Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Wednesday, 23 September 2026

A new cybersecurity member.

DeNexus has officially joined the ISA Global Cybersecurity Alliance (ISAGCA), demonstrating its commitment to advancing operational (OT) cybersecurity through the ISA/IEC 62443 series of standards.

Created by the International Sociey of Automation (ISA), the ISA Global Cybersecurity Alliance is a collaborative forum focused on strengthening OT cybersecurity through education, knowledge sharing and industry collaboration. Leveraging the widely used ISA/IEC 62443 standards, ISAGCA works to expand cybersecurity expertise, openly share knowledge and resources and protect the OT cybersecurity worldwide community.

DeNexus delivers an evidence-based solution for OT industrial stakeholders to gain visibility into each facility’s cyber exposure, calculate the probability and financial impact of potential cyber incidents and prioritize risk mitigation based on ROI or other KPIs. By joining ISAGCA, the company underscores its commitment to supporting standards-driven security practices across the OT lifecycle from system design and integration to operations and maintenance.

DeNexus founder and CEO Jose M. Seara spoke at the ISA OT Cybersecurity Summit in Prague (CZ) in June 2026, leading a session titled “OT Cyber Insurance and Risk Transfer: Right-Sizing Coverage Using Evidence, Not Guesswork.” Based on interest, he also conducted an encore presentation on the topic via webinar in September. Through ISAGCA membership, DeNexus will collaborate with global industry leaders to accelerate awareness, adoption and implementation of the ISA/IEC 62443 standards framework.

This is a significant moment for the ISAGCA community,” said Michelle Ritterskamp, ISAGCA program coordinator. “DeNexus brings a deep OT technical experience and a desire to incorporate ISA/IEC 62443 into their business. ISAGCA staff would like to thank DeNexus for the excellent collaboration on programs already, and we look forward to further sharing DeNexus’ expertise in future initiatives.” 

"Industrial cyber risk has been invisible to the people who carry it — boards, CFOs and the markets that could underwrite it,” Seara said. “That's the problem I started DeNexus to solve, and it's the same problem ISA/IEC 62443 addresses from the standards side. A common standard for how OT security is designed and assessed is what makes risk assessable in the first place. And once risk can be assessed, it can be quantified, mitigated and transferred. That's the chain: ISA/IEC 62443 gives the industry a shared language for control, and our platform turns that control state into a financial number a board can govern by and an underwriter can price against. Joining ISAGCA puts us alongside the organizations building that foundation. Our mission is to make industrial cyber risk quantifiable for boards, investors and the risk transfer market — and standards are what make that possible at scale."

Automation Summit - Prague (June 2026)


@ISA_Automation @DeNexusInc1 #Cybersecurity #PAuto

Wednesday, 26 August 2026

Co-operation in improving OT cybersecurity.

A collaboration to help strengthen OT cybersecurity across critical infrastructure has been announced between the International Society of Automation (ISA) and the Operational Technology Cybersecurity Coalition (OTCC).

The two organisations have signed a Memorandum of Understanding (MOU) to work together on initiatives that raise awareness of OT cybersecurity risks and solutions, explore strategic issues of shared interest and facilitate technical engagement between members of each organisation. The goal is to encourage better implementation and recognition of foundational cybersecurity standards like ISA/IEC 62443, the globally recognised consensus-based series of OT cybersecurity standards developed by ISA.

ISA's CEO, Claire Fallon
“Protecting critical infrastructure requires sustained collaboration, practical guidance and a shared commitment to standards-based cybersecurity,” said Claire Fallon, CEO of ISA. “This partnership creates an important framework for ISA and OTCC to help advance key OT cybersecurity practices.”

"ISA and OTCC come at OT cybersecurity from different angles — ISA through the standards that define good practice, OTCC through the companies putting them to work," said Tatyana Bolton, executive director of OTCC. "Bringing those perspectives together is how standards move from paper into practice, and we look forward to working with ISA to make that happen.”

OTCC recently published a position paper advocating for a single, horizontal standard for OT cybersecurity rather than a patchwork of sector-specific mandates. The paper recommends that ISA/IEC 62443 be recognized as the global OT security standard. It names ISA/IEC 62443 as an established framework uniquely situated to harmonize around, as this standard has been specifically tailored to meet the requirements of OT. With one interoperable OT cybersecurity standard such as ISA/IEC 62443, the OTCC paper argues, the burden of adhering to duplicative standards can be reduced, helping to ensure critical infrastructure and industrial operations stay resilient everywhere.


