Editorial Note: This article is for informational purposes only and reflects the author's understanding of regulatory developments as of the publication date. It does not constitute legal advice or official certification guidance. Regulatory interpretations may evolve, and compliance requirements vary by product specifics. Readers should consult qualified legal or compliance professionals for their specific situations.
Executive Summary
This white paper addresses a single question: how do the 2026 regulatory changes affect your signal isolators? The answer depends on one factor — your product’s digital footprint. Pure analogue isolators with no firmware or software are exempt from the EU Cyber Resilience Act (CRA), while smart isolators with digital interfaces (HART, RS‑485, Bluetooth) face mandatory compliance by 11 December 2027. Separately, the ATEX 2014/34/EU Guidelines (6th Edition) allow digital Declarations of Conformity — but a broken QR link after a website redesign may be treated as an inaccessible DoC, which could trigger market surveillance action. This document is structured for three primary roles: R&D architects determining CRA scope, compliance specialists updating ATEX documentation, and project leads preparing third-party approval packages. Each section is labeled accordingly. For engineers and procurement teams seeking pre-assessed, regulation-ready hardware, request compliance verification data via SUCH Shop.

- R&D / System Architects refer to Section 1.2 – CRA "digital elements" boundary & platform upgrade scope.
- Compliance / Certification Specialists see FAQ Q4 – DoC strategy for ATEX Edition 6; SIL vs CRA overlap.
- Project Technical Leads see Section 4 – One‑pass third‑party approval package.
- Quick cost reference see Section 2 – Certification fees & timelines.
- Deep Dive into the Two Key 2026 Regulations
- Significant Technical Cost Structure for Compliance Implementation
- Systemic Risks from Misinterpretation of Compliance Requirements
- Technical Response Strategies Under the Compliance Framework
- FAQ (Frequently Asked Questions on Technical Compliance)
Document Structure – Quick Product Classification:
- Category 1: Pure Analogue Isolators – No microprocessor, no firmware, no digital interface.
- Covered in Section 1 (CRA applicability)
- Verdict: Exempt from CRA. ATEX physical layer only.
- Category 2: Configurable Analogue Isolators – Internal MCU/EEPROM, but no external communication.
- Covered in Section 5 (FAQ Q2/Q3)
- Verdict: Borderline CRA coverage. SBOM preparation advised.
- Category 3: Smart Communication Isolators – HART/RS-485/Bluetooth/DTM external digital interfaces.
- Covered in Section 1.2 (CRA jurisdiction) and Section 4 (compliance strategy)
- Verdict: 100% mandatory CRA compliance by 11 December 2027.
Each category has its own compliance pathway. Jump to the relevant section for full technical details.
2026 brings the most significant regulatory overhaul for industrial automation in recent years. If you work on signal isolators—whether in R&D, certification, or project delivery—two dates deserve a clear mark on your calendar:
13 January – The European Commission releases the ATEX 2014/34/EU Guidelines, 6th Edition. This several-hundred-page document clarifies long-standing practical issues, including digital DoC formats and spare parts classification.
11 September – The vulnerability reporting obligation under the EU's first mandatory cybersecurity law, the Cyber Resilience Act (CRA), takes effect early — 15 months before the full enforcement date. Full compliance (including SBOM, security updates, and secure‑by‑default) follows on 11 December 2027.
For signal isolators—a critical safety barrier in industrial control systems—the combined impact of these two regulations is more complex than you might expect.

This article addresses the key questions from three decision-maker roles:
| Role | Core Challenge / Question | 2026 Response Focus |
| R&D / System Architects | How much does your current product platform need to change under the new rules? Where exactly does the CRA draw the line for "digital elements"? | Assess platform upgrade scope; clarify CRA's definition boundary for digital elements; plan hardware/software roadmaps early. |
| Compliance / Certification Specialists | How should you update your DoC documentation strategy for ATEX Edition 6? How do SIL and CRA boundaries align? | Revise DoC strategy for Edition 6; recognise that SIL and CRA address distinct risk domains — functional safety and cybersecurity — and currently no mutual recognition exists between them and require separate assessments; avoid overlap gaps. |
| Project Technical Leads | How do you design a third‑party approval package that passes in one round under the new framework? | Integrate new requirements early; coordinate with notified bodies; prepare a comprehensive, one‑pass submission package. |
1. Deep Dive into the Two Key 2026 Regulations
1.1 ATEX 2014/34/EU Guidelines, 6th Edition: The "Long‑Term" Trap Behind Digital Convenience
One sentence sums up the core change: documents can go digital, but liability never expires.
