Cyber Resilience Act · Machinery Regulation · NIS2

Turn CRA compliance into a process that runs every day

The CRA asks two things of every product. Shield Lifecycle covers both.

  • Before the sale: the evidence for the CE marking
  • After the sale: every new vulnerability checked, exploited ones reported, until the end of support
Three dates

Your machine runs software. EU law makes you responsible for its security.

Each date links to its regulation, with the official text. All three side by side.

Per delivered machine, not per model

Same model, same customer. One machine is exposed, the other is not.

A critical vulnerability hits a VPN gateway. One X-200 has it and drops to 68. The other was delivered with a different gateway and stays at 90.

CVE-2026-•••• · CVSS 9.1 New Affects VPN gateway GW-A · FW 2.4
  • PLC FW 2.9
  • HMI FW 17.0
  • GW-A FW 2.4
  • TLS 3.0.x
  • Linux 5.15-rt

GW-A 2.4 is inside and can be reached through remote maintenance.

X200-2024-001 Exposed · customer notice drafted
  • PLC FW 2.9
  • HMI FW 17.0
  • GW-B FW 5.1
  • TLS 3.0.x
  • Linux 5.15-rt

Delivered with GW-B. The CVE does not apply.

X200-2024-002 No active CVE
Same model, same line, different parts inside. Exposed means the vulnerable part is in this machine and can be reached through its network.

Vulnerable is not the same as exposed.

Talk to us

Tell us who you are and what you need. We answer fast, usually within one working day.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026

Background photo generated with AI.