---
title: "Edge SDN | Turn CRA compliance into a process that runs every day"
description: "Shield Lifecycle prepares the evidence for the CE marking of every product and checks new vulnerabilities until the end of support. Edge Shield and Edge SDN reduce the attack surface of machines and plants."
url: https://www.edge-sdn.com/
last_updated: 2026-10-05
---

[13–16 Oct**Meet us at 35.BI-MU, Milan** Hall 24, stand A60C Book 15 minutes ](https://meet.brevo.com/edge-sdn-team/bi-mu)

Cyber Resilience Act · Machinery Regulation · NIS2

# Turn CRA compliance into a process that runs every day

The CRA asks two things of every product. Shield Lifecycle covers both.

- **Before the sale: the evidence for the CE marking**
- **After the sale: every new vulnerability checked, exploited ones reported, until the end of support**

Three dates

## Your machine runs software. EU law makes you responsible for its security.

1. [11 Sep 2026 **CRA reporting duty** Report actively exploited vulnerabilities and severe incidents within 24 hours. It also covers products already on the market.](https://www.edge-sdn.com/regulations/cyber-resilience-act/)
2. [20 Jan 2027 **Machinery Regulation applies** Cybersecurity becomes an essential health and safety requirement for CE marking of machines.](https://www.edge-sdn.com/regulations/machinery-regulation/)
3. [11 Dec 2027 **CRA applies in full** Every new product with digital elements needs an SBOM, vulnerability handling and security updates.](https://www.edge-sdn.com/regulations/cyber-resilience-act/)

Each date links to its regulation, with the official text. [All three side by side](https://www.edge-sdn.com/regulations/).

Per delivered machine, not per model

## Same model, same customer. One machine is exposed, the other is not.

A critical vulnerability hits a VPN gateway. One X-200 has it and drops to 68. The other was delivered with a different gateway and stays at 90.

Same model, same line, different parts inside. **Exposed** means the vulnerable part is in this machine and can be reached through its network.

Vulnerable is not the same as _exposed_.

Start from your problem

## Which one are you?

I build machines

### Your machines run software you did not write

When a component has a vulnerability, you must know which delivered machines are exposed and tell the customer.

[Keep every machine CRA-ready](https://www.edge-sdn.com/products/shield-lifecycle/)

I build software products

### A 24-hour reporting duty, and no security team

The CRA asks for an SBOM, vulnerability handling and fast reporting, every day.

[See what the CRA asks](https://www.edge-sdn.com/regulations/cyber-resilience-act/)

I run a plant

### Segment the OT network without stopping production

Old machines, flat networks and auditors who ask for NIS2 and IEC 62443 evidence.

[Segment on the switches you have](https://www.edge-sdn.com/products/edge-sdn/)

Photos generated with AI.

The product line

## Find what is exposed. Protect it. Prove it.

Cyber Resilience Act

### Shield Lifecycle

Know every day which machines you shipped are exposed to a new vulnerability, and tell your customer in time.

[Explore Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/)

Machinery Regulation · IEC 62443

### Edge Shield

Reduce the attack surface of the machine. Micro-segment and inspect its traffic, without touching the network or the PLC program.

[Explore Edge Shield](https://www.edge-sdn.com/products/edge-shield/)

NIS2 · IEC 62443

### Edge SDN

See and segment the whole OT network from one console, without stopping production.

[Explore Edge SDN](https://www.edge-sdn.com/products/edge-sdn/)

## Talk to us

Tell us who you are and what you need. We answer fast, usually within one working day.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026

Background photo generated with AI.
