Siemens is introducing a new hardware generation for its Sinumerik One CNC control system. With significantly enhanced computing performance, modern graphics architecture, and a platform designed for long-term cybersecurity, the hardware addresses key technological and regulatory requirements across the manufacturing industry.
At the same time, the new architecture lays the foundation for the use of artificial intelligence in machine tools. Customers benefit from increased productivity through data-driven optimization of machining processes and improved use of machine data.
The Cyber Resilience Act as a regulatory framework
As connectivity increases and the use of data continues to grow, the security requirements for industrial systems are becoming more demanding. The EU Cyber Resilience Act establishes regulatory requirements that particularly address long-term updateability and product security.
The entire Sinumerik portfolio is aligned with the requirements of the EU Cyber Resilience Act and is therefore CRA-ready. The Sinumerik One hardware generation allows machine builders and operators to design their machines in accordance with regulatory requirements.
How does the EU Cyber Resilience Act (CRA) affect UK companies?
The EU Cyber Resilience Act (CRA) is a landmark regulation that introduces mandatory, EU-wide cybersecurity requirements for all products with digital elements (PDEs) sold on the European market. Enacted as Regulation (EU) 2024/2847, it covers both hardware and software - shifting the legal responsibility for cybersecurity away from consumers and onto manufacturers, importers, and distributors.
CRA applies to UK manufacturers if they sell hardware or software into the EU market, regardless of Brexit. However, for products sold strictly within the UK, products are governed by the Product Security and Telecommunications Infrastructure (PSTI) Act. This law targets consumer connectable products, banning default passwords and requiring clear vulnerability disclosure windows.
Therefore, UK manufacturers targeting both British and European consumers must now navigate two separate product security frameworks. The primary difference between the two laws is that the UK PSTI Act serves as a "security floor" for consumer internet-of-things (IoT) devices, while the EU CRA is a highly strict, comprehensive framework covering almost all digital hardware and software.
More information
This content was created in paid collaboration with the Newsletter Editors Andy Pye and Bob Dobson.