What PROFINET Brings to the Table: the EU Cyber Resilience Act

  • Post category:PI NEWS
  • Reading time:2 mins read

Industrial automation is entering a new regulatory era. Starting December 11, 2027, the EU Cyber Resilience Act (CRA) will require manufacturers of “products with digital elements” to build in cybersecurity from the ground up. Reporting obligations kick in even earlier, namely this month (September 2026). For anyone building or deploying PROFINET-enabled devices, the question is obvious:

How much of this does the protocol already handle, and how much is still on the manufacturer’s plate?

PI has recently published a Whitepaper answering exactly that.

Management Summary

The new white paper addresses product manufacturers, distributors, and integrators. It summarizes how PROFINET can contribute to EU CRA compliance of products that implement the technology. It identifies the technological options provided by the PROFINET specification, including features introduced in the latest version, PROFINET specification V2.5.

PROFINET provides a basis for EU CRA compliance. Since the EU CRA targets products, not protocols, a standard (like PROFINET) cannot provide “automatic compliance” of the EU CRA for any product. Measures beyond the PROFINET specification are required for EU CRA compliance.

Compliance must be assessed individually for each product by the manufacturer. Furthermore, EU CRA compliance does not automatically imply the need for implementing specific protocol features. In all cases, a product-specific cybersecurity risk assessment must be done to determine technical elements required for EU CRA compliance.

Introduction

The EU CRA is a regulation about products with digital elements. It specifies cybersecurity-related requirements for placing on the market products it applies to. It comes into full effect on December 11, 2027. Cybersecurity regulations in general, and the EU CRA in particular, affect the development of products that implement PROFINET. The EU CRA defines two classes of essential cybersecurity requirements, namely:

  1. requirements relating to product properties (EU CRA, Annex I, Part I) and
  2. requirements relating to vulnerability handling (EU CRA, Annex I, Part II).

In either case, the CRA does not explain how to technically fulfill these requirements.

The new Whitepaper aims to support product manufacturers, distributors, and integrators in making informed decisions about the selection of security features for PROFINET products. It focuses on features specified in the PROFINET standard and reflects PI’s knowledge and understanding as of August 2026. It will be updated once further official guidance and interpretations are available.

Read the Whitepaper Here