@ISA_Automation  @automation_com @OT_Coalition #Cybersecurity #PAuto

Monday, 24 August 2026

Certification for commercial products procured by US.

ISASecure®, a wholly owned subsidiary of The International Society of Automation (ISA), is partnering with the United States National Security Agency (NSA) to develop a new certification scheme for commercial operational technology (OT) components sold by manufacturers and procured by the US government for use within National Security Systems (NSS). With a common goal of securing high criticality OT systems, the new certification scheme is intended to increase confidence in the security of commercial components.

ISA developed a set of security levels (SL) with specific cybersecurity requirements for OT components in the international OT cybersecurity standard ISA 62443-4-2. In addition, six new technical security requirements were developed and published by NSA’s Operational Technology Assurance Partnership (OTAP) Program in the NSA/CSS Cybersecurity Technical Report titled "Operational Technology Assurance Partnership: Smart Controller Security within National Security Systems" (April 2025).

In response to the need, ISASecure is developing a separate High Criticality Component Security Assurance (HCSA) certification scheme derived from the well-established Component Security Assurance certification scheme (CSA). Upon completion and the OTAP program office's acceptance of the ISASecure HCSA scheme, the NSA will use the scheme as an approved certification mechanism in the evaluation process of adding OT OEM components to the NSS OT Product Compliant List (PCL).

“This is a major achievement in the history of ISASecure,” said Dr. Mark P. DeAngelo, program manager of ISASecure. “The NSA recognizes the importance of the ISA 62443 standard and the ISASecure program, which independently evaluates a product's conformity to the ISA 62443 standard. ISASecure's reputation and commitment to robust OT security precedes the NSA's decision to partner with us. Our CSA product certification set the foundation for HCSA."

An ISASecure HCSA certificate provides a product manufacturer with essential evidence in consideration of that product's inclusion on the NSA's NSS OT PCL. In other words, ISASecure certification is an important step before a smart controller can be purchased and installed within an NSS.

Manufacturers interested in developing smart controllers are encouraged to join ISASecure to be part of the HCSA development. Stakeholders include manufacturers of components, accreditation bodies and certification bodies.


@ISA_Automation  @automation_com @NSAGov #Cybersecurity #PAuto

Tuesday, 4 August 2026

Cybersecurity in Energy.

“Cybersecurity is integral across the oil and gas value chain, for securing data, safeguarding asset integrity, and preventing financial losses.”

Energy infrastructure is a high-value target for cybercriminals. Attacks on critical national infrastructure (CNI) can have an outsized impact, disrupting essential services, causing nationwide instability, and generating financial gains for hackers. As geopolitical uncertainty intensifies, so does cyber espionage, making it crucial for energy companies to invest in resilient cybersecurity programs, says GlobalData, a leading intelligence and productivity platform.

L GlobalData’s Strategic Intelligence report, “Cybersecurity in Energy,” highlights how cybersecurity impacts key challenges in the energy industry. These include digitalization, distributed energy resources (DERs), grid modernization, supply chains, third-party vendors, and geopolitics.

Ravindra Puranik, Oil and Gas Analyst at GlobalData, comments: “Energy companies depend on extensive third-party ecosystems, making supplier vulnerabilities a major cyber risk that can spread into IT and OT environments. Attacks exploiting shared vendor software (e.g., file-transfer tools) have hit major players.”

“Mitigation requires stronger vendor governance, such as continuous monitoring, standards, segmentation, least privilege, audits, and joint incident response.”

GlobalData notes that digitization and the convergence of information technology (IT) and operational technology (OT) are connecting legacy assets and modern grid technologies, expanding entry points where IT compromises can disrupt operations. Generative artificial intelligence (AI) further increases attacker speed and sophistication, shrinking defenders’ response windows.

Puranik concludes: “Oil and gas firms should invest in specialized cybersecurity services that provide continuous monitoring and rapid response, expert validation, and strong operational readiness. Equipment and oilfield service providers should also add product-focused services such as secure development support and security audits/certification to reduce supply chain risk and maintain customer trust. 

 “Cybersecurity is integral across the oil and gas value chain, for securing data, safeguarding asset integrity, and preventing financial losses.”


