- 07/22/2026
- Article
- Machinery Change
From Nice-to-Have to Mandatory: Cybersecurity in Packaging Machine Manufacturing
Networked packaging machines increase efficiency and transparency, but they also create new attack surfaces. With the Cyber Resilience Act, cybersecurity becomes a binding requirement for machine manufacturers across the entire product lifecycle. Which obligations arise from this, and why cyber resilience is increasingly determining competitiveness and purchasing decisions.
Written by Alexander Stark

Flexible, powerful, efficient and easy to operate at the same time: the requirements placed on modern packaging machines are anything but simple to meet. Mechanics and automation features alone are no longer enough. Only intelligent controls and connectivity turn them into the powerhouses that machine manufacturers bring to market today.
Software, digital interfaces, remote maintenance access, and networked controls and line components have now made these machines part of a complex IT and OT system. This connectivity brings real added value: more transparent processes, seamless traceability, data-driven production optimisation, predictive maintenance and faster service response. But this very strength becomes a weakness: the more closely machines, corporate networks and external service providers are connected, the greater the attack surface for cyberattacks. The desired data exchange is thus in direct tension with security aspects. "A cyberattack can not only lead to production downtime and significant financial damage, but can also jeopardise product safety or compromise sensitive data," emphasises Christian Meyer, Senior Solution Architect – Cybersecurity at Siemens.
Cybersecurity From The Design Phase To End Of Support
The regulatory pressure to act is also increasing noticeably: NIS2 focuses on the security of companies, the Cyber Resilience Act (CRA) addresses the cybersecurity of networked products and their manufacturers or importers, and the European Machinery Regulation is increasingly linking safety – the protection of people and the environment from hazards posed by the machine – with security, i.e. the protection of the machine against targeted cyberattacks.

Meyer sees the Cyber Resilience Act as a decisive driver bringing cybersecurity to the forefront of attention for packaging machine manufacturers. This EU regulation, which will apply in full from 11 December 2027, obliges manufacturers of products with digital elements to meet high cybersecurity standards. "The CRA will fundamentally change the cybersecurity requirements for packaging machines. It affects packaging machines to a large extent and turns cybersecurity from a 'nice-to-have' into a 'must-have'," says Meyer. Siemens sees this as an opportunity to strengthen the resilience of the entire industry.
The CRA requires that products with digital elements be designed to be cybersecure from the design phase onwards ("security by design") and remain cybersecure throughout their entire lifecycle. "This means a manufacturer must not only ensure that their packaging machine is cybersecure at the time it is placed on the market. They are also obliged to provide security updates free of charge during the support period they define for their machine," explains the expert.
Who Is Affected – And Who Is Liable?
All packaging machines with digital interfaces or embedded software are covered by the CRA. This includes controllers (PLCs), HMI systems, industrial PCs, as well as networked sensors and actuators, and the entire communications infrastructure. "Components that are placed on the market as standalone products with digital elements are also covered by the CRA," Meyer adds.
The CRA distributes responsibilities differently. Manufacturers must ensure their machines or components are CRA-compliant both at the time they are placed on the market and throughout the support period. Importers and distributors, meanwhile, are subject to verification, documentation and information obligations regarding product conformity.
Automation partners and component suppliers such as Siemens are not direct addressees of the EU regulation, but their role in providing cybersecure products and information is nonetheless crucial for manufacturers, as Meyer points out. After all, the integrator remains responsible for the product it manufactures, including any third-party components it contains.
Operators fall outside the scope of the CRA. However, they remain responsible for the safe operation of the entire plant within their specific environment. "This includes assessing risks for their operating environment, promptly installing security updates provided by manufacturers, and protecting their own IT and OT infrastructure," says Meyer.
CRA: A Marathon, Not A Sprint – What Needs To Happen Now
Although the CRA will not take full effect until December 2027, preparing for it should not be underestimated. "Packaging machine manufacturers should carry out a stocktake of their products without delay and assess which ones fall under the CRA," Meyer advises, adding: "A risk analysis is essential to identify potential vulnerabilities." It is also crucial, according to Meyer, to embed "security by design" principles into the development process and to establish processes for vulnerability management and the provision of security updates.
Users, for their part, should align their own operating processes with cybersecurity requirements, for example through regular staff training, says the Senior Solution Architect. Further important measures include:
- Network segmentation: separates critical production areas from less sensitive networks and prevents attacks from spreading
- Firewalls and anomaly detection systems: block unauthorised access and detect suspicious activity
- Secure authentication and authorisation mechanisms: ensure that only authorised personnel can access the machines
- Encryption of communication data: protects against the interception of sensitive information
- Regular security updates and patches for all software components close known vulnerabilities
Cybersecurity Becomes A Competitive Factor
Against the backdrop of the CRA, cybersecurity is shifting from a pure compliance requirement to a decisive competitive factor in packaging machine manufacturing. "Customers, particularly large corporations, will increasingly favour machines that demonstrably meet high security standards," Meyer is convinced.
Robust cybersecurity extends far beyond protection against attacks. When downtime caused by cyber incidents is minimised, plant availability increases as a result. Manufacturers, in turn, can build trust and strengthen their reputation through convincing security measures. "Much like energy efficiency or serviceability, a machine's cyber resilience is becoming a quality benchmark that significantly influences purchasing decisions," says Meyer, adding: "Manufacturers that invest in cybersecurity early on and communicate this transparently will secure a clear advantage in the market."
