MES, SCADA, or industrial machinery may fall under the Cyber Resilience Act if they qualify as products with digital elements made available on the EU market and their use involves a direct or indirect data connection to a device or network.
The name of the system, Internet access, or the presence of a PLC alone does not determine whether CRA applies. For manufacturers, the first step is to establish exactly what the product is, how it reaches the customer, and who is responsible for placing it on the market.
This distinction is already worth keeping in mind. The reporting obligations under Article 14 of the CRA start applying on September 11, 2026, while most of the remaining requirements apply from December 11, 2027.
Do SCADA, MES, and Industrial Machines Fall Under the CRA? First, Define What You Sell
The CRA covers hardware and software classified as products with digital elements. This category may include finished products, components offered independently, and certain remote data processing solutions. A product must be made available on the market and have an intended or reasonably foreseeable data connection to a device or network. For an industrial company, this leads to the following initial assessment:
| Scenario | What to check |
|---|---|
| SCADA installed at customer sites and offered as a product | Typically requires a CRA assessment if it meets the definition of a product with digital elements |
| MES installed on premises at the customer site | Typically requires a CRA assessment under the same principles as other software |
| MES developed exclusively for internal use within a plant | As a rule, remains outside the CRA product scope if it is not made available on the market |
| MES offered exclusively as SaaS | SaaS itself is generally not a product covered by the CRA, but related locally installed software may require a separate assessment |
| Machine with PLC, HMI, and network connectivity sold in the EU | Requires verification of whether the machine qualifies as a CRA product and whether any sector-specific exclusion applies |
CERT Polska also points out that typical software provided exclusively as SaaS remains outside the scope of the CRA, while software and devices placed on the EU market may be covered.
A similar distinction applies between software developed exclusively for a single organization and a solution supplied to a customer for payment. For industrial equipment, particular attention should be paid to software, communications, and the way the product is made available.
A 5-Question CRA Test for SCADA, MES, and Industrial Machinery
1. What Is the Product in Your Offering?
Start with the SKU, software version, or machine configuration. Separate the machine, PLC, HMI, firmware, MES or SCADA application, and any components sold independently.
The CRA also covers software and hardware components placed on the market separately. A manufacturer of a complete machine should also know which third-party digital components are included in the product. This information will later be needed for cybersecurity risk assessment and vulnerability handling.
2. Does the Product Exchange Data With a Device or Network?
No connection to the public Internet does not automatically mean that the CRA does not apply. Article 2 covers direct and indirect, logical and physical data connections to a device or network. A SCADA system communicating only with PLCs inside a closed OT network may therefore still meet this condition.
The person responsible for OT should review interfaces, communication protocols, remote administration, update mechanisms, and dependencies on other systems.
3. Is the Product Made Available on the Market?
If your company develops its own production reporting tool and uses it exclusively within its own facility, the situation is different from supplying the same software to a customer for payment. The European Commission indicates that products with digital elements not supplied in the course of a commercial activity are not covered by the CRA.
This distinction is particularly relevant for custom MES solutions and applications developed by system integrators.

4. Are You the Manufacturer, Importer, or Distributor?
The scope of obligations depends on your company’s role. A manufacturer is responsible, among other things, for cybersecurity risk assessment, product security requirements, technical documentation, conformity assessment, and vulnerability handling.
A manufacturing company that purchases an off-the-shelf SCADA system for internal use is therefore in a different legal position than a company selling that system under its own name. Machines imported from outside the EU also require a separate assessment.
5. Are You Modifying a Product That Is Already on the Market?
For retrofits, updates, and modifications to existing machines, you need to determine whether the change qualifies as a substantial modification under the CRA. The European Commission’s current guidance dated July 27, 2026, includes a dedicated section on this topic because the nature and extent of a modification may affect the obligations applicable to an existing product.
Do not assume that every PLC replacement or SCADA update automatically creates a new product. First assess the nature and impact of the change.
For Industrial Machinery, CRA Obligations Extend Beyond the Acceptance Date
A manufacturer of a product covered by the CRA must define a support period and effectively handle vulnerabilities throughout that period. The European Commission indicates that the support period should be at least five years unless the product’s expected lifetime is shorter.
A machine manufacturer needs to be prepared for this before the product is sold. The organization should know which firmware versions, libraries, and components are included in the product, who monitors vulnerability information, and how security updates will be prepared and delivered to the user.
You can start preparing for the CRA by inventorying products, versions, components, vulnerability management processes, and support periods.
Prepare for the CRA with greater confidence. Start with technology consulting.
September 11, 2026 Changes Manufacturers’ Priorities
Starting September 11, 2026, manufacturers subject to Article 14 will be required to report actively exploited vulnerabilities and severe incidents affecting product security. An early warning must be submitted within 24 hours of becoming aware of the issue, while the full notification is generally due within 72 hours.
The transitional rule is also important. Products placed on the market before December 11, 2027 generally become subject to the remaining CRA requirements if they are substantially modified after that date. The reporting obligations are an exception and also apply to products made available on the market earlier.
Waiting until the end of 2027 to analyze your product portfolio could therefore leave a manufacturer without the procedures required as early as September 2026.
Where Should an Industrial Company Start Its CRA Assessment?
The first document does not need to be an extensive legal analysis. Create a product register that includes the product name and version, business owner, digital components, network interfaces, delivery model, sales market, your organization’s role, and the planned support period.
Involve people responsible for automation or product development, IT/OT, quality or compliance, and product market introduction. Webinar materials similarly indicate that CRA readiness requires collaboration across technical, security, quality, legal, procurement, and product management teams.
If you first need to organize communication between PLCs, SCADA, MES, and the plant network, knowledge of industrial IT infrastructure and IT/OT communications can help you build a clearer foundation.
For now, create a list of the MES systems, SCADA systems, and machines your company sells. For each one, record the connectivity model, delivery model, and your organization’s role. Products that meet the CRA criteria should then move to a detailed technical and legal qualification.

FAQ
Does a SCADA System Without Internet Access Fall Under the CRA?
It may. The CRA also covers products that use a direct or indirect data connection to a device or network. Internet access is not a mandatory condition.
Does an MES System Delivered as SaaS Fall Under the CRA?
A service delivered exclusively as SaaS is generally not considered a product covered by the CRA. If the solution includes locally installed software or other elements that qualify as products with digital elements, those components should be assessed separately.
Does Every Machine With a PLC Require External CRA Certification?
No. The conformity assessment procedure depends on the product category. For many products, internal conformity assessment may be possible, while important and critical products may be subject to different procedures.
Don’t let new regulations catch you off guard. Let’s talk about your readiness today.
Explore the practical side of information technology in manufacturing with the explitia blog.