@Technology_GD #PAuto #Energy #Cybersecurity

Wednesday, 29 July 2026

Cybersecurity in the Energy Sector of Cost Rica.

The Instituto Costarricense de Electricidad, also known as ICE or the Costa Rican Institute of Electricity, has officially joined ISASecure®, a wholly owned subsidiary of ISA. ISASecure is the globally recognized certification program that validates conformance to the ISA/IEC 62443 series of standards for industrial automation and control systems (IACS) cybersecurity.

The Instituto Costarricense de Electricidad was founded in 1949 with the mandate to take advantage of water resources efficiently and responsibly for the electrification of the country. A Costa Rican state company, its mission is to provide energy, connectivity and safe and sustainable digital services to the inhabitants of Costa Rica. Their electrical matrix takes advantage of the earth's steam, wind, water, solar energy and biomass. It also focuses on the development of smart grids and electric mobility.

This new partnership with ISASecure reflects the Costa Rican Institute of Electricity’s ongoing mission to strengthen the OT security maturity of Costa Rica’s energy matrix and ensure OT cybersecurity procedures are continually maintained to the highest standards.

Erick Obregón Navarro, ICE Dirección Ciberseguridad y Protección Empresarial, Gerencia General shared: “Joining ISASecure and the adoption of the ISA/IEC 62443 standard supports the implementation of key industrial cybersecurity capabilities, such as:

  1. Protection of industrial networks and SCADA systems.
  2. Definition of security levels and layered control approaches.
  3. Network segmentation and reduction of the attack surface.
  4. Secure management of access and industrial components.
  5. Continuous monitoring and incident response.

“We look forward to our partnership with ISASecure to ensure our energy systems and Costa Rican residents are protected from cybersecurity attacks.”

“It is an honor to welcome the Costa Rican Institute of Electricity (ICE) into the ISASecure program,” said Mark DeAngelo, ISASecure program manager. “Today’s critical infrastructure demands comprehensive, rigorously validated cybersecurity. We look forward to collaborating with the Instituto Costarricense de Electricidad as we advance our mission of industry partnership, certification and standards-based product development to help achieve a more secure world. It is an honor to welcome our first Costa Rican company to ISASecure.”


@ISA_Automation  @automation_com @GrupoICEcr #Pauto #Cybersecurity

Tuesday, 14 July 2026

Secure accreditation assured.

The American Association for Laboratory Accreditation (A2LA), an ISASecure® Accreditation Body (AB), is now offering Inspection Body (IB) and Product Certification Body (CB) accreditation for ISASecure Automation and Control System Security Assurance (ACSSA) Certification to ISA/IEC 62443-2-1, 2-2, 3-2 and 3-3. ISASecure, a wholly owned subsidiary of ISA, is a globally recognized certification program that validates conformance to the ISA/IEC 62443 series of standards for industrial automation and control systems (IACS) cybersecurity.

ISASecure’s CBs and IBs are independently accredited by ISO/IEC 17011 Accreditation Bodies (ABs) that are Multilateral Recognition Arrangement (MRA) signatories of the Global Accreditation Cooperation Incorporated (Global ACI) for ISO/IEC 17065, ISO/IEC 17025 and ISO/IEC 17020.

A2LA is among the largest accreditation bodies in the world and the only independent 501(c)3 non-profit internationally recognized accreditation body in the United States that offers a full range of comprehensive conformity assessment accreditation services.

Established in 1978 as a public service membership society, A2LA is dedicated to the formal recognition of competent testing and calibration laboratories, biobanking facilities, inspection bodies, product certification bodies, proficiency testing providers and reference material producers. A2LA has over 4,500 actively accredited certificates representing all 50 US states and more than 50 countries. For a current listing of A2LA’s accredited organizations, please search A2LA’s directory.

All ISASecure certification testing is conducted by accredited, independent test laboratories. A2LA has been an ISASecure AB working with members to become CBs for ISASecure’s Security Development Lifecycle (SLDA), Component Security Assurance (CSA) and System Security Assurance (SSA).

“Expanding A2LA’s services to include Inspection Body and Product Certification Body accreditation for ACSSA reflects our commitment to supporting emerging cybersecurity frameworks that protect critical infrastructure,” says Trace McInturff, vice president of accreditation services, A2LA. “As automation and control systems become increasingly interconnected, independent third-party assurance is essential. We are proud to be recognized by ISASecure and to help organizations demonstrate competence, consistency and conformance in this rapidly evolving area.”

