OIML BULLETIN - 2026 - VOLUME LXVII - NUMBER 3
f o c u s p a p e r
Meaning of the EU cybersecurity legislation for measuring instruments
Luis Cachóni , Hilmar Brunnii
and Michele Gobbi
Mettler-Toledo International Inc.
i. President of CECIP
ii. Member of the CENELEC Working Group on Cybersecurity under TC 65X/WG 03 and CEN CENELEC JTC 13/WG 9
Citation: L. Cachón, H. Brunn and M. Gobbi, 2026 OIML Bulletin LXVII(3) 20260307
1. Digital security vs physical safety
Manufacturers of measuring instruments subject to legal metrology have traditionally understood product conformity in physical hazards at the time of placing on the market: preventing malfunction, avoiding injury, and ensuring that measuring instruments perform within prescribed tolerances. That understanding remains essential. However, the increasing digitalization of measuring systems has fundamentally changed the risk landscape. In connected environments, cybersecurity is no longer an auxiliary IT concern; it is a direct precondition for product safety, measurement integrity, and public trust.
For manufacturers of measuring instruments and for policy makers responsible for regulatory oversight, this shift is not merely technical. It is legal, operational, and societal. When a device can be accessed remotely, manipulated through software, or impersonated within a network, the risks extend beyond data loss. They can affect the safety of persons and property, distort commercial transactions, and undermine confidence in regulated measurements.
2. The invisible threat: cybersecurity as product safety
The central argument is straightforward: in modern metrology, digital compromise can produce physical consequences. A measuring instrument that is hacked, tampered with, or subtly manipulated may continue to appear functional while delivering incorrect outputs. Unlike an overt mechanical failure, this type of compromise is often invisible to the user and difficult to detect through ordinary operation.
This invisibility is precisely what makes cybersecurity a product safety issue. Based on the CIA triad – a core security model founded on Confidentiality, Integrity, and Availability used to guide information security policies and protect data across organizations – a secure device is not only one that resists unauthorized access to its software or data impacting its confidentiality; it is one that preserves the integrity of the measurement process itself. If the measurement result cannot be trusted, then neither can the downstream decisions based on it. Moreover, the availability of the device can also be impacted through a cyberattack, preventing the device from functioning at all.
2.1 The physical impact
Direct danger
Instruments used in industrial, medical, environmental, or commercial contexts may directly influence physical processes. If hacked sensors or manipulated control systems produce false readings, the consequences can include equipment damage, unsafe operating conditions, and personal injury. In such cases, cyber compromise becomes a pathway to tangible physical harm.
This is especially relevant where measurements trigger automated responses. A corrupted signal may cause a system to overheat, overfill, misdose, misroute, or otherwise behave unsafely. The safety function of the instrument is therefore inseparable from the integrity of its digital components.
Societal instability
Beyond immediate physical harm, compromised devices can damage market integrity and fair trade. Legal metrology exists to ensure confidence in measurements used in commerce, healthcare, regulation, and public administration. If attackers can alter readings, imitate legitimate instruments, or inject false data into measurement chains, then the foundation of equitable trade is weakened.
The broader societal implication is loss of trust. When measurement results are no longer seen as reliable, both regulated markets and enforcement systems become vulnerable. Cybersecurity therefore supports not only device-level safety but also the integrity of the economic and regulatory order.
2.2 The digital shift
Connected risks
The transition from standalone instruments to networked systems has expanded the attack surface significantly. Modern measuring devices increasingly rely on IoT architecture, remote monitoring, cloud synchronization, and software update mechanisms. These features provide efficiency and flexibility, but they also create remote entry points for attackers.
A device that was once isolated can now be reached across networks, integrated into larger systems, and influenced by external services. This connectivity means that threats are no longer limited to physical access or local tampering, and potentially extend to any person having an internet connection. Remote exploitation, credential abuse, supply-chain compromise, and malicious updates are now realistic threat vectors.
