SEW-EURODRIVE integrates cybersecurity into its products and services, as well as throughout the company and its manufacturing operations. With an ISO 27001-certified Information Security Management System, an IEC 62443-4-1-certified Product Security Management System (Security by Design), and the gradual implementation of “Security Inside” features, SEW-EURODRIVE protects its drive and automation solutions throughout their entire lifecycle.
In this way, we support our customers in the practical implementation of European Union regulatory requirements, such as the Cyber Resilience Act (CRA), the Machinery Regulation, and the Network and Information Security Directive 2 (NIS2).
The availability and security of networked drive and automation technology are becoming increasingly important.
As digitalization continues to advance across manufacturing environments, the threat landscape is expanding. That is why we are committed to helping our customers meet regulatory requirements, including the Cyber Resilience Act (CRA), the Machinery Regulation (MVO), and the NIS2 Directive. Our goal is always to reduce the risk of production downtime and prevent unauthorized manipulation within drive and automation technology environments.
Cybersecurity is systematically integrated into the development, production, and maintenance of our drive and automation solutions. The benefit for you as a machine manufacturer or operator: SEW-EURODRIVE develops its drive and automation systems step by step according to the principles of Security by Design. Vulnerabilities and potential threats are addressed through defined processes, and you are kept informed through security notices and updates (Security Advisories).
We rely on an IEC 62443-4-1-certified Secure Development Lifecycle (SDL) process, our own Cybersecurity Emergency Response Team (CERT), and clearly defined procedures for identifying, reporting, assessing, and remediating vulnerabilities. In addition, SEW-EURODRIVE is registered as a Very Important Entity under the NIS2 Directive.
Machines and digital products that fall within the scope of the Machinery Regulation (will replace the current Machinery Directive) and the new CRA will be required to demonstrate compliance with the applicable cybersecurity requirements. Only then can they meet the conditions for CE marking and be placed on the European Single Market.
This means:
SEW-EURODRIVE has signed the first CE markings in accordance with the new cybersecurity requirements of the Machine Regulation for a selection of drive technology products from the MOVI‑C® modular automation system:
Additional products will follow.
As a pioneer in drive technology, we integrate security by design into all our solutions and products and, as a highly skilled partner, we support our customers through a secure digital transformation.Dr. Hans Krattenmacher
SEW-EURODRIVE is gradually developing drive and automation systems in accordance with the principles of Security by Design – from development through production to deployment at the customer site. Risks are addressed early on, and safety measures are taken into account throughout the entire lifecycle.
New security features are being gradually integrated into products, solutions, and digital services:
Your benefit:
Our Information Security Management System (ISMS) is certified in accordance with ISO/IEC 27001 and provides the foundation for a structured approach to information security management. In addition, SEW-EURODRIVE is registered as a Very Important Entity (VIE) under the NIS2 Directive, underscoring our commitment to maintaining a high level of cybersecurity and resilience. In addition, we take into account the requirements of the EU Data Act regarding secure data access, data exchange, and interoperability mechanisms for connected products and digital services.
SEW-EURODRIVE processes personal data on behalf of its customers, including employee-related information, and implements appropriate technical and organizational measures to protect privacy rights and ensure compliance with data protection requirements.At the same time, we ensure that data is handled securely and in compliance with regulations in connected products, digital services, and IT and OT environments (GDPR and the EU Data Act).
Our Product Security Management (PSM) ensures that our products, applications, and system solutions remain protected throughout their entire lifecycle. A centralized Computer Emergency Response Team (CERT) identifies, assesses, and manages security vulnerabilities and publishes Security Advisories. Our Product Security Management System is certified in accordance with IEC 62443-4-1 and provides the foundation for implementing current requirements, such as the Radio Equipment Directive (RED).
Safety refers to all measures aimed at preventing unintentional hazards and accidents. Safety thus protects people and the environment from machines.
Security focuses on protection against malicious or criminal attacks. Security thus protects machines from people.
Product Security is the protection of products against unauthorized access, manipulation, loss, or destruction.
Yes. We continuously enhance our Product Security measures to ensure compliance with evolving cybersecurity requirements and standards.
No. Cybersecurity is becoming part of CE conformity. Under the CRA), manufacturers must demonstrate that their connected products meet defined cybersecurity requirements. Cybersecurity is thus becoming an integral part of product conformity.
Use the “Contact” link below to find your local contact person for any questions or concerns you may have.
For additional information, please see our “Data & Documents” section or the “International Regulations” section.
By activating the zip code search, data is transferred to the USA by Google. For more information, see our privacy policy.
The NIS2 Directive strengthens the cyber resilience of essential and important entities.
Among other things, companys are required to:
As of December 11, 2027, the Cyber Resilience Act (CRA) will apply to all products with digital elements placed on the EU market.
Among other things, it requires:
As of January 20, 2027, the Machinery Regulation will replace the current Machinery Directive.
A key change is that cybersecurity becomes a mandatory responsibility for manufacturers.
Among other things, manufacturers are required to:
As of August 1, 2025, additional cybersecurity requirements apply to radio equipment under the Radio Equipment Directive (RED).
Products that use radio waves and do not comply with the applicable RED requirements may no longer be placed on the market in the European Union (EU) or the European Economic Area (EEA).
Effective September 12, 2025.
The regulation strengthens the rights of users of connected products and related services while creating a harmonized framework for accessing, using, and sharing data across the European Union.
The extensive existing and upcoming EU legislation and the huge volume of requirements are causing ever greater uncertainty among plant manufacturers and operators. We've put together a list of the most common questions our customers ask us on a daily basis.
Safety refers to all measures designed to prevent the unintentional occurrence of hazards. Depending on the application, this aspect of safety is addressed by the appropriate safety technology or functional safety in our products and system solutions. Security, on the other hand, protects against malicious and criminal attacks on companies and their services.
Product security is a state in which an automation or control solution is protected against unauthorized access and against unintentional or intentional changes, losses, or destruction. Security includes protection against both digital threats (cybersecurity) and physical risks (physical security). In this context, the EU has imposed legislation (see above) that is either already binding or will become binding in the near future.
If you are a manufacturer of products, machinery, or plants that contain digital elements, are networked, exchange data with each other, or transmit radio waves, you must comply with the applicable regulatory requirements and take appropriate measures to minimize security risks for users, operators, and third parties.
The information security management system at SEW-EURODRIVE has been certified to ISO 27001 since 2006 and has been continually recertified since then to ensure it meets the latest requirements. Product security management at SEW-EURODRIVE has been successfully certified to IEC 62443-4-1 by TÜV NORD. With its various precautions and measures, our product security management helps protect our products, solutions, and services against cyber threats throughout the entire product lifecycle – from development and production through to use by our customers.
SEW-EURODRIVE uses product security measures to protect its products, solutions, and services against cyber threats. This applies throughout the entire lifecycle of our products and services. What's more, we develop these measures on a continuous basis. One important element in this context is the establishment of our international, corporate CERT, which receives, analyzes, and processes reports of vulnerabilities.
To keep you as well-informed as possible, we are offering a free webinar on cybersecurity.
Date: September 22, 2026, from 10:00 a.m. to 10:45 a.m. Here’s what you can expect: