Expertenthemenbeschreibung Cybersecurity

Cybersecurity

Trustworthiness of networked machines and systems

Photo
shutterstock

When it comes to security at the VDMA, everything revolves around protecting machines and systems in production, manufacturing or intralogistics from attacks and disruptions. The aim of these organizational and technical protective measures is to develop cyber-resilient machines and systems and trustworthy services while reliably maintaining their permanent operation.

Through this expert page, we are providing an overview of the various aspects, tasks and requirements concerning cybersecurity and industrial security. We refer to both VDMA recommendations and positions as well as concrete assistance from our members and partners.

Photo

shutterstock

Titel der Empfehlung: Cybersecurity

RecommendedTIPP
  • Supply Chain Security Document Series Guide
Shutterstock
The Industrial Security working group makes the complete Supply Chain Security document series freely available
Shutterstock

Empfehlung Cockpit Cybersecurity

Your guide through the regulatory jungleTIPP

exklusiv

  • Factsheets Cybersecurity

The VDMA Regulatory Cockpit provides clear, practical fact sheets on the most important regulations for mechanical and plant engineering, offering an at-a-glance overview. You can find out which industries are affected, what the schedule looks like, where action is needed and what sanctions can be expected. It is a valuable guide for any company looking to prepare for new requirements at an early stage.

Factsheet: Cyber Resilience Act

Factsheet: NIS-2 Directive

Podigee Player

From our content

From our content
27th HANSA Forum - Connecting Maritime Minds

The HANSA Forum is approaching. VDMA members receive a 20% discount on the regular ticket price.

From the idea to the medical device - industry meeting at HEITEC AG

Invitation to the expert meeting on medical device development in the area of conflict between the NIS2 Directive and the Cyber Resilience Act on October 22, 2025 in Eckental near Nuremberg.

Technology Stage powered by VDMA/ZVEI for SPS 2025

In 2025, the VDMA and the ZVEI are once again organizing the "Technology Stage powered by VDMA/ZVEI" forum at SPS - with exciting presentations and lively panel discussions.

Cybersecurity as the key to energy resilience

The draft of the NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) introduced by the German government will be discussed in the Bundestag tomorrow.

Personal Information Protection Regulatory Developments in China

Updated policy briefing on China’s Personal Information Protection Regulation (PIPL)

Two New Safety Standards for Machinery in Glass Technology

The VDMA Glass Technology Forum is advancing two important standards that will enhance the safety of hollow glass machinery and strengthen competitiveness across Europe.

Maritime 4.0 Conference in Hamburg

September 15 and 16, 2025, Hamburg. Discounted participation for VDMA members.

Regul8: NIS2 Directive

Did you miss the last Regul8 of the Materials Handling and Intralogistics Association? No problem, you can watch the presentation and talk on the NIS2 Directive again here.

Applied Risk management for Asset Owners and Plant Operators

Risk-based OT security: A practical guide to help plant operators and asset owners get started with risk management and threat evaluation

VDMA regulatory cockpit - exclusive for you as a member!

The VDMA regulatory cockpit provides you with a central, practical overview of current and upcoming regulations. It helps you identify relevant information at an early stage, evaluate it strategically, and derive concrete measures.

Importance of industrial security in mechanical engineering

Industrial security is increasingly important in mechanical engineering as networked systems face growing attacks. The VDMA calls for EU-wide standards and SME support to meet security needs.

Cyber resilience on the rise - but no all-clear

A new VDMA study shows: for the first time, social engineering and phishing are the biggest cyber threats to companies, followed by human error and sabotage

Digitale Lösungen im und für den Maschinen- und Anlagenbau

Erleben Sie am 08.-09. Mai 2025 in Wien spannende Vorträge und Podiumsdiskussionen zu Digitalisierungslösungen im Maschinen- und Anlagenbau.

Cyber Resilience Act (CRA)

VDMA Power Systems is highlighting the topic of cyber security and the Cyber Resilience Act in this session of the event series "With new knowledge into 2025".

ISH 2025: New possibilities for building automation with BACnet/SC

SAUTER Germany and VDMA at the ISH 2025

Cyber Resilience Act comes into force - details have been finalized

New requirements apply to products with digital components. Manufacturers must now ensure cyber security throughout the entire product life cycle - even for integrated software! An update on responsibilities and deadlines.

Industrial & product security: complex, extensive, indispensable

On November 28, 2024, VDMA Austria held its annual exchange of experience on Industrial & Product Security in mechanical and plant engineering with 40 participants at the headquarters of the TGW Logistics Group in Marchtrenk.

Mechanical engineering in Baden-WĂĽrttemberg: Resilient through crises

After the very weak economy in 2024, hopes are pinned on markets picking up in 2025 / Politicians must set business-friendly framework conditions

Cyber Resilience Act is published

The Cyber Resilience Act (CRA) was published in the Official Journal of the EU on 20.11.2024. The act is an EU Regulation that has legal effect in the European Union and the European Economic Area (EEA) without national implementation.

