Made in Germany. Supporting the World. Built for the Future.

Written by Michael Zillgith

21. August 2026

In an era of global supply chain volatility, the locations of key product-development activities, support, and compliance functions can be an important consideration in supply chain risk management. Choosing an EU-established partner like MZ Automation, based in Germany, does not, by itself, guarantee compliance. However, working with a supplier that operates directly within the EU regulatory environment may offer advantages through its familiarity with European cybersecurity, product, and data requirements. Many EU regulations also apply to non-EU companies that place relevant products or services on the EU market. The decisive factors are therefore not simply where a supplier is headquartered, but whether it maintains the necessary technical, organizational, and contractual processes to satisfy the applicable supply chain requirements.

This article aims to describe several current and forthcoming European Union regulations relevant to industrial automation customers, particularly in the areas of cybersecurity, artificial intelligence, and data security.

The Cyber Resilience Act

The Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements intended to improve the security of hardware and software products with digital elements made available on the EU market. Although the Act covers a wide range of products, its scope is not limited to software embedded in physical devices. It can also cover standalone software and hardware, or software components made available separately on the EU market. The most relevant changes this creates for the industrial automation industry include mandatory requirements for manufacturers that cover the planning, design, development, and maintenance of products, as well as vulnerability handling throughout all stages of the product lifecycle.

The key obligations of the CRA can be sorted into two primary groups:

  1. Cybersecurity requirements that covered products must satisfy, and
  2. Effective vulnerability management.

Examples of the former include secure configuration in the design of the product, as well as no known exploitable vulnerabilities; whereas the latter includes security updates, maintaining software bill of materials, and reporting known vulnerabilities and incidents.

All EU manufacturers should be currently implementing the changes necessary to fulfill the requirements of the CRA, will begin reporting on CRA implementation by December 2026, and are expected to be fully compliant by December 2027.

The AI Act

The AI Act is the first comprehensive AI law in the world. It was first proposed by the European Parliament with the intent to ensure that current and future AI systems are safe, transparent, traceable, non-discriminatory, and environmentally friendly, as well as establishing a uniform definition for AI and AI risks that protect users from potentially harmful systems.

The AI Act has established different obligations for providers and users of AI systems depending on the level of risk, ranging from unacceptable and high-risk systems to minimal risk. Even though most AI systems fall under the latter category, they are still subject to transparency requirements under the AI Act, including disclosing the use of AI in generated content, preventing the generation of illegal content when designing the model, as well as publishing the copyrighted data used for system training. These obligations apply to providers, deployers, importers, distributors, and product manufacturers of AI systems operating in or connected to the EU market.

The AI Act follows a phased implementation schedule. Prohibited AI practices and AI-literacy obligations began applying on 2 February 2025, while governance rules and obligations for general-purpose AI models began applying on 2 August 2025. The Act became generally applicable on 2 August 2026, but important requirements for high-risk AI systems will apply later. Requirements for certain high-risk use cases will apply from 2 December 2027, while requirements for high-risk AI embedded in regulated physical products will apply from 2 August 2028.

The Data Act

One of the most recent acts particular to data protection proposed and applied in the EU is the Data Act. The Data Act aims to increase users’ control over their data by establishing clear legal rules regarding who may access and use certain data and under which conditions, reducing contractual abuse in data sharing, authorizing public bodies access to data held by private organizations for specific public interest purposes, enabling customer ease in switching cloud providers, and ensuring the balance between data holder’s and user’s interests. The Data Act was first entered into force in January 2024 and has since been applied across the European Union since 12 September 2025.

The measures this act takes to increase users’ control include giving owners, renters, and lessees of connected products rights to access and use certain raw and pre-processed data generated through their use of those products and related services.

These rights are subject to important limitations and safeguards, including rules concerning personal data, trade secrets, product security, and the development of competing connected products. The Data Act does not provide an unrestricted right to access all information held by a manufacturer or service provider.

In addition, the act introduces requirements intended to facilitate switching between cloud and other data-processing services. It may also enable businesses to use data generated by industrial and agricultural equipment to improve maintenance and operational efficiency. Furthermore, it protects businesses, particularly smaller businesses, against certain unfair contractual terms concerning data access and use that are unilaterally imposed by a stronger contractual party.

Although these are just a handful of regulations that affect industrial products, software, and digital services offered within the EU, they provide a conceptual overview of the increasing technical, organizational, and documentation requirements faced by suppliers serving the European market.

These requirements are not limited exclusively to European companies. Depending on the legislation concerned, they can also apply to non-EU manufacturers and providers placing products or services on the EU market. For customers, the relevant value comes not from a supplier’s location alone, but from its product-security practices, technical expertise, transparency, and ability to support applicable compliance obligations.

As an EU-established industrial software supplier, MZ Automation continuously reviews its products and organizational processes in light of this evolving regulatory environment while supporting customers and projects worldwide.

Below is a real-life example of an international client who greatly benefited from MZ Automation’s services as a solution provider in the industrial automation industry operating from the EU.

Selected References

MZ Automation partnered with a Fortune Global 100 industrial technology company to integrate an IEC 61850 Client in RD55UP06-V/RD55UP12-V, develop a IEC 61850 Configuration Tool with integrated COMTRADE file management capabilities, and strengthen post‑fault analysis, diagnostics, and grid event transparency. The initiative focused on delivering a seamless, user‑friendly, and scalable solution that enabled reliable retrieval and management of COMTRADE disturbance records directly from the function module.

MZ Automation led the end‑to‑end design and implementation, including the definition of a robust file transfer protocol, development of a dedicated file transfer client, and enhancement of embedded functionalities to selectively retrieve COMTRADE files and monitor SD card memory usage. To ensure operational transparency and ease of use, the existing web interface was extended with a dedicated COMTRADE status view, complemented by enhanced logging for improved traceability and support.

In parallel, MZ Automation evolved the configuration file format and extended the existing configuration tool to fully support the new COMTRADE workflows. The resulting solution enabled customers to efficiently access critical fault data, reduce operational complexity, and accelerate troubleshooting and compliance processes—delivering tangible value for large‑scale, mission‑critical IEC 61850 deployments.

Interested in partnering with us? Contact us to learn more.

You May also Like…

IEC61850Browser: IEC 61850 in the Field

When commissioning protection and control systems, quick checks are often essential: Is the IED reachable through the substation network? Are process values being transferred correctly? What state and quality information does a data point report? Is a control command accepted or rejected by the device?

A notebook, engineering software, and various diagnostic tools are often available for these tasks. In practical work, however, there is often no compact tool that is immediately available at the panel, at the test setup or during troubleshooting.

This need led to IEC61850Browser. The native app for iPhone and iPad provides mobile access to IEC 61850-capable IEDs and brings together key diagnostic, testing, and analysis tasks in a clear interface designed for field use.

Company

About us

What we do

Links

Products

Privacy Policy

Legal Information

FAQ

Contact

Merzhauser Str. 76A, 79100 Freiburg

info@mz-automation.de

+49 7681 – 20 91 980

Follow Us