Data tampering
Measurement integrity depends on the authenticity and completeness of data. Malicious software does not need to destroy a device to be effective. It can silently alter calibration data, change thresholds, distort signal processing, suppress alarms, or manipulate recorded values.
This form of tampering is particularly serious because it may remain undetected for long periods. A device may continue to operate normally from the user’s perspective while producing systematically incorrect results. In legal metrology, where traceability and reliability are critical, such silent corruption is incompatible with the principle of trustworthy measurement.
A measuring instrument should be able to prove that software, configuration data and measurement records originate from authorized sources and have not been altered. Digital signatures and cryptographic authentication mechanisms therefore become increasingly important elements of legal metrological trust.
2.3 Legal reality
Strict mandates
Regulatory frameworks are evolving to address these risks. Around the world, new and emerging legal requirements increasingly demand robust cybersecurity controls for connected products, including measuring instruments. These requirements reflect a growing recognition that safety, conformity, and digital resilience are now intertwined.
For manufacturers of measuring instruments, compliance can no longer be limited to conventional performance and accuracy criteria. Security-by-design, vulnerability management, access control, secure updates, and integrity protection are becoming essential components of conformity. For regulators, this means that cybersecurity considerations must be integrated into technical requirements, assessment procedures, and market surveillance strategies.
Equal priority
The key policy conclusion is that product safety cannot exist without strong digital defense. In a connected environment, a technically accurate device that can be altered remotely is not truly safe in the regulatory sense. Similarly, a secure platform that does not preserve the measurement function is incomplete.
Cybersecurity and product safety should therefore be treated as mutually reinforcing obligations. Security safeguards measurement integrity; measurement integrity underpins safety, fairness, and compliance. The legal framework must reflect this relationship explicitly, rather than treating cybersecurity as an optional or secondary layer.
3. EU cybersecurity: distinction between NIS2 and the EU CRA
The current European cybersecurity framework [1] is best understood as two complementary but distinct layers of obligations. The Network and Information Security Directive (NIS2) [2] addresses the cybersecurity of the organization – its internal processes, governance, and operational resilience – while the EU Cyber Resilience Act (EU CRA) [3] addresses the cybersecurity of the product itself across its lifecycle. This distinction is essential for manufacturers of measuring instruments and other products with digital elements, because compliance requires both secure corporate operations and secure products placed on the EU market.
In practical terms, NIS2 is about ensuring that the development and production environment is resilient against cyber threats. The EU CRA, by contrast, is about ensuring that the product remains secure and reliable when used at the customer site. For connected measuring instruments, both regimes may be relevant at the same time, but they regulate different risk domains.
3.1 NIS2: internal cybersecurity
NIS2 establishes a framework for internal cyber security. Its primary goal is to secure the organization’s development, production, and operational environment against cyber threats. The directive adopts an all-hazards approach and expects proportionate technical and organizational measures. In other words, controls must be suitable to the level of risk and the role of the entity in question. NIS2 entered into force in January 2023. Member states were required to transpose it into their national laws by October 2024.
The directive identifies a set of core practices that organizations should implement [4]. These include:
- Risk analysis and security policies
Organizations must systematically identify cyber risks and define policies that govern security behavior and decision-making. - Incident handling
Procedures are required for detecting, responding to, and recovering from cybersecurity incidents. - Business continuity
Critical operations must remain available, or be restored quickly, in the event of disruption. - Supply chain security
Cybersecurity must extend beyond the immediate organization to suppliers, contractors, and outsourced services. - Secure system lifecycle
Security must be integrated throughout the lifecycle of systems and services, from design to retirement. - Effectiveness assessment
Security measures must be tested and evaluated to confirm that they work as intended. - Cyber hygiene and training
Personnel must be trained, and basic security discipline must be maintained. - Cryptography and encryption
Appropriate cryptographic controls should protect confidentiality and integrity where needed. - Human resources, access control, and asset management
Sensitive functions require proper authorization, personnel controls, and inventory of assets. - Multi-factor authentication
Strong authentication is expected, especially for critical systems and privileged access.
