products with embedded digital elements—such as pre-instrumented structural components with built-in sensors, smart steel products with embedded monitoring capabilities, or digitally-enabled manufacturing equipment—would fall within scope. The key question is whether the product includes software or firmware that enables network connectivity as part of its intended use. For most steel producers, the CRA primarily affects the industrial equipment and software they manufacture or supply to customers, rather than the steel products themselves. However, as the industry moves toward smart manufacturing and Industry 4.0, the boundary between "steel product" and "product with digital elements" is increasingly blurred.
What is a Software Bill of Materials and why does the CRA require it?
A Software Bill of Materials (SBOM) is a comprehensive inventory of every software component, library, and dependency included in a product—including open-source components, third-party libraries, and proprietary code. The CRA requires SBOMs because they enable effective vulnerability management: when a vulnerability is discovered in a widely-used library (like Log4j), an SBOM allows manufacturers and users to instantly determine which products are affected. For steel manufacturing equipment, this means cataloging every software component in your PLC firmware, HMI applications, SCADA systems, and embedded controllers. The SBOM must identify component names, versions, suppliers, and known vulnerabilities. Industry standards like SPDX and CycloneDX provide standardized SBOM formats. Building SBOM capability requires integrating SBOM generation into your software development and build processes—and maintaining the SBOM throughout the product lifecycle as components are updated.
How does the CRA interact with existing standards like IEC 62443?
IEC 62443 is the primary international standard for industrial automation and control system security, and it aligns closely with CRA requirements. The European Commission has indicated that harmonized standards based on IEC 62443 will provide a "presumption of conformity" with CRA essential requirements—meaning that products certified to the appropriate IEC 62443 security levels will be presumed to meet CRA requirements without additional assessment. Specifically, IEC 62443-4-1 (secure product development lifecycle) addresses CRA requirements for security by design. IEC 62443-4-2 (technical security requirements for components) addresses many of the product-level security requirements including authentication, access control, and data integrity. For steel companies already pursuing IEC 62443 certification, CRA compliance may require relatively modest additional effort—primarily around vulnerability disclosure, ENISA reporting, and SBOM generation. For those starting from scratch, pursuing IEC 62443 certification simultaneously with CRA compliance is the most efficient path because a single compliance program addresses both frameworks.
What are the ENISA reporting requirements and how do we prepare?
ENISA reporting under the CRA requires manufacturers to report two categories of events. First, actively exploited vulnerabilities in their products must be reported within 24 hours of becoming aware—an extremely tight timeline that requires pre-established processes. The initial notification can be brief (product affected, vulnerability description, known exploitation), but a detailed follow-up report is required within 72 hours and a final report within 14 days including remediation measures. Second, severe security incidents that affect the integrity of the product must be reported within 72 hours. Preparation requires four capabilities: a vulnerability monitoring process that tracks CVEs and threat intelligence relevant to your product components (this is where SBOMs become critical), an internal assessment process that can rapidly determine whether a vulnerability is actively exploited, a pre-drafted notification template and identified reporting contacts at ENISA, and a remediation process that can develop and distribute security patches within the reporting timeline. These reporting obligations activate in September 2026—before full CRA enforcement—so organizations must have these processes operational within the next year.
What happens to products already on the market when the CRA enforcement begins?
Products already placed on the EU market before the December 2027 enforcement date are not retroactively required to meet CRA requirements at that point. However, there are important nuances. First, any "substantial modification" to an existing product after the enforcement date triggers CRA requirements—and the definition of substantial modification includes significant software updates that affect cybersecurity properties. Second, ongoing vulnerability handling and reporting obligations apply to all products for which the manufacturer continues to provide support, regardless of when the product was first placed on the market. Third, new units of existing product models placed on the market after enforcement must comply, even if the product design predates the CRA. This means manufacturers cannot indefinitely sell non-compliant products by claiming they were designed before the regulation. The practical implication for steel companies is that product lines intended to remain on the EU market beyond 2027 need CRA remediation regardless of when they were originally designed. Products approaching end-of-life before 2027 may be exempted from the most expensive compliance investments.

Share This Story, Choose Your Platform!