---
title: "CRA, Machinery Regulation and NIS2: dates and duties | Edge SDN"
description: "Dates and duties of the Cyber Resilience Act, the Machinery Regulation 2023/1230 and NIS2 for machine builders and plants, with links to the official texts."
url: https://www.edge-sdn.com/regulations/
last_updated: 2026-09-30
---

# Three EU rules, three dates, one machine

If your machine contains software and you sell it in the EU, two regulations apply to you as a manufacturer. If your company is a medium or large organisation in a listed sector, a third one applies to your own networks. Machine building is a listed sector. This page gives the dates and the duties, with links to the legal texts.

Last updated 30 September 2026. This page is a summary and not legal advice.

[11 Sep 2026**CRA reporting duty**Report actively exploited vulnerabilities and severe incidents within 24 hours. It also covers products already on the market.](https://www.edge-sdn.com/regulations/cyber-resilience-act/)[20 Jan 2027**Machinery Regulation applies**Cybersecurity becomes an essential health and safety requirement for CE marking of machines.](https://www.edge-sdn.com/regulations/machinery-regulation/)[11 Dec 2027**CRA applies in full**Every new product with digital elements needs an SBOM, vulnerability handling and security updates.](https://www.edge-sdn.com/regulations/cyber-resilience-act/)

Regulation (EU) 2024/2847

## Cyber Resilience Act

Every product with digital elements must be secure by design. 24-hour reporting since 11 September 2026, SBOM and security updates from 11 December 2027.

Manufacturers, importers and distributors of products with digital elements.

[Dates, duties and fines ](https://www.edge-sdn.com/regulations/cyber-resilience-act/)

Regulation (EU) 2023/1230

## Machinery Regulation

From 20 January 2027, protection against cyber threats is an essential health and safety requirement for CE marking.

Manufacturers of machinery, and whoever makes a substantial modification.

[Dates, duties and fines ](https://www.edge-sdn.com/regulations/machinery-regulation/)

Directive (EU) 2022/2555

## NIS2

Risk management, supply chain security and 24-hour incident reporting for organisations in critical sectors. In Italy: Legislative Decree 138/2024.

Medium and large organisations in the listed sectors, machinery manufacturing included.

[Dates, duties and fines ](https://www.edge-sdn.com/regulations/nis2/)

Side by side

## Which rule asks what

|                         | Cyber Resilience Act                                                    | Machinery Regulation                                                                  | NIS2                                                                       |
| ----------------------- | ----------------------------------------------------------------------- | ------------------------------------------------------------------------------------- | -------------------------------------------------------------------------- |
|                         | [Full page](https://www.edge-sdn.com/regulations/cyber-resilience-act/) | [Full page](https://www.edge-sdn.com/regulations/machinery-regulation/)               | [Full page](https://www.edge-sdn.com/regulations/nis2/)                    |
| **Applies to**          | Products with digital elements                                          | Machinery and safety components                                                       | Organisations in critical sectors                                          |
| **You are affected as** | Manufacturer, importer, distributor                                     | Manufacturer, importer, distributor, modifier                                         | Medium or large organisation in a listed sector, machine builders included |
| **Key dates**           | 11 Sep 2026 reporting · 11 Dec 2027 in full                             | 20 Jan 2027                                                                           | In force through national laws                                             |
| **Core duty**           | SBOM, vulnerability handling, security updates, 24-hour reporting       | Protect safety software and control systems against corruption and attacks, keep logs | Risk management, supply chain security, incident reporting                 |
| **Our product**         | [Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/) | [Edge Shield](https://www.edge-sdn.com/products/edge-shield/)                         | [Edge SDN](https://www.edge-sdn.com/products/edge-sdn/)                    |

Check 2027

### Where are you against these dates?

Seven questions about how you work today, three minutes. You get a score out of 10 and the two things to fix first, by email.

[Take the Check 2027](https://www.edge-sdn.com/check-2027/)

## Where are you against 20 January 2027?

Seven questions about how you work today. Three minutes. You get a score out of 10 and what is missing for you.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026
