Page 1 of 1

EU Cyber Resilience Act

Posted: 14 Apr 2025, 22:47
by Robbie_B
With the EU's new Cyber Resilience Act phasing in, is there any guidance regarding how this legislation will affect PROFINET devices? For example, will it become mandatory that all data is encrypted in transit, etc? Is there any official guidance from PROFIBUS and PROFINET International regarding how manufacturers of devices prepare to comply with the CRA?

Re: EU Cyber Resilience Act

Posted: 04 Feb 2026, 17:31
by XSPN
Robbie_B wrote: 14 Apr 2025, 22:47 With the EU's new Cyber Resilience Act phasing in, is there any guidance regarding how this legislation will affect PROFINET devices? For example, will it become mandatory that all data is encrypted in transit, etc? Is there any official guidance from PROFIBUS and PROFINET International regarding how manufacturers of devices prepare to comply with the CRA?
PROFIBUS & PROFINET International (PI) has published official guidance on this topic. According to their latest press release, PROFINET already provides the foundational technical mechanisms required for CRA compliance, and manufacturers can extend existing devices step‑by‑step with additional security features depending on their risk assessment (e.g., Secure Cell, Secure Access, Secure Realtime). Full encryption of all traffic is not mandated by default but depends on the assessed security level and use case.
You can find the official PI statement here: https://www.profibus.com/newsroom/press ... compliance

Re: EU Cyber Resilience Act

Posted: 10 Feb 2026, 10:31
by paaaz
XSPN wrote: 04 Feb 2026, 17:31
Robbie_B wrote: 14 Apr 2025, 22:47 With the EU's new Cyber Resilience Act phasing in, is there any guidance regarding how this legislation will affect PROFINET devices? For example, will it become mandatory that all data is encrypted in transit, etc? Is there any official guidance from PROFIBUS and PROFINET International regarding how manufacturers of devices prepare to comply with the CRA?
PROFIBUS & PROFINET International (PI) has published official guidance on this topic. According to their latest press release, PROFINET already provides the foundational technical mechanisms required for CRA compliance, and manufacturers can extend existing devices step‑by‑step with additional security features depending on their risk assessment (e.g., Secure Cell, Secure Access, Secure Realtime). Full encryption of all traffic is not mandated by default but depends on the assessed security level and use case.
You can find the official PI statement here: https://www.profibus.com/newsroom/press ... compliance
The link parsing unfortunately does not work correctly. "-n e w s" gets alway replaced by "-The"
Short URL https://tinyurl.com/mrx2dk4n

And PNO, please upload a PDF instead of a .docx .... :lol: