Go back

Safety & Security

Vulnerability reporting for OEMs - legal basics

cybersecurity lock

Vulnerability reporting is now mandatory in the EU

Mandatory vulnerability reporting is how regulators ensure that serious security weaknesses and cyber incidents are found, fixed and shared fast enough to protect operators, bystanders and the wider market. For OEMs, it turns “nice-to-have” security routines into legal duties tied directly to CE marking and market access.

 

The Cyber Resilience Act (CRA) makes this explicit. From 11 September 2026, manufacturers of products with digital elements must notify actively exploited vulnerabilities and severe security incidents affecting those products.

They must send

  • an early warning within 24 hours

  • a detailed notification within 72 hours

  • a final report after corrective measures are available.

That timeline is written into EU law, not into an internal policy.

Cybersecurity and the EU CRA 1080x1080-3-What makes a machine a -product with digital...- (1)

 

 

 

 

 

 

What it means for a machine builder

For a machine builder, this is not just an IT requirement. If a vulnerability in a radio remote control, gateway or software module can affect functional safety or machine availability, you are expected to detect it, assess it and escalate it. Reporting becomes part of the safety chain, just like risk assessments and safety functions already are.

Seen from the regulator’s perspective, unreported vulnerabilities create systemic risk. A weakness discovered on one (i.e.) crane, harvester or concrete pump may also exist in thousands of similar machines across the EU. Without a structured reporting obligation, those machines continue operating with a known, exploitable flaw – and the responsibility ultimately lands on the manufacturer.

How CRA, RED and the Machinery Regulation fit together

The Cyber Resilience Act (CRA) does not stand alone. For mobile machines and remote control systems, it sits alongside the Radio Equipment Directive (RED) and the Machinery Regulation (MR) which is replacing the Machinery Directive in January 2027. Together, they define how security, safety and connectivity must be handled across the full system – from the transmitter to the hydraulic valves.

RED focuses on radio equipment, including industrial radio remote controls. Its cybersecurity requirements under Article 3(3) started to apply from 2025 and cover, for example, protection against fraud and misuse of network resources.

The Machinery Regulation sets safety requirements for machinery placed on the EU market, explicitly recognising that cybersecurity issues can become safety issues when control systems are compromised.

The CRA adds horizontal cybersecurity requirements for “products with digital elements”. It also creates clear obligations after placement on the market: manufacturers must handle vulnerabilities for the declared support period and report actively exploited vulnerabilities and severe incidents via a central EU platform. The European Commission describes this in its overview for manufacturers at digital-strategy.ec.europa.eu.

 

Manufacturers must handle vulnerabilities for the declared support period and report actively exploited vulnerabilities and severe incidents via a central EU platform

For OEMs who want to integrate a remote control into a machine, this means different pieces of legislation apply to different layers of the system. The transmitter and receiver must meet RED. The complete machine, including its control architecture, must meet the Machinery Regulation. And any component with digital elements – including remote control systems – falls into the CRA’s lifecycle and reporting obligations.

What mandatory reporting means in practice for machine builders

What does all this add up to on your side of the drafting table? In practical terms, mandatory reporting means you are expected to treat vulnerabilities and cyber incidents with the same structure and traceability as you already treat safety incidents and field failures.

CRA three steps

Concretely, this has three main implications

  1. The need to be able to detect relevant security issues. A vulnerability discovered is not just a component problem – it may directly affect the machine’s risk profile.

  2. One must assess impact: which machine types, serial ranges and configurations are affected, and how could safety or operations be compromised?

  3. One must decide when a situation meets the threshold for regulatory reporting under the CRA.

Documenting the assessment – including why the issue was or was not escalated – becomes part of the compliance evidence.

This does not mean every software bug becomes a regulatory case. But it does mean that defined criteria, owners and workflows are needed so that when a serious issue emerges, one can move from discovery to assessment and reporting without improvisation.

Work with suppliers who meet vulnerability reporting duties

No OEM wants to run a separate security lifecycle for every component in a machine. To meet reporting duties efficiently, you should choose suppliers who already treat product security as part of their design and support process – not as an add-on.

The more transparent this exchange is, the easier it becomes to demonstrate to a regulator that you have treated the vulnerability responsibly. Instead of claiming perfection, you show traceable cooperation between OEM and component supplier around real issues.

At Scanreco, reports are handled through a structured workflow of review, assessment, investigation, mitigation and communication, aligned with the CRA’s reporting obligations. That structure is what allows machine builders to plug supplier information into their own incident management.


Where to go next: guidance, whitepapers, and internal steps

Mandatory vulnerability reporting can feel like one more burden in an already complex regulatory landscape. But the same structures that keep you compliant also make your machines more predictable, supportable and trustworthy over their lifetime.

If you are still at the early stages, it is definitely time to begin as incident reporting is mandatory since earlier this year. A sensible first next step is to build an internal view of how CRA and the Machinery Regulation apply to your machine portfolio.

Learn more:

Our page about cybersecurity regulations for remote controlled machines outlines how these laws intersect for radio remote control.

On the same page you can watch a webinar series where we take you through the legislation step by step.

Whitepaper: Machinery Regulation – to align engineering, legal and product management on a common threat and obligation picture.

The Safety & Security articles in our knowledge hub may be useful conversation starters with teams who may not think of themselves as working with cybersecurity yet.


Finally, define your minimum viable process: who receives vulnerability reports, who leads impact assessments, how you involve suppliers, and how you decide when a case must be reported under the CRA. With that in place, vulnerability reporting becomes not just a legal requirement, but a predictable part of how you design, support and continuously improve remote-controlled machines.

Cybersecurity and the EU CRA 1080x1080-5

Contact

Contact us for more information!

Related content