Digital DoC is here – but a broken link voids your certificate.
Previously, the EU DoC (Declaration of Conformity) had to accompany each shipment as a paper copy. Edition 6 now explicitly allows digital DoCs via QR codes or web links – a real cost saving for document distribution. But what is the trade‑off?
Manufacturers must ensure that the DoC remains accessible to regulators and end‑users for at least 10 years after the product is placed on the market. If your company website is redesigned, your domain expires, or your server migrates and the QR link breaks – the DoC may be deemed inaccessible, which could trigger market surveillance action and the product being treated as non‑compliant.
This is not a theoretical risk. Our recommendation: set up a dedicated domain or cloud storage path for ATEX digital DoCs, with automatic renewal reminders. Do not rely on your general corporate web pages.
Safety instructions: still paper‑based with each shipment.
This is the most overlooked "grandfather clause" in Edition 6. The digital DoC does not replace the paper safety manual. The Commission explicitly applies a risk‑based approach: safety‑critical information must be on paper; non‑safety information may be digital, but paper copies must be supplied free of charge on request.
Spare parts clarification
Edition 6 clarifies that spare parts for products already placed on the market do not require a new ATEX application – unless the spare part itself qualifies as equipment or a component. This means repair parts for conventional analogue isolators can continue to circulate without being "audited retroactively."
Practical warning
For smart isolators with software configuration, the configuration software may fall under ATEX "component" scrutiny. The Directive clearly distinguishes between "equipment" and "components". The "U" suffix in ATEX markings indicates component status (e.g., an isolator module with component‑only certification has a "U" at the end of its certificate number, showing it is not for standalone use).
Market surveillance authority — §38 of the ATEX Guidelines (6th Edition)
The 6th Edition also clarifies that market surveillance authorities may withdraw "simple products" (e.g., hand tools, enclosures) from the market if they are deemed to present a safety risk — even if previously exempt from ATEX. Manufacturers should not assume that a product falls outside ATEX solely based on its "simple" classification.
1.2 EU Cyber Resilience Act (CRA): Is Your Isolator a "Product with Digital Elements"?
The answer depends on your isolator's digital footprint – and the CRA draws a clear line.
The CRA applies to "products with digital elements" – defined as software or hardware whose intended purpose involves a direct or indirect data connection to a device or network.
CRA applicability for three types of signal isolators – find your product type below for a risk‑based assessment of your compliance pathway.
CRA Applicability – Risk‑Based Assessment Framework
This classification is based on current industry interpretation of the CRA and is not an official EU classification. Final determination of CRA applicability requires case‑specific legal analysis.
Product Type: Pure Analogue Signal Path
Hardware & Interface: No microprocessor, no firmware, no software. Pure hardware pass‑through (4‑20 mA / 0‑10 V / thermocouple / RTD). No HART, no digital bus, no debug interface.
CRA Jurisdiction: Not mandatorily covered – only CE‑EMC/LVD and ATEX physical layer requirements apply.
Deadline: N/A
Action: No CRA action required; maintain existing EMC/LVD and ATEX compliance.
Product Type: Configurable Analogue Isolator
Hardware & Interface: Internal MCU for zero/span calibration, cold‑junction compensation, or linearisation. Rewritable registers (EEPROM) but no external communication interface – adjustment only via PCB jumpers or internal potentiometers.
CRA Jurisdiction: Borderline – leans toward coverage because it contains embedded code ("digital elements"), but risk level is low.
Deadline: By December 2027 (recommended)
Action: Maintain internal firmware version records and monitor official CRA updates; formal SBOM is not yet confirmed for this category.
Product Type: Smart Communication Isolator
Hardware & Interface: MCU/MPU with external digital interfaces: HART modem, RS‑485/Modbus/Profibus fieldbus, USB/Bluetooth/NFC local wireless debug, FDT/DTM/EDS files, or host configuration software.
CRA Jurisdiction: Clearly falls under CRA scope – full compliance is strongly recommended.
Deadline: 11 December 2027
Action: Full compliance: SBOM, vulnerability monitoring (24h reporting), 5‑year security updates, secure‑by‑default configuration.