NIS2 contact point NRW

In order to prepare SMEs in NRW for the challenges of cyber security and to sustainably improve the IT security landscape, the state of NRW has created a NIS2 contact point that NRW companies can use.

Hannover Messe - Joint stand software and digitalization

From March 31 to April 4, 2025, the world's leading trade fair for industry will take place under the motto "Shaping the Future with Technology". VDMA Software and Digitalization members will have the opportunity to present themselves there.

Technology Stage powered by VDMA/ZVEI for SPS 2024

In 2024, the VDMA and the ZVEI are once again organizing a forum for the SPS, the "Technology Stage powered by VDMA/ZVEI" with many interesting presentations and panel discussions.

Cyber Resilience Act (CRA)

Impact on mechanical and plant engineering in conjunction with electrical automation

Security Solutions for Industry

The mechanical and plant engineering industry does not have to think about cybersecurity alone. Companies that support the manufacturing industry with services and solutions can exchange ideas and cooperate within this expert’s circle.

Cybersecurity according to IEC 62443

Take advantage of our seminar series "Cybersecurity according to IEC 62443", developed in cooperation with ISA Europe and Fraunhofer IOSB, to acquire your personal ISA certificate as an ISA/IEC 62443 Cybersecurity Expert.

VDMA FAQ on the EU Cyber Resilience Act available

Update! The Cyber Resilience Act (CRA) has been published and will enter into force on december 11th. The VDMA has compiled a FAQ document to provide support and non-binding guidance to its members.

OT-Risk Cookbook

The VDMA Industrial Security Working Group publishes the OT Risk Cookbook

Supply Chain Security document series

The Industrial Security working group makes the complete Supply Chain Security document series freely available

Cyber Resilience Act: New obligations for manufacturers - act now!

The European Union's Cyber Resilience Act affects many products and components in the mechanical engineering sector. Companies should quickly identify the extent to which they are affected and take measures to ensure compliance and product security.

Meet the Expert - Focus on digitalization

Meet the digitization experts at the VDMA Software and Digitization stand to exchange experiences.

Security.txt - mandatory exercise for supply chain security

A text file on the website for better cyber security? Manufacturers can achieve this with security.txt. A simple and essential step towards addressing vulnerabilities.

Extended protection against side channel attacks

The new safe lock standard offers enhanced protection against new attack methods.

Supply Chain Requirement Specification: Component Manufacturer

VDMA Informatik publishes the requirements specification for component manufacturers

Targeted prevention of attacks - overcoming financial resistance

VDMA Ost has set up an information technology working group. The kick-off event focused on IT security in day-to-day business. Experts raised awareness and gave tips on prevention and what to do in an emergency.

Radio equipments: cybersecurity requirements binding


As of August 1, 2025, new mandatory cybersecurity requirements apply to radio equipment when being placed on the EU internal market.

Pharmaceutical and cosmetic machines: new challenges in the future

In pharmaceutical companies, the need for fast, lean processes is increasing. In this context, digitization can help shorten market entry times, while maintaining and even improving product quality. However, players must also arm themselves against threats.

Title

Description

Now new: VDMA Cyber Awareness

How to turn your team into a human firewall!

Preparation for NIS2

These cybersecurity obligations are coming to mechanical engineering companies

Supplier self-disclosure on cybersecurity

The VDMA Supplier Self-Assessment is a standardised questionnaire that companies can use with suppliers regardless of specific procurement purposes. Highly topical with the mapping of regulatory requirements from MVO and CRA.

All information about our publication overview - compact and online

Our publications deal with various aspects of digitalization in mechanical engineering companies as well as cybersecurity and information security and serve as recommendations for action.

#HM25: Der Gemeinschaftsstand des VDMA Software und Digitalisierung

Erleben Sie die Zukunft des Maschinen- und Anlagenbaus! Besuchen Sie den Gemeinschaftsstand in Halle 15 F28 auf der Hannover Messe und entdecken Sie, wie digitale Softwarelösungen die produzierende Industrie revolutionieren!

NIS2: Mandatory cybersecurity requirements

The new version of the NIS directive will in future oblige manufacturers of "critical products" such as machines or control components to implement cybersecurity in their own operating environment.

Cybersecure procurement of machinery and equipment

The VDMA Supply Chain Security specification gives purchasers a standard-compliant aid to minimum requirements in accordance with IEC 62443, simplifying the process for both sides without sacrificing security.

China: New regulations on cross-border data transfer

Since September 1, 2022, new cybersecurity regulations have been in effect in China. VDMA's policy briefing shows the implications for the industry, especially for the transfer of personal data.