For manufacturers of measuring instruments, NIS2 therefore concerns the resilience of the engineering, production, support, and administrative environment that creates and maintains the product. It is an organizational security framework, not a product conformity regime.
3.2 EU CRA: product security
The EU Cyber Resilience Act is fundamentally different. Its focus is product security. The objective is to ensure the secure and reliable operation of products at the customer site throughout their support lifecycle. In scope are products with digital elements, including hardware and software that rely on digital functionality. The EU CRA entered into force on 10 December 2024. The main obligations introduced by the Act will apply from 11 December 2027, with reporting obligations to apply as of 11 September 2026.
Under the EU CRA, cybersecurity must be considered across the full lifecycle of the product:
- planning,
- design,
- development,
- production,
- delivery, and
- maintenance.
This lifecycle approach means that cybersecurity cannot be added later as a patch. It must be built into the product from the outset (“Secure by Default”) and sustained after being placed on the market. The cybersecurity requirements the product shall fulfil must be identified based on the risks to which the product is exposed, considering its intended purpose and reasonably foreseeable use. Manufacturers are required to document cybersecurity risks and actively report exploited vulnerabilities and relevant incidents.
A central EU CRA obligation is post-market security support. Once a product is placed on the market, the manufacturer must ensure that vulnerabilities are handled effectively for the duration of the support period. The support period is expected to be at least 5 years in many cases, and during that period security updates must be made available free of charge to users.
The EU CRA also requires clear and understandable instructions for the use of products with digital elements. This is not merely a usability issue. For regulated products, security depends on correct configuration, appropriate deployment, and proper maintenance by the user. If instructions are incomplete or ambiguous, the product cannot be considered adequately secured in practice.
The EU Commission has published practical guidance to help manufacturers, developers, and businesses of all sizes meet their obligations under the Cyber Resilience Act [5].
The guidance addresses the questions stakeholders have been asking most, including:
- Clarifying when certain products fall within the scope of the Cyber Resilience Act, including remote data processing solutions and free and open-source software
- What constitutes a “substantial modification”
- How support periods should be understood and applied
- How to meet reporting obligations and risk assessment requirements
3.3 Key distinction in the context of legal metrology
For manufacturers of measuring instruments, the distinction can be summarized as follows:
- NIS2 = security of the organization
- EU CRA = security of the product
NIS2 addresses the internal cyber resilience of the manufacturer or operator. EU CRA addresses the product’s resilience in the field. Both are relevant to connected measuring instruments, but they operate at different regulatory levels and impose different responsibilities.
In regulated metrological applications, this distinction matters because product integrity, measurement reliability, and legal compliance depend on both secure organizational processes and secure product design. A manufacturer may have excellent internal cybersecurity under NIS2 yet still fail under EU CRA if the product cannot be maintained securely throughout its support lifecycle.
The EU Agency for Cybersecurity (ENISA) has published the Micro, Small and Medium-sized enterprises (SME) Cyber Resilience Maturity Assessment Model[6], a simple and practical guidance for SMEs to support them assess their status, identify improvements and strengthen their cyber resilience practices.
3.4 Practical illustration: long-life products
The implications become particularly significant for legacy products with long market relevance. Consider the following scenario:
If a 15+ year old product with digital elements is placed on the EU market on 12 December 2027, i.e. day after the enforcement of the EU CRA, the manufacturer may generate a support obligation until 11 December 2032, assuming the applicable support period is five years.
This creates a substantial compliance burden for products built on obsolete or unsupported platforms. For example, if the underlying operating system can no longer be secured, the manufacturer may be unable to remediate vulnerabilities effectively. In such cases, the manufacturer could face the need to provide a replacement solution, potentially at no cost to the user, depending on the legal and contractual circumstances.
