Do Machinery Regulation certificates or approval decisions avoid CRA reassessment?
Not completely. Draft CRA guidance applies the Article 69(1) rule to certificates or approval decisions issued for cybersecurity-related Machinery Regulation requirements. Those certificates can remain useful evidence for the covered cyber-safety risks during the Article 69(1) period.
The manufacturer still needs the CRA cybersecurity risk assessment. If that assessment identifies additional CRA risks not covered by the machinery certificate, those gaps must be assessed and mitigated under the CRA. The draft guidance gives Machinery Regulation examples tied to protection against corruption and the safety and reliability of control systems, but it treats them as covered-risk examples, not as a blanket CRA exemption.
Article 69(1) is the legal basis for continued validity of certain certificates and approval decisions under other Union harmonisation legislation.
Section 9.3.2, points 230-232, applies Article 69(1) to Machinery Regulation cybersecurity-related health and safety requirements.