0

European Cyber Resilience Act

A DOMS 12 months ago updated by Gustav Widén (System support) 1 week ago 5

Are you working to correspond to the new European Cyber Resilience Act ?
It will be imposed by the Machinery Directive in 2027.

https://industrialcyber.co/expert/cra-and-machinery-regulation/

https://www.european-cyber-resilience-act.com/

+1

Yes, the upcoming regulatory changes for products on is in full focus here at the IQAN team. 

In the near future you will be seeing more information and updates related to this topic. 

There are separate (and partially overlapping) regulatory requirements coming, where the inclusion of cybersecurity in the Machinery Regulation is an important step for those who use (or should use) IQAN-MC4xFS in safety functions. 

The EU Machinery regulation is replacing the current Machinery Directive already in January 2027

EU Cyber Resilience Act has a wider scope and adds new requirements to essentially all products, all requirements here must be fulfilled  after December 2027

+1

Hello, what is the IQAN team's current stance on this EU compliance?


Are the secureboot models required for Machinery Regulation or just CRA?

All logs get wiped during certain programming; would you need a persistent log of software/firmware updates?

       They want '5 years' of records for that?

Should the ability to mark function groups as 'Frozen' be used for critical safety (marked FS) logic?

       They want safety settings and rules to have 'no modifications allowed'.

Any other consideration to keep in mind for the January 2027 and December 2027 dates?

It is important to have systems with IQAN master modules that will be supported in IQANdesign 8. IQAN-MD5 series and MC4x/MC4xFS. 

Version 8 is adding security enhancements needed for Machinery Regulation and CRA, and will support security updates in accordance with CRA.

The Parker IQAN approach is compliance via IEC 62443, going for SL-C2.  Secure boot is a requirement on the Security Level SL 2. 

Audit logs need to be access protected, but truly persistent logging is only required at SL 4. 

The IQANdesign 'frozen' feature only protects from accidental modification by person who has access to editing the project file, for security it is more important to limit who has access to editing project files. 


What changed are needed to production / field update environment with IQANrun and IQANscript? Currently we have IQAN run 6 widely in field use.

If you are currently using the recommended way issuing safe passwords for service technicians, and never use clear text passwords in the field, I'd say you are relatively well prepared for the version 8 changes. 


We'll have more information on how to issue credentials (login) for IQANdesign version 8 systems shortly.