A common example would be a device based on a legacy platform. If a serious vulnerability emerges in the underlying operating system and no effective security fix is available, continued market support may become problematic. The EU CRA logic is clear: if the manufacturer keeps the product available on the market, it must remain secure for the support period.
This consideration is reinforced by the rapid development of AI-enabled vulnerability discovery and exploitation techniques. These developments may increase the speed at which serious vulnerabilities are identified and weaponized, particularly in legacy platforms that are no longer actively maintained [7]. Manufacturers should therefore take this evolving threat environment into account when assessing whether such devices can be supported securely throughout the required support period.
4 The bar is raised: Modern product compliance across the entire lifecycle
One of the most important regulatory developments in Europe in recent years is the shift from static product conformity to lifecycle-based product compliance. In the traditional model, conformity was assessed primarily at the moment the product was placed on the market. In the modern model, especially where cybersecurity, software, connectivity, and machinery safety are involved, compliance obligations extend throughout the product’s operational life.
This is not marginal legal refinement. It is a fundamental change in the allocation of responsibility between manufacturers, supply chain, and users. It also changes the role of software from a secondary technical component to a central compliance factor.
4.1 “Classic” product compliance
The “classic” compliance model applies to product domains such as safety and legal metrology in their traditional form. Under this model, the decisive question is whether the product is conforming at the time of placing on the market.
Core characteristics
- Conformity at time of placing on the market
The manufacturer must ensure that the product meets the applicable requirements when it is first made available on the market. - No assumed lifecycle responsibility for the installed base
Once the product is in the field, the manufacturer generally does not carry open-ended responsibility for every subsequent change in the installed base, unless specific legal obligations apply. - Software as a subordinate element
Software may matter where it affects metrology or safety, but in the classic model it is often treated as one component among many rather than the dominant compliance driver. - Reporting obligations
Where non-conformities are identified, the manufacturer must notify users and, where required, the competent authorities. - Low urgency for response times
The legal framework usually does not impose highly compressed correction deadlines comparable to those seen in cybersecurity regimes. - User responsibility for reverification
In legal metrology, the user of the measuring instrument bears responsibility for periodic reverification and maintenance of measurement integrity. Typical reverification cycles may be 1–3 years, with associated costs that can be significant on a per-unit basis.
This model reflects a product world in which the compliance problem is primarily linked to design and initial conformity, not continuous digital exposure.
4.2 “Modern” product compliance
The modern compliance model applicable in areas such as cybersecurity implies that product conformity must be maintained throughout the entire lifecycle while the product remains in operation. The regulatory expectation is no longer limited to the placement of the product on the market; it extends into use, maintenance, updates, and support.
Core characteristics
- Lifecycle conformity
The product must remain compliant not only at launch, but throughout its operational life. - Due diligence in the supply chain
Manufacturers are expected to exercise due diligence over components, software, services, and suppliers that can affect compliance. - Software as a central compliance factor
Software is no longer subordinate. It becomes a primary determinant of security, functionality, and conformity. - Cybersecurity support period free of charge
Security-relevant maintenance, including updates and vulnerability remediation, may need to be provided for a defined support period at no cost to the user. - Reporting of vulnerabilities and incidents
Manufacturers have obligations to report actively exploited vulnerabilities and relevant incidents to users and authorities. - Guaranteed response times
Regulatory frameworks increasingly expect predictable and timely correction of defects, vulnerabilities, or safety-related faults. - Impact on metrological approval
In legal metrology, software updates may trigger a need for product approval review or reverification, particularly where the update affects metrological functions or legally relevant parameters [8].
This model reflects the reality that digital products can be changed, attacked, or degraded after being placed on the market. Compliance is therefore a continuing obligation rather than a one-time event.
4.3 Why this matters for legal metrology
For legal metrology, the transition from classic to modern compliance is important because it changes when, why, and by whom product conformity needs to be maintained after market entry.
