Cyber Resilience Act

Security as an integral part of our sensors

The increasing level of connectivity in industrial automation is opening up new opportunities for efficiency and transparency – yet at the same time, demands on cybersecurity are also rising. For Leuze, security is therefore not merely a downstream issue, but a central component of product quality and corporate responsibility. Our aim is to develop sensor solutions that not only are high-performing and reliable, but also meet current and future security requirements.

We take a holistic approach to this: from development and production right through to the operation of our products at the customer’s premises. We are constantly working to further develop our internal processes, methods and structures to identify potential risks at an early stage and address them systematically. At the same time, we monitor technological developments and regulatory requirements very closely so that we can take the right measures at an early stage.

In this way, we lay the foundations to ensure that you can rely on one thing:
secure, future-proof sensor solutions for your applications.

CRA-4_700x500px
CRA-5_700x500px

The Cyber Resilience Act (CRA) – explained simply

The Cyber Resilience Act (CRA) is a new EU regulation aimed at significantly improving the cybersecurity of products containing digital elements. This includes many components used in industrial automation – such as sensors, controls and networked systems.

The aim of the CRA is to establish a uniform level of security across the European Union whilst also providing greater transparency for users. For you as a customer, this means clearer information, transparent security standards and better-protected products in use.

Specifically, the CRA requires manufacturers to consider cybersecurity throughout the entire product lifecycle. This begins as early as the development phase (“Security by Design”) and includes, among other things, regular risk assessments, a structured approach to addressing vulnerabilities, and the provision of security-related updates.

Another key component is mandatory reporting: in future, serious security incidents and actively exploited vulnerabilities must be reported within defined timeframes. This is intended to enable a faster response to new threats and reduce the risk to users.

The first requirements will come into force from September 2026, with full implementation scheduled for December 2027. This gives companies time to adapt their processes and products in stages.

For users, the CRA means one thing above all: greater security, greater reliability and a stronger focus on protecting industrial systems in an increasingly connected world.


Cyber Resilience Act (CRA) overview:

  • EU Regulation 2024/2847 for digital product cybersecurity
  • Uniform standards and greater transparency
  • Security throughout the entire product lifecycle
  • Mandatory risk assessments and updates
  • Reporting obligations from September 2026 for serious security incidents and actively exploited vulnerabilities
  • Full implementation by December 2027


How we prepare our sensors to meet these requirements:

To ensure your operations are as secure as possible, we analyze our entire range of sensors. In doing so, we identify which products are affected by the EU regulations and assess any potential risks even before delivery. This includes threat analyses, risk assessments and defining appropriate protective measures. Our aim is to ensure that our sensors not only impress in terms of their functionality, but also meet the required security standards – particularly in sensitive and industrial environments. 

1. Security is built in from the development stage

Before a sensor is manufactured, we ensure that security considerations are firmly embedded in the development process and assessed. This includes clear security requirements, well-documented software components (SBOM), automated checks, code reviews and comprehensive security tests such as penetration tests and static code analysis. By following this approach, we prevent vulnerabilities from arising in the first place and sustainably improve product quality. 

2. Security features integrated directly into the product

Our newly developed sensors will be fitted with multiple protective mechanisms upon delivery. These include secure default settings with only the necessary access rights and permissions (“Security by Default”), a secure boot process in which only software signed by Leuze may be loaded (“Secure Boot”), and secure updates that are transmitted in encrypted form and verified. If an update fails, a rollback mechanism ensures operational security. These measures significantly reduce the attack surface and reliably protect your systems during operation. 

3. Secure processes in production and during commissioning

We will also prioritize security in the production process: Software artefacts are stored with digital signatures, access is strictly regulated and all verification steps are documented. During commissioning, we check for updates, set up secure networks and ensure that configurations are loaded and archived correctly. In future, we will provide you with a digital product passport containing important information such as manuals and certificates. 

4. How we deal with vulnerabilities – transparently and quickly

If a vulnerability is discovered at a later date, we respond immediately: We assess the risk, document it, provide solutions or updates, and actively inform affected customers. At the same time, we continuously monitor international public databases for security vulnerabilities so that new risks can be detected at an early stage. In this way, we ensure maximum transparency and remain a reliable partner at your side, even after your purchase. 

CRA-2_700x500px
CRA-1_700x500px

What this means for you as a customer – your benefits at a glance

Cybersecurity protects your production and ensures that your operations remain smooth, reliable, and efficient.

