
Cyber Resilience Act: What It Means for Encoders
Cybersecurity has become a critical consideration in industrial automation. As factories become increasingly connected through Industrial Ethernet, Industrial IoT, and remote diagnostics, the security of every connected component matters—not just PLCs and industrial PCs, but also sensors and other automation devices.
To strengthen the cybersecurity of connected products, the European Union introduced the Cyber Resilience Act (CRA). The regulation establishes mandatory cybersecurity requirements for products with digital elements sold within the EU and represents one of the most significant changes to industrial product development in recent years.
For machine builders, system integrators, and equipment manufacturers, understanding these new requirements is becoming increasingly important.
What Is the Cyber Resilience Act?
The Cyber Resilience Act is an EU regulation designed to improve the cybersecurity of digital products throughout their lifecycle.
Manufacturers will be expected to design products with cybersecurity in mind, manage vulnerabilities responsibly, provide security updates where applicable, and maintain appropriate technical documentation.
The regulation entered into force in 2024. Vulnerability reporting obligations begin in September 2026, while the main cybersecurity requirements become mandatory in December 2027.
Why Does This Matter for Rotary Encoders, Inclinometers and Linear Sensors?
Not every sensor is affected in exactly the same way. As automation systems become more connected and software-driven, however, rotary encoders, inclinometers, and linear sensors can form part of the wider digital architecture of a machine.
Depending on their functionality and communication capabilities, these devices may exchange data with controllers, PLCs, and other automation components. Cybersecurity therefore needs to be considered alongside the technical and functional requirements of the sensor.
What Does This Mean for Machine Builders?
For OEMs and machine builders, cybersecurity is becoming another important specification alongside accuracy, interface compatibility, and environmental protection.
The CRA distinguishes between different categories of products with digital elements based on their cybersecurity relevance and potential risk: non-classified or standard products, important products Class I, important products Class II, and critical products. The applicable category determines, among other things, how conformity with the CRA requirements needs to be demonstrated.
For machine builders, CRA compliance will increasingly become part of selecting and integrating automation components. Manufacturers will need to ensure that the products used in their machines meet the applicable cybersecurity and documentation requirements for their respective category.
How POSITAL Is Responding
Our engineering teams are actively preparing our complete product portfolio, including rotary encoders, inclinometers, and linear sensors, to align with the evolving requirements of the European Cyber Resilience Act.
Our preparations include strengthening cybersecurity throughout the product development lifecycle, improving technical documentation, and implementing structured vulnerability management procedures.
Our objective is clear: to strengthen cybersecurity across our position sensors without compromising the performance, flexibility, and reliability customers expect from POSITAL. We aim to meet tomorrow’s cybersecurity requirements while maintaining the product capabilities our customers rely on today.