| Obligation | Compliance Standard / Requirement | Timeline / Timeframe |
| SBOM (Software Bill of Materials) | Disclose all open‑source components, third‑party libraries, and their version numbers – including embedded RTOS, TCP/IP stacks, crypto libraries, etc. Technical documentation must be retained. | Retain for 10 years after market placement. |
| Vulnerability monitoring and reporting | Three‑stage reporting under Article 14: • 24h – Early warning upon becoming aware of an actively exploited vulnerability • 72h – Detailed notification (impact, scope, mitigation measures) • 14 days – Final report after corrective/mitigating measure is available |
Report within 24h / 72h / 14 days respectively |
| Security update commitment | Provide free security patches to address vulnerabilities. | At least 5 years of free patches from market placement. |
| Secure‑by‑default configuration | Factory default passwords, default ports, etc., must comply with the "security default" principle. | Immediate / ongoing – applies from product launch and throughout lifecycle. |
A common misconception: If a pure analogue isolator is mounted inside a control cabinet that also contains an Ethernet switch, does the CRA require that isolator to comply? No. The CRA applies to the product itself – "products with digital elements". If the isolator is a physical‑layer signal processor with no executable code and no data send/receive capability, it is not covered. However, system integrators should be aware that when they CE‑mark the entire control cabinet, they assume responsibility for system‑level cybersecurity risks.
2. Significant Technical Cost Structure for Compliance Implementation
The following is an objective cost breakdown, with no brand comparisons or commercial quotations.
| Cost Area | Specific Technical / Process Inputs | Cost Reference |
| Certification testing | ATEX explosion protection tests (enclosure impact, thermal cycling, overpressure) and SIL functional safety assessment (including FMEDA failure rate calculations) | EUR 20,000–50,000 (approx. RMB 150k–400k) per product, based on industry estimates and dependent on complexity and notified body schedule |
| Certification lead time | Full cycle from technical documentation submission to formal certificate issuance | 6–12 months for initial certification (documentation submission to certificate issuance, including possible re‑testing after corrective actions) |
| Component selection and BOM upgrade | To meet ATEX increased safety (Ex e) or intrinsic safety (Ex i) requirements, specific grades of PCB materials, potting compounds, and terminal blocks are required | BOM cost increase: typically 20%–60% (depending on explosion protection level) |
| Routine factory testing | Each unit must undergo 1,500 V AC / 2,500 V AC dielectric strength testing, plus high/low temperature ageing – equipment depreciation and energy costs add to fixed production line expenses | Long‑term fixed production expenditure |
| Supply chain compliance management | Collecting REACH 241 SVHC test reports and RoHS 10 substance test reports from all upstream component suppliers | Significant manual review costs – often underestimated as a hidden expense |
3. Systemic Risks from Misinterpretation of Compliance Requirements
The following table maps the most common misinterpretation scenarios to their corresponding non‑compliance details and project‑level consequences.
| Trigger Scenario | Common Non‑compliance Details | Consequences (Project / Business Impact) |
| On‑site acceptance rejection by Notified Bodies | • Ex marking format on product nameplate does not fully comply with EN 60079‑0 font and size requirements. • Standard versions cited in the DoC do not match the latest OJEU publications. • Technical documentation lacks complete circuit diagrams and temperature class (T‑class) calculation sheets. |
Entire batch of isolators rejected for installation, delaying the project acceptance milestone. |
| Customs detention upon import inspection | • CE mark affixed improperly (e.g., incorrect size ratio). • DoC lacks the Notified Body number (mandatory for ATEX Category 2 products). • No paper safety instructions included with the shipment (violating ATEX Edition 6 grandfather clause). |
Goods marked as "non‑compliant" and held in customs warehouses for weeks, incurring high demurrage charges and penalty claims. |
| Zero market access in 2027 due to CRA compliance delays | • SBOM not submitted by 11 December 2027. • Vulnerability reporting process not established by the deadline. |
Product model automatically loses EU market access on that date. Neither private labelling nor OEM assembly can bypass – full liability rests with the product‑level responsible entity. |
4. Technical Response Strategies Under the Compliance Framework
The following strategies address the three risk scenarios outlined in the previous section, translating each into a structured technical response.
