Cyber Resilience Act

Legal framework

What is the Cyber Resilience Act, and how does it affect us?

As of December 11, 2027, a clear rule will apply in the EU: Components and machines with digital elements may only be placed on the market if they can be shown to comply with the cybersecurity requirements of the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847.

This applies to mechanical engineering companies and all suppliers who provide components for the machines they manufacture. The first deadline will come sooner, since implementation will take place in phases: Starting on September 11, 2026, a requirement to report vulnerabilities and security incidents to the European Union Agency for Cybersecurity (ENISA) will take effect. It applies to all products that fall within the scope of the CRA – regardless of when they were placed on the market. Acting now will allow companies to protect not only their products, but also their ability to deliver.

STOBER integrated the CRA requirements into the development of its drive controllers and motors early on. The following sections will explain what this means in concrete terms.

Cyber-Sicherheit in industriellen Antriebssystemen
Potential hazards

What are the attack vectors against drive systems?

Cybersecurity starts with an honest analysis. Based on a TARA (Threat Analysis and Risk Assessment), STOBER has systematically investigated the pathways through which attacks on digital components in drive controllers and motors could occur – and which scenarios are particularly relevant in this context.

01

Remote attack via communication interfaces

Communication and service interfaces enable data exchange with higher-level controllers and engineering tools during operation. If these interfaces are not adequately protected, they can also be exploited for attacks, such as data theft or manipulation of process parameters.

02

Attack via the fieldbus protocol itself

If the communication protocol is not implemented in conformity with the specification, specially crafted protocol messages can be used to cause the device to enter undefined states. Therefore, the drive must be operated strictly in accordance with the PROFINET, EtherCAT, and EtherNet/IP specifications.

03

Physical access to the device

Direct physical access to the device also poses a risk – for example, through removable storage media, the operating unit, or unauthorized tampering with connections and cabling.

Requirements

What specific requirements does the CRA set?

The CRA sets forth mandatory requirements for manufacturers of products with digital elements. These are not mere recommendations, but prerequisites for market entry. The following are examples of key CRA requirements; this list is not intended to be exhaustive.

01

Availability of basic functions

Even under attack conditions, essential security-relevant functions must be maintained.

02

Limiting the attack surface

Interfaces and services that are not needed must not offer an active attack surface.

03

Minimizing the impact of an incident

A successful attack must not have uncontrolled consequences for other systems or processes.

04

Comprehensive logging of security-relevant events

Access attempts, parameter changes, and communication events must be logged in a traceable manner.

05

Secure deletion of all data

At the end of the product life cycle – or when devices are replaced – it must be possible to delete all data completely and reliably.

06

ENISA notification requirement

Known and actively exploited vulnerabilities must be reported to the EU Agency for Cybersecurity.

Security by Design

What STOBER is doing in practice

Cybersecurity is not an afterthought. The CRA requires a demonstrable “security-by-design” process, which STOBER implements.

The basis for this is the TARA (Threat Analysis and Risk Assessment): a structured method that systematically evaluates which threats are real, how likely an attack is, and what damage it could cause.

The measures derived from it are intended to meet the criteria for Security Level 2 as defined in IEC 62443-4-2.


Have you discovered a vulnerability?

Please contact our cybersecurity team directly:

csirt@stoeber.de

Our cybersecurity contact information is also stored in a machine-readable format in accordance with the international standard RFC 9116 – available at:
stoeber.de/.well-known/security.txt

Secure communication and data protection

Sensitive data is secure only if it cannot be intercepted or tampered with during transmission. STOBER therefore relies on encrypted communication, structured certificate management, and signed firmware, ensuring that only authenticated and unmodified software runs on the device.

Access control and identity management

Not every person and not every service should be able to access every parameter. Consistent user management and access rights management ensure that only authorized access is permitted, including engineering and service access.

Secure firmware updates

Updates are necessary, but they must not create security vulnerabilities themselves. Firmware updates are checked for integrity before installation, ensuring that only authorized and unmodified software is executed on the drive systems.

Comprehensive logging

Security-relevant events in the drive system are logged. This ensures the necessary traceability in the event of a disruption – a key requirement of the CRA.

Security right from the factory

When they ship, STOBER drive systems are configured in such a way that they present no unnecessary attack surface. Security is the starting point, not the result of subsequent hardening.

Documentation and support

STOBER provides mechanical engineering companies with structured security documentation and hardening recommendations as a basis for secure use of our drive systems in their respective machine applications.

A coordinated approach to addressing vulnerabilities

Security vulnerabilities can never be completely ruled out – what matters is how we deal with them. Anyone who discovers a vulnerability in a STOBER product can report it directly through our reporting portal. An internal team is responsible for coordinating the assessment, remediation, and legally required reporting to the competent EU authority ENISA.

Report a vulnerability:
csirt@stoeber.de

Our cybersecurity contact information is also stored in a machine-readable format in accordance with the international standard RFC 9116 – available at:
stoeber.de/.well-known/security.txt

Development in accordance with recognized standards

Our development processes are based on established industrial cybersecurity standards and guidelines, with the goal of meeting the criteria for Security Level 2 as defined in IEC 62443-4-2.

Building cyber security in from the outset

With ‘Security by Design’, structured processes and secure drive systems, STOBER supports machine builders in meeting the requirements of the Cyber Resilience Act.

Get in touch

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.