Cybercrime and the consequences

The number of hacker attacks in the mechanical and plant engineering sector is on the rise. More and more VDMA member companies are reporting attacks on office and production systems within the company. Already almost 40 percent of the attacks lead to production downtimes. How can medium-sized companies in particular arm themselves against attacks in advance or react correctly in the event of an actual attack?

Minimum recommendations for security in the supply chain

The recommendations are addressed to machine and plant manufacturers and describe a minimum of technical, organizational and procedural requirements for the implementation of security for products (such as machines, plants, digital systems for predictive maintenance & condition monitoring, ICS controls, ...) and processes.

Cybersecurity Use Cases in China

Updated guide with recommendations for data-centric business processes of European companies in China.

Security by Design reaches the machine tool

When the German Federal Office for Information Security (BSI) issues a cyber security warning of the highest alert level, industry is alarmed.

Policy Briefing Personal Information Processing (PIP) Law

On November 1, 2021, the Personal Information Processing and Protection Law (PIP Law) came into force in China. For this purpose, VDMA together with Sinolytics has prepared a policy briefing with the view of the mechanical engineering industry.

Events

Events

Thu. 16.10.25 Thu. 16.10.25

  • Industrie 4.0
  • Industrial Security

Experience how research and practice come together: The Campus provides insights into current developments, the Allianz Industrie 4.0 Baden-WĂĽrttemberg presents its new OT security study - and two medium-sized companies report openly on their experiences and solutions.

Places available

Thu. 16.10.25 Thu. 16.10.25

  • Digitalization & Industrie 4.0
  • Industrial Communication
  • Research, Innovation & Technology
  • Electrical Automation

The Customer Innovation Center™ (CIC) supports you in the development and implementation of robust, reliable and secure networks that deliver the data and insights needed for better business performance.

Places available

Tue. 04.11.25 Tue. 04.11.25

exclusive

  • Information Security

This year's Information Security Info Day will be held as a hybrid event. The central element of the event will be the practical implementation of NIS2 in mechanical and plant engineering.

Places available

SambaCommittee

Groups & Working Groups

closed group

Technical Regulations & Standardization Working Group

VDMA Working Group Cybersecurity

The Working Group Cybersecurity reports to the VDMA Technical Affairs Committee and prepares proposals for positioning the mechanical engineering industry in the field of cybersecurity. The Working G

Consultant Technical Affairs and Standardization

Markert, Alexey

conditionally open group

Digitalization & Industrie 4.0 Working Group

Information security working group

The VDMA "Information Security" working group aims to raise awareness among VDMA members and promote the exchange of experience between working group members.

conditionally open group

Digitalization & Industrie 4.0 Working Group

Industrial Security Working Group

The VDMA "Industrial Security" working group has been a VDMA committee on security in industrial production environments and industrial products since 2012 and develops guidelines and practical aids

conditionally open group

Digitalization & Industrie 4.0 Working Group

EK Security Solutions for Industry

The "Security Solutions for Industry" expert group facilitates the exchange of experience in securing mechanical and plant engineering. It is aimed at companies that support the manufacturing indu

closed group

Technical Regulations & Standardization Committee

VDMA Technical Affairs Committee

The VDMA Technical Affairs Committee adopts mechanical engineering p

Asset Publisher

More VDMA services

More VDMA services
VDMA cyber risk assessment
With the cyber risk check, you can easily check online how much risk your company is exposed to. If you so wish, you can receive a detailed assessment via email.
Corporate Cybersecurity Cyber-Newsletter
The Cyber Newsletter provides regular information on current cyber risks and developments. It also includes practical tips on IT security
Info portal for the Corporate Cybersecurity Initiative
"Corporate Cybersecurity" is an initiative launched in 2020 by the VSMA and the VDMA. The info portal supports its members by providing tips, working aids and the latest reports.
Online offering tool for the VDMA cyber policy
With this convenient online tool of the VDMA cyber policy, you can request an individual offer for industry-specific cyber insurance free of charge and without obligation
Industrial Security Working Group
The VDMA working group "Industrial Security" is a VDMA committee dedicated to security in industrial production environments and industrial products that has been in existence since 2012.
Information Security Working Group
The VDMA working group "Information Security" aims to promote awareness among VDMA members and to encourage the exchange of experience between working group members.
Cybersecurity Working Group
The Cybersecurity Working Group submits reports to the VDMA Technology Policy Steering Committee and prepares proposals on the mechanical engineering industry's stance in the domain of cybersecurity. The Cybersecurity Working Group follows legislative initiatives at a European and national level and maintains ties with policymakers in this area.

Asset Publisher

VDMA partners

Photo
MBI – Schulung Security
Photo
University4Industry
Photo
Allianz fĂĽr Cyber-Sicherheit

Level 2 Minimal Contact Display