| Strategy | Description |
| Strategy 1 – Set up an internal mechanism for dynamic standard version tracking | Assign a designated person (or use RPA tools) to review the OJEU harmonised standard update list monthly. During the transition period between publication and mandatory effective date, align technical documentation and test reports with the new versions. |
| Strategy 2 – Tiered management of digital elements (for CRA) | Segment your product portfolio into three layers: • Pure analogue • Configurable (no external communication) • Smart communication For the third tier, start internal deployment of SBOM scanning tools (e.g., open‑source solutions like OWASP Dependency‑Track) early to trace the origin of every line of embedded code. |
| Strategy 3 – Digital documentation and long‑term preservation | Set up a dedicated domain or cloud storage path for ATEX digital DoCs, with automatic renewal reminders. Ensure that QR codes / short links are set to "permanent" validity and provide a backup manual request channel in case of link failure. |
5. FAQ (Frequently Asked Questions on Technical Compliance)

Q1: The new ATEX Edition 6 guide allows digital DoCs. If my company website is redesigned and the QR link breaks, what are the consequences?
A: Yes, a broken link may be treated as an inaccessible DoC, which could trigger market surveillance action and the product being treated as non‑compliant. Under ATEX traceability rules, manufacturers must ensure the DoC remains accessible to regulators and end‑users for at least 10 years after the product is placed on the market. Recommendation: set up a dedicated long‑term document repository, rather than relying on general corporate web pages.
Q2: If a pure analogue signal isolator is mounted inside a control cabinet that also contains an Ethernet switch, does the CRA require that isolator to comply?
A: No. Pure analogue isolators without executable code or firmware fall outside the CRA scope, even if installed inside a cabinet with network equipment. The CRA applies strictly to the product itself – "products with digital elements". However, system integrators should note that when they CE‑mark the entire control cabinet, they assume responsibility for system‑level cybersecurity risks.
Q3: How can I confirm that the harmonised standards cited in my ATEX DoC are the latest valid versions published in the OJEU?
A: Check the OJEU regularly – not just the standard's publication year. The OJEU publishes an updated list of harmonised standard references. Manufacturers must not simply quote the standard's publication year; they must check, line by line, the "date of entry into force" for each standard as published in the OJEU. A common pitfall: the technical content of a standard may not change, but its status in the OJEU (re‑affirmed or withdrawn) may change – the DoC must reflect the latest OJEU reference status.
Q4: Do SIL (functional safety) and CRA (cybersecurity) have overlapping test items that can be mutually waived?
A: No, they address distinct risk domains. Currently, the assessment logics of the two frameworks are completely different. SIL (per IEC 61508) evaluates random hardware failures and systematic capability (hardware redundancy, diagnostic coverage). CRA evaluates information security resilience against malicious attacks (vulnerabilities, encryption, access control). No mutual recognition or waivers exist at this time – each requires a separate independent assessment.
Need to confirm your product classification? Review our signal isolator range or contact our support team to discuss product specifications and applicable compliance documentation. For ordering, delivery, and return information, see our Shipping & Returns page.
Compliance Checklist – For Final Review
The following checklist consolidates the key compliance actions discussed in this white paper for a final self‑review.
| Check Item | Reference |
| ATEX DoC accessible via QR/URL for at least 10 years after market placement? | Section 1.1 |
| Paper safety manual included with each shipment? | Section 1.1 |
| Product classified: Pure Analogue / Configurable / Smart? | Section 1.2 |
| If Smart: SBOM prepared, vulnerability reporting process in place, 5‑year update commitment documented? | Section 1.2 |
| SIL and CRA assessed separately (no mutual recognition)? | FAQ Q4 |
Note on cost data: Cost and timeline figures are industry estimates and may vary significantly by product complexity, protection concept, and notified body. Formal quotations are recommended before project initiation.
Closing Remarks
2026 is a milestone year for EU industrial automation regulations. ATEX Edition 6 opens the door to digital documentation, but it also raises the bar for long‑term record‑keeping. The CRA, meanwhile, pushes cybersecurity compliance down from the IT layer to every smart terminal on the OT floor.
Signal isolators may be small, but they are one of the most overlooked – yet critical – links in the compliance chain. Whether you are adjusting your technical architecture on the R&D side or upgrading your documentation strategy on the compliance side, starting early and progressing in phases is far better than a rushed response just before the deadline.
11 December 2027 is not far away – for products that require redesign, testing, and re‑certification, the window is narrowing.