First, conformity becomes a lifecycle issue. A measuring instrument that was compliant at the time of approval may cease to be compliant after a software update, a cybersecurity incident, or the loss of support for a critical component.
Second, each software or cybersecurity change must be assessed to determine whether it is regulatory relevant, especially if it is a substantial modification under the EU CRA. A substantial modification in this context is a change to a product with digital elements after it has been placed on the market that either affects compliance with the essential cybersecurity requirements in Part I of Annex I of the EU CRA or modifies the intended purpose of the product [9]. This assessment must not be treated as a purely formal check. It is a case-by-case and risk-based assessment, especially for software updates, where the manufacturer must assess whether the update introduces new or increased cybersecurity risks and whether those risks were already covered by the cybersecurity risk assessment.
Third, post-market compliance is a shared responsibility and is becoming a more time-sensitive issue. Under the classic model, the user typically manages periodic reverification at defined intervals. Under the modern model, the manufacturer may also have to maintain security support, communicate vulnerabilities, provide updates, and correct issues under strict deadlines.
The practical takeaway is that technical maintenance and regulatory compliance can no longer be treated as separate activities. In the digital era, a software patch may be an IT measure, a cybersecurity measure, and a conformity-relevant intervention at the same time.
4.4 Summary comparison: classical vs modern compliance
|
Aspect |
Classic Product Compliance |
Modern Product Compliance |
|
Compliance basis |
At time of placing on the market |
Throughout lifecycle |
|
Manufacturer responsibility |
Primarily initial conformity |
Ongoing due diligence and support |
|
Role of software |
Secondary |
Central |
|
Reporting |
Non-conformities to users/authorities |
Also vulnerabilities/incidents to users/authorities |
|
Response times |
Generally less demanding |
Defined and often strict |
|
User responsibility |
Reverification, maintenance |
May still apply, but within a more complex compliance framework |
|
Effect of updates |
Often limited |
May trigger approval review/reverification |
5. Conclusion
For manufacturers of measuring instruments and for policy makers, the key message is clear: cybersecurity has become part of product safety and product conformity. If a measuring instrument can be altered, disrupted, or impersonated digitally, then the reliability of the measurement, the safety of downstream processes, and trust in regulated markets are at risk.
This means that modern legal metrology can no longer rely only on accurate sensors, robust mechanics, and initial conformity assessment. It also requires secure architecture, controlled connectivity, protected data flows, secure updating mechanisms, and clear responsibility for vulnerability handling throughout the product lifecycle.
The European cybersecurity framework should therefore be understood in two layers:
- NIS2 protects the organization: its internal processes, governance, operations, and resilience against cyber threats.
- The EU Cyber Resilience Act protects the product: its cybersecurity across design, development, placement on the market, support, updates, and vulnerability management.
The practical consequence is that the compliance bar has been raised. For connected and software-based measuring instruments, conformity is no longer only a snapshot at market entry. It becomes a condition that must be maintained while the product remains supported and exposed to evolving cybersecurity risks.
As a result, software maintenance, vulnerability handling, incident reporting, update governance, and the assessment of substantial modifications must be treated as compliance activities, not merely as technical support tasks. The final takeaway is simple: in modern legal metrology, trustworthy measurement requires both physical robustness and digital resilience.
References
[1] https://digital-strategy.ec.europa.eu/en/policies/cybersecurity-policies
[2] https://digital-strategy.ec.europa.eu/en/policies/nis2-directive
[3] https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
[4] https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance
[5] https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation
[6] https://www.enisa.europa.eu/news/where-do-smes-stand-in-preparing-for-the-cyber-resilience-act
[7] https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence
[8] https://www.ptb.de/cms/fileadmin/internet/fachabteilungen/abteilung_8/8.5_metrologische_informationstechnik/8.51/PTB-8.51-MB06-SWaktualisierung-EN-V04.pdf
[9] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847