The EU Cyber Resilience Act Is Coming : New Cybersecurity Compliance Challenges for Machine Tool Exports - Part II
IV. EN 40000: Future CRA Harmonised Standards
After understanding the practical value of IEC 62443, we also need to pay attention to another standards framework currently under development: EN 40000.
If the CRA is the legal requirement, and IEC 62443 is the engineering methodology that can be adopted immediately, then EN 40000 can be viewed as an important future standards-based pathway for CRA conformity assessment, helping manufacturers demonstrate that their products meet the cybersecurity requirements of the CRA.
(1) Positioning of EN 40000
As a horizontal harmonised standards series for the CRA, EN 40000 aims to translate the abstract regulatory requirements of CRA Annex I into verifiable standard requirements, including:
|
Standard Item |
Main Positioning |
Significance for Companies |
|
EN 40000-1-2 |
Cyber resilience principles / risk-based approach |
Product cybersecurity risk assessment and lifecycle security |
|
EN 40000-1-3 |
Vulnerability handling |
Vulnerability intake, analysis, remediation, disclosure, and coordinated disclosure |
|
EN 40000-1-4 |
Generic security requirements |
Product security controls, such as authentication, authorization, encryption, logging, and secure updates |
Among these, EN 40000-1-4 is particularly important for machine tool product development teams. EN 40000-1-4 focuses on Security Controls – Generic Security Requirements and serves as an important horizontal standard supporting the basic product requirements of the CRA. It is expected to establish a general security control framework for the product security requirements in CRA Annex I Part I, including:
- Identity authentication
- Access control
- Secure updates
- Secure communications
- Data protection
- Key management
- Secure storage
- Logging
- Monitoring and alerts
- Secure deletion
- Attack surface reduction
- Secure default settings
For smart machine tools, nearly all of these controls will ultimately be reflected in actual product design. For example:
- Does remote maintenance require multi-factor authentication?
- Do the gateway and cloud platform use TLS?
- Are firmware update files digitally signed?
- Can data be securely erased before a machine is decommissioned or resold?
- Are Linux, OpenSSL, Python, and AI packages included in SBOM management?
(2) Relationship Between EN 40000 and IEC 62443
One question may arise: if EN 40000 will be available in the future, is it still necessary to adopt IEC 62443 now?
The answer is yes. This is because EN 40000 is not an entirely new system built from scratch. Rather, it references existing standards, including IEC 62443, ETSI EN 303 645, and the ISO/IEC 27000 series. The relationship between them can be understood as follows:
|
Level |
Role |
Significance for Machine Tool Manufacturers |
|
CRA |
Regulatory requirement |
Legal obligation that must be met to enter the EU market |
|
EN 40000 |
Harmonised standard |
Important basis for obtaining future presumption of conformity with the CRA |
|
IEC 62443 |
Engineering methodology |
Secure development and product security implementation standard that can be adopted immediately at the current stage |
|
Internal Corporate Processes |
Implementation |
SBOM, PSIRT, OTA, security testing, and technical documentation |
In other words, adopting IEC 62443 now will not conflict with the future EN 40000 framework. On the contrary, it can significantly reduce future transition costs. If a company has already established secure development processes under IEC 62443-4-1 and product security controls under IEC 62443-4-2, it will only need to map existing documentation, test reports, and control measures to EN 40000 requirements in the future.
V. Action Recommendations for Machine Tool Manufacturers
Although EN 40000 is expected to become an important basis for future presumption of conformity with the CRA, given that the CRA will soon take effect in 2027, companies are advised to refer to IEC 62443 to establish fundamental compliance capabilities.
- Establish a product cybersecurity requirements checklist based on CRA Annex I, and inventory product and system architecture diagrams. Clearly list CNCs, PLCs, IPCs, gateways, operating systems, firmware, cloud APIs, mobile apps, and third-party packages.
- Establish an SBOM and a component vulnerability tracking mechanism. This is among the documents most likely to be requested during CRA and supply chain cybersecurity reviews.
- Establish vulnerability handling and customer notification processes to prepare for the forthcoming vulnerability reporting mechanism.
- Select a new machine model as a starting point for introducing the secure development process under IEC 62443-4-1.
- Use IEC 62443-4-2 to review product security functions, confirming whether the product has account management, access control, encrypted communications, secure updates, and logging capabilities.
At the same time, companies should continue monitoring developments in the EN 40000 harmonized standards, pay attention to CRA compliance seminars and advisory programs available in the market, and consult the Taiwan branches of organizations that may serve as EU conformity assessment bodies to better understand conformity assessment details. These actions can help shorten the learning curve and reduce compliance costs.