  • Reduced risk of production downtime:
    Targeted protective measures fend off attacks and disruptions at an early stage, ensuring that your production processes run continuously.
  • Higher system availability:
    Fewer unplanned downtimes mean greater productivity and optimized utilization of your machinery.
  • Protection of sensitive operational data:
    Your valuable information remains confidential and secure, both within your organization and against unauthorized access.
  • Future-proofing through regulatory compliance:
    Our solutions enable you to meet current security requirements whilst ensuring you are prepared for future standards.


Cybersecurity for your systems: Frequently asked questions about the CRA

The Cyber Resilience Act (CRA) is an EU regulation on the cybersecurity of products containing digital elements.

Example: A manufacturer of conveyor systems must ensure that the control software is protected against hackers so that production is not brought to a halt.

Essentially, this applies to all products containing digital elements that exchange data or communicate with other products or a network – regardless of the industry or field of application.

Example: Both a sensor on a production line and a smart maintenance device fall within the scope of the regulations.

The CRA will take full effect on December 11, 2027. Initial obligations regarding the reporting of actively exploited vulnerabilities and serious security incidents will take effect as early as September 11, 2026.

Example: A machine builder should conduct security assessments as early as the development phase to avoid having to make adjustments later on.

Yes – cybersecurity is systematically integrated throughout the entire development process.

Example: Potential threats and risks to the control software are assessed right from the design phase of a conveyor system, and appropriate protective measures are implemented.

Manufacturers must identify security risks, safeguard their products, provide security updates, and demonstrate compliance with regulations.

Example: A manufacturer of packaging machines documents all security measures and provides regular software updates.

Customers receive more secure products that are less vulnerable to attacks. This reduces production downtime, protects sensitive data, and ensures long-term reliability.

Example: A food producer can keep its production line running without interruption, even as cyberattacks on corporate systems increase.

Yes – the CRA requires evidence of conformity that demonstrates security and compliance. Leuze confirms compliance with the CRA requirements in the respective product-specific EU Declaration of Conformity (CE Declaration).

Example: A manufacturer of robotic systems can provide its customers with official documentation proving that all safety standards have been met.

Products newly placed on the market must meet the requirements. 

Products that are in use or in the customer’s inventory prior to the CRA’s entry into force do not need to be retroactively modified. The same applies to replacement parts that do not involve any technical changes. 

Example: Existing systems can be made CRA-compliant through updates and additional security checks without halting production.

Leuze supports customers in the practical implementation of CRA requirements – so you can achieve compliance on time without compromising production.

Contact us directly

CRA-3_700x500px
CRA-7_700x500px

Side note: The cybersecurity challenges of industrial automation

Why industrial networks are particularly vulnerable

Industrial networks combine older systems with modern digital systems. The long service life of machinery and control systems means that security vulnerabilities can persist for years. At the same time, connectivity within the production environment is increasing, which broadens the attack surface. Without targeted security measures, even minor vulnerabilities can lead to significant production downtime or data loss.

OT security protects your production

Operational Technology (OT) controls critical production processes. Attacks on OT systems have a direct impact on machinery and production lines and can cause significant economic damages. Targeted security strategies protect OT systems, ensuring that systems run reliably and downtimes are minimized, all while maintaining the security of sensitive operational data.

Sensors and actuators designed for security

Modern production systems rely on networked sensors and actuators. These devices must operate with precision while remaining secure against attacks. Manufacturers face the challenge of developing devices that can receive updates and process data securely, while remaining reliable and high-performing. Otherwise, insecure sensors can become gateways for cyberattacks.

Updates and patch management are essential

Software and firmware updates close security gaps and protect production systems in the long term. A structured patch management system ensures that updates are carried out promptly and reliably without disrupting ongoing operations. This keeps systems secure without compromising production output.

IT and OT must work together

The increasing integration of IT and OT systems boosts efficiency, enhances transparency and enables new digital services. At the same time, complexity is on the rise, and with it the potential attack surface. A holistic security approach ensures that IT and OT measures are coordinated, risks are identified at an early stage, and security measures complement one another – for reliable and secure production.


Your partner for secure sensor solutions

Cybersecurity is a shared journey.

Leuze supports you every step of the way with accountability, foresight and a clear focus on your needs. Our aim is to provide you with comprehensive guidance – clear, reliable and practical.