Skip to content

Compliance

Cyber Resilience Act

Our statement on the EU Cyber Resilience Act (Regulation (EU) 2024/2847): what it covers, what applies to us now, and what we’re preparing for December 2027.

Who we are under the CRA

Moorfield Nanotechnology Ltd designs and manufactures thin-film deposition, etch and annealing systems in Knutsford, United Kingdom, and is a Judges Scientific company. Under the CRA we are the manufacturer of these systems and the software and firmware supplied with them.

Which products are in scope

The CRA applies to products with digital elements placed on the EU market. Every system we sell contains controller firmware and control panel software, and many connect to a PC running our software (IntelliDep on MiniLab systems, data-logging software on benchtop systems), so we expect them to be in scope when we sell them in the EU. That covers the MiniLab range, nanoPVD, nanoETCH, nanoCVD and nanoANNEAL.

Every system we sell contains a computer of some kind (a controller, touchscreen control panel or PC), so we treat all of our products as in scope.

What applies, and when

FromWhat applies
11 September 2026Manufacturers must report actively exploited vulnerabilities and severe security incidents through the EU single reporting platform: an early warning within 24 hours, a notification within 72 hours, and a final report afterwards.
11 December 2027The full requirements apply: security by design, a vulnerability handling process, a published support period with free security updates, a software bill of materials, technical documentation, conformity assessment and CE marking under the CRA.

What we have in place now

What we are preparing for December 2027

  • A documented vulnerability handling process covering our software and firmware
  • Software bills of materials for our control software and firmware (see Software transparency)
  • The technical documentation and risk assessment the CRA requires
  • Conformity assessment and CE marking under the CRA

Expected conformity route: the core function of our systems is thin-film deposition, etching and annealing. That isn’t one of the higher-risk product categories listed in Annexes III and IV of the CRA, so we expect our products to fall in the default category. The default category allows us to assess conformity ourselves, through the procedure the CRA calls internal control.

Our current position

We don’t yet claim conformity with the Cyber Resilience Act, and our products don’t yet carry CE marking under it. We’ll update this page as our work towards December 2027 progresses.