Six Actions to Prepare Now for the EU Cyber Resilience Act

A half-dozen expert-backed steps that could separate compliant OEMs from those facing massive penalties.

Screenshot 2026 04 28 At 12 23 34 Pm
PMMI

In today’s global marketplace, the European Union’s Cyber Resilience Act (CRA) isn’t just a European problem. For any North American OEM shipping connected machinery or products with digital elements to the EU market, the clock is already ticking and the first major deadline is closer than many realize.

That was the central message of a recent PMMI Cyber Resilience Act webinar featuring Bruce Main, Technical Director and Standards Specialist, PMMI; Juergen Kress, Managing Director / Global Business Unit Leader, Mettler Toledo Garvens GmbH; and Scott Tenorio, Principal Platform Lead at Rockwell Automation.

CRA in simple terms

The CRA establishes mandatory cybersecurity requirements for any product with digital elements sold on the EU market. CE marking, which is already familiar to most OEMs exporting to Europe, will now require demonstrated cybersecurity compliance. Non-compliance carries significant financial penalties described in Article 64 as “effective, proportionate and dissuasive.”

Don't miss Packaging Recycling Summit 2026
Where innovation meets sustainability. Join the leading forum for packaging recycling professionals, featuring cutting-edge solutions, expert insights, and the connections you need to advance the circular economy. Secure your spot today.
Discover More
Don't miss Packaging Recycling Summit 2026
Need help with your packaging project?
We’ve done the legwork to identify and vet experienced packaging and processing consultants you can contact directly for your next project. Decades of combined experience in packaging line engineering, machinery selection, package and materials development, and food processing operations.
See your advisor options now.
Need help with your packaging project?