Cyber Resilience Act (CRA)
At Metso, cybersecurity is a core enabler of how we build, operate and support our products, services and digital solutions. Protecting our customers, business partners and employees is a key priority, and resilience against cyber threats is an essential part of our way of working. Cybersecurity considerations are integrated into our operating model, product and solution development, and end-to-end lifecycle processes.
The EU Cyber Resilience Act (CRA) introduces common cybersecurity requirements for products with digital elements across their entire lifecycle. Metso views the CRA as an important regulatory milestone that supports a higher level of cybersecurity across the European market and complements our established security principles and practices.
As part of our long-term cybersecurity strategy, Metso is committed to complying with the requirements of the Cyber Resilience Act. To support this, Metso has launched a company-wide CRA initiative bringing together product development, cybersecurity, supplier management, sourcing and lifecycle management to ensure a coordinated approach.
With defined governance and a structured compliance roadmap, Metso is advancing towards CRA readiness in line with the regulatory timelines of 11 September 2026 and 11 December 2027. By embedding CRA requirements into our broader cybersecurity framework, Metso continues to strengthen trust and resilience as a responsible partner in an increasingly digital and connected industrial landscape.