B&Rs commitment to the EU cyber resilience act

B&R is advancing CRA readiness for its products through IEC 62443-based secure development, timely vulnerability handling and clear security documentation – supporting our customers to address their Cyber Security requirements

Machine builders, system integrators and operators of industrial automation systems need partners who take Cyber Security and regulatory obligations seriously. At B&R Industrial Automation GmbH, we are preparing our products and processes for the EU Cyber Resilience Act (CRA) with a clear focus on delivering secure products, providing transparent information and offering reliable support for our customers. Our approach is grounded in established, practiced and certified IEC 62443-4-1 processes and IEC 62443-4-2 defined product Cyber Security capabilities.

By anchoring our efforts on these internationally recognized standards, we ensure that our solutions not only meet the CRA requirements but also address the regulatory frameworks and industry-specific requirements of other countries, including the updated Machine Regulation 2023/0123.

We believe trust starts with action. That’s why we have taken a proactive approach to the Cyber Resilience Act (CRA) – implementing requirements early and working closely with our customers to navigate what comes next.

Stefan Schönegger
CTO

B&R addresses Cyber Security across the full product lifecycle. From risk-based design and secure development through testing and vulnerability handling and security updates. We maintain a comprehensive approach that includes internal security tests, DSAC (ABB Device Security Assurance Center) validation, and independent penetration tests. We also support coordinated vulnerability disclosure, publish security advisories, create SBOMs (Software Bills of Materials), and digitally sign software packages to ensure the integrity and authenticity of our software deliverables.

Beyond these technical measures, we are committed to providing our customers with the resources they need. B&R is sharing relevant Cyber Security documentation already today, such as guidance on securely design and operate B&R POWERLINK machines, or taking advantage of continuously added Cyber Security features. We are also strengthening the information and documentation that support secure installation, operation, maintenance and update management, this includes visibility of CRA compliance on product level.

As the regulatory landscape continues to evolve, we remain closely engaged with the European legislative roadmap and actively participate in standardization activities. Our goal is to provide our customers with reliable, practical and up-to-date guidance and trainings as the legal and technical framework matures.

B&Rs Cyber Security implementation continues by stringently applying IEC 62443-4-1 and IEC 62443-4-2, closely monitoring EU legislation and standards, and informing our customers through advisories, documentation and direct support. At B&R we’re creating a practical path toward CRA readiness for B&R products today.

Robert Fuchs
Cyber Security Officer

Vyberte prosím zemi a jazyk

B&R Logo