Security and Regulations

Regulations, cybersecurity, and innovation:

ASEM's response to the new industrial challenges.


The evolving European regulatory landscape is redefining cybersecurity requirements for industrial products, machines, and plants. To address this transformation, ASEM is strengthening its processes, expertise, and technologies in line with international standards, with the goal of providing customers and partners with increasingly secure, reliable, and compliant solutions.


Security and Regulations


Machinery Regulation 2023/1230: When Digital Meets Safety

How can cyber risks in machine safety functions be assessed in a practical way? 

Join our webinar to explore real-world industrial examples and gain insight into the new requirements introduced by Machinery Regulation 2023/1230, their relationship with IEC 62443 and prEN 50742, and the steps needed to turn regulatory requirements into actionable practices. Discover how ASEM can support your compliance journey and help you navigate the evolving landscape of industrial cybersecurity. 


When? il 07-10-2026, 10:00 - 11:00 + Q&A


Register now 

and learn directly from our technical experts how to prepare for the new cybersecurity-driven regulatory framework.

Directive (EU) 2022/2555

Concerns corporate cyber security risk management.

Target audience

Essential and important entities, both public and private.

It aims to improve cybersecurity within organizations by imposing stricter requirements for the protection of corporate networks and business data. 

The National Cybersecurity Agency's dedicated NIS portal provides the official documentation:

Entry into force: In Italy, Legislative Decree No. 138/2024 has been in force since 16 October 2024 .

Deadline for implementing security measures: 31 October 2026 .

End users must be provided with assurance that all four key areas have been addressed: 


  • Supply Chain Security and Secure Software Development 
  • Risk Management and Technical Measures (Access Control and Encryption) 
  • Incident and Vulnerability Management
  • Auditing, Monitoring, and Business Continuity 

​


ASEM provides a dedicated tool for machine builders and system integrators to generate a mitigation report covering these four areas.

Regulation (EU) 2023/1230

Concerns cybersecurity within the physical safety of machinery.

Target audience

Manufacturers, importers, and distributors of machinery, related products, and partly completed machinery placed on the EU market.

The new Machinery Regulation (EU) 2023/1230 , also known as the Machinery Regulation (MR) , replaces the previous Machinery Directive and applies to machinery placed on the market or put into service from 20 January 2027 . It introduces explicit cybersecurity requirements for connected machines. Reason: a cyberattack can create a physical safety risk. 

NOTE: This regulation has a direct impact on machine safety and on the CE marking process.

Entry into force: 20 January 2027

  • Structured roadmap towards alignment with IEC 62443-4-2 Security Level 2 (SL2) for its products, initiated in January 2026. 
  • Enhancement of Authentication, Auditing, and Documentation capabilities to support RESS 1.1.9 and RESS 1.2.1 requirements. 
  • Guideline/Checklist for implementing ASEM products in a manner consistent with the requirements of the new regulations (currently in preparation). 

Cybersecurity becomes part of the technical file. ASEM provides components designed to support the machine CE marking process.

Regulation (EU) 2024/2847

Concerns the cybersecurity of digital products.

Target audience

Manufacturers, importers, and distributors of hardware and software with a direct or indirect connection to devices or networks.

The Cyber Resilience Act (CRA) is a European regulation that: 

  • Introduces mandatory cybersecurity requirements. 
  • Applies to hardware and software with digital elements. 
  • Is a prerequisite for obtaining and maintaining CE marking. 


The CRA requires manufacturers to: 

  • Develop products according to a Secure Development Lifecycle (SDL).
  • Manage security updates for at least 5 years after the product is placed on the market. 
  • Ensure software integrity. 
  • Ensure secure software updates. 
  • Protect products against unauthorized access.
  • Provide security-related information (e.g., SBOM - Software Bill of Materials ).


 The CRA is therefore both a product regulation and a process regulation . Security becomes a continuous obligation, not a one-time compliance check.

Mandatory reporting of exploited vulnerabilities and/or incidents: 11 September 2026. 

Entry into force: 11 December 2027.

  • Designs hardware and software according to secure-by-design principles. 
  • Applies the Rockwell Secure Development Lifecycle (IEC 62443-4-1) to ASEM products relevant to the CRA. 
  • Integrates secure update mechanisms, software integrity protection, vulnerability management, and SBOM (Software Bill of Materials). 


ASEM provides products designed to support customers in achieving CRA compliance. Cybersecurity becomes a product requirement, and ASEM provides the right building blocks to address it.

Radio Equipment Directive (RED) – Cyber Security (Art. 3.3)

Concerns the cybersecurity of internet-connected radio equipment.

Target audience

Manufacturers, importers, and distributors of radio equipment incorporating Wi‑Fi, cellular, or other radio communication technologies and placed on the EU market.

The Radio Equipment Directive (RED) harmonized standards have been updated to include cybersecurity requirements for categories and classes of internet-connected radio equipment . With the entry into force of the RED Cybersecurity requirements (Article 3.3) , all products incorporating Wi-Fi or Cellular connectivity must comply with the new security requirements in order to obtain and maintain CE marking.

Entry into force: 1 August 2025

ASEM has carried out a comprehensive assessment of products equipped with radio interfaces (Wi-Fi/Cellular) to define the appropriate RED Cyber Security compliance path , identifying which devices should be certified and which should be phased out in anticipation of the new CE requirements.

Personal area

Login to your personal area to download your restricted contents. If you don’t have am ASEM account yet, register here.

Contact us