Cyber rules reach the control cabinet

Cyber rules reach the control cabinet

European Commission guidance has clarified how the Cyber Resilience Act applies to connected products, remote services, support periods, modifications, and vulnerability reporting ahead of September obligations.

Cyber rules reach the control cabinet
Summary
  • Cyber Resilience Act reporting obligations begin on 11 September 2026, before the main product requirements in December 2027.
  • New guidance uses 67 examples to explain scope, remote processing, support periods, modifications, and risk assessment.
  • Connected controls and equipment suppliers face closer scrutiny of product security, firmware support, and vulnerability processes.

The European Commission has published implementation guidance for the Cyber Resilience Act, clarifying how the legislation applies to connected products, remote data-processing services, software modifications, support periods, risk assessments, and vulnerability reporting.

The non-binding guidance arrives before the Act’s first operational deadline. Mandatory reporting begins on 11 September 2026, while the main requirements governing products placed on the European market apply from 11 December 2027.

Its 67 examples, use cases, flowcharts, and diagrams extend well beyond conventional computers. Building-management controllers, intelligent power-distribution units, cooling gateways, access systems, network appliances, environmental sensors, and remote-maintenance platforms can all fall within the Act’s product-security framework.

Product security enters technical procurement

The Cyber Resilience Act covers products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect connection to a device or network. Manufacturers must assess cyber risk, address vulnerabilities throughout the support period, provide security updates, and complete the required conformity process before covered products enter the EU market.

Data centre infrastructure contains networked components across its electrical, mechanical, and security systems. UPS interfaces, generator controllers, cooling-system gateways, data centre infrastructure management appliances, building controls, and intelligent rack equipment may all carry embedded software and remote connectivity.

The guidance explains when a remote data-processing service forms part of a product. A cloud-hosted function may be captured where it is necessary for the product to perform one of its intended functions, which can include monitoring, analytics, configuration, licensing, or security updates.

Manufacturers will therefore need to define whether remote services are optional additions or integral parts of the product. Buyers will need the same information when they assess dependency on a vendor platform, the location of operational data, and the effect of losing access to the remote service.

The Commission also examines substantial modification. Changes that alter a product’s intended purpose or cyber risk can create fresh obligations for the party carrying them out. An integrator may cross that threshold after changing firmware, adding remote access, combining equipment with a different control platform, or materially altering a product after it has entered service.

An operator does not become a manufacturer simply by purchasing and using connected equipment, although its responsibilities can change if it imports a product, distributes it under its own name, or carries out a modification that meets the statutory test.

Support periods must match long-lived plant

Reporting obligations begin before the full product regime. Manufacturers will need to notify actively exploited vulnerabilities and severe security incidents, while also navigating contractual requirements, NIS2-related duties, and sector-specific rules that may apply to the same event.

Critical equipment often remains in service for 15 or 20 years, yet its embedded operating systems, gateways, or communications cards can become obsolete much sooner. A short firmware-support period can therefore leave otherwise serviceable electrical or mechanical plant carrying an unsupported network interface.

Replacing that component may require downtime, control-system changes, renewed testing, and recommissioning. Procurement specifications will increasingly need firm information on update periods, vulnerability handling, software dependencies, and the commercial arrangements available after standard support ends.

Software bills of materials, secure-update mechanisms, disclosure policies, and support commitments are likely to become routine parts of technical submittals. Consulting engineers and contractors will also need to ensure that substitutions, firmware changes, and integrated packages preserve the security assumptions on which a design was approved.

Remote maintenance remains another pressure point. Vendors often require access for diagnosis and software support, while operators seek to restrict pathways into operational networks. Product compliance will sit alongside network segmentation, privileged-access controls, session recording, multifactor authentication, and strict approval of third-party connections.

Conformity documentation may follow equipment through design, construction, commissioning, and operation. A product delivered with one firmware version and commissioned with another will need controlled records showing which configuration was installed and whether its security status has changed.

The Commission’s guidance and accompanying annex reduce some uncertainty, although the legal text, harmonised standards, national enforcement, and later guidance will continue to determine how the requirements are applied.

Equipment being specified now may remain on sale, enter construction, or receive support after the main obligations take effect. Cybersecurity evidence is consequently becoming part of the permanent product and commissioning record rather than a general assurance supplied separately from the engineering package.


Stay updated with the latest insights and trends in the data centre industry by subscribing to our newsletter.

← Back

Thank you for your response. ✨