0
European Cyber Resilience Act
Are you working to correspond to the new European Cyber Resilience Act ?
It will be imposed by the Machinery Directive in 2027.
https://industrialcyber.co/expert/cra-and-machinery-regulation/
Customer support service by UserEcho
Yes, the upcoming regulatory changes for products on is in full focus here at the IQAN team.
In the near future you will be seeing more information and updates related to this topic.
There are separate (and partially overlapping) regulatory requirements coming, where the inclusion of cybersecurity in the Machinery Regulation is an important step for those who use (or should use) IQAN-MC4xFS in safety functions.
The EU Machinery regulation is replacing the current Machinery Directive already in January 2027
EU Cyber Resilience Act has a wider scope and adds new requirements to essentially all products, all requirements here must be fulfilled after December 2027
Hello, what is the IQAN team's current stance on this EU compliance?
Are the secureboot models required for Machinery Regulation or just CRA?
All logs get wiped during certain programming; would you need a persistent log of software/firmware updates?
They want '5 years' of records for that?
Should the ability to mark function groups as 'Frozen' be used for critical safety (marked FS) logic?
They want safety settings and rules to have 'no modifications allowed'.
Any other consideration to keep in mind for the January 2027 and December 2027 dates?
It is important to have systems with IQAN master modules that will be supported in IQANdesign 8. IQAN-MD5 series and MC4x/MC4xFS.
Version 8 is adding security enhancements needed for Machinery Regulation and CRA, and will support security updates in accordance with CRA.
The Parker IQAN approach is compliance via IEC 62443, going for SL-C2. Secure boot is a requirement on the Security Level SL 2.
Audit logs need to be access protected, but truly persistent logging is only required at SL 4.
The IQANdesign 'frozen' feature only protects from accidental modification by person who has access to editing the project file, for security it is more important to limit who has access to editing project files.
What changed are needed to production / field update environment with IQANrun and IQANscript? Currently we have IQAN run 6 widely in field use.
If you are currently using the recommended way issuing safe passwords for service technicians, and never use clear text passwords in the field, I'd say you are relatively well prepared for the version 8 changes.
We'll have more information on how to issue credentials (login) for IQANdesign version 8 systems shortly.