“A2LA has a great reputation for being on the leading edge of cybersecurity. We look forward to A2LA’s newest offering to ISASecure members who are looking to be an IB or CB for ACSSA,” says Dr. Mark DeAngelo, ISASecure program manager. “It’s an important milestone for ISASecure ACSSA and for the future security of critical industrial sites.”


@ISA_Automation  @automation_com #A2LA #ISA62443 #PAuto #Cybersecurity #USA

Wednesday, 24 June 2026

Security in engineering.

Proven standards for critical infrastructure – more relevant today than ever.

The topic of cybersecurity is currently gaining new regulatory visibility with the NIS2 Implementation Act and the upcoming Cyber Resilience Act (CRA). Requirements are becoming more concrete, obligations to provide evidence are increasing, and deadlines are drawing closer. This means a need for action for many companies. AUCOTEC regards this above all as confirmation.

AUCOTEC has worked for decades with operators of critical infrastructure. Throughout all these years, one central customer expectation has been taken as a given: the systems used must be secure at all times. Cyber Security is therefore not a new field of action, but has always been an integral part of the development and provision of the Engineering Base software platform.

Regulatory momentum meets established practice.
The current developments surrounding NIS2 and the CRA do not change the fundamental expectation of security – they make it more visible, measurable and, in many cases, also formally subject to evidence requirements.

This is precisely where AUCOTEC creates additional transparency: Engineering Base versions 2025 and 2026 were independently analysed using ReversingLabs Spectra Assure – and achieved Level 3 in the assessment process.

Importantly, this analysis does not mark a new security level, but confirms the one already established. At the time of the assessment, no known vulnerabilities classified as critical, no malware findings and no relevant license risks were identified. This is complemented by full transparency regarding all software components used, in the form of a Software Bill of Materials (SBOM).

External validation of an existing commitment.
“Cyber Security has never been optional for our customers – and therefore not for us either,” explains Dr. Jan-Mirko Maczewski, Head of Research & Development at AUCOTEC. “Current regulatory requirements such as NIS2 or the Cyber Resilience Act are not prompting a rethink; rather, they confirm our long-standing approach.”

The Spectra analysis addresses key technical aspects of modern security requirements – in particular transparency, traceability and the systematic assessment of software components. There is no formal equivalence with regulatory requirements. However, there is substantial alignment in key areas.

For customers, this means: a robust, independent security assessment, support in meeting growing evidence requirements, reduced effort in audit and approval processes, and additional assurance in regulated project environments.

Continuity as the decisive factor.
The independent assessment is deliberately designed as part of a continuous process. Security analyses are carried out regularly and continued with every version.

The fact that both the current and the already established version of Engineering Base achieve this level underlines the key message: Cyber Security at AUCOTEC is a consistent standard.

Holistically embedded – technologically and organisationally.
This commitment is reflected not only in the product itself, but also in the supporting structures: ISO 27001-certified information security management, ISO 9001-certified quality management, clear responsibilities, including through a Chief Information Security Officer (CISO), as well as established audit and governance processes.

These are being continuously developed further with the ongoing expansion of Quality Excellence structures.

A clear signal in the context of new requirements.
Looking ahead to the upcoming CRA deadlines and the implementation of NIS2, it is clear: Cyber Security is increasingly evolving from an implicit expectation into an explicit obligation to provide evidence. AUCOTEC is addressing this development with transparency regarding a security level that has been established for decades. Or put another way: the requirements are becoming more concrete – the response to them has long been part of the solution at AUCOTEC.


@AUCOTEC_AG @PresseBox @UnnGmbh @Cybersec_EU @ec.europa.eu #Aucutec #Cybersecurity #PAuto

Monday, 15 June 2026

Simplify secure connectivity.

A unified industrial connectivity platform that combines plug-and-play edge gateways with a cloud-based subscription service to deliver simple, secure remote access from day one.

The solution offered by New Ewon Edge & Cloud from HMS Networks, enables machine builders and end users to get started quickly and progressively expand into data services, advanced analytics, and fleet management, providing deeper insights into machine performance as their digitalisation needs and business models evolve.

Shift toward service-driven industrial models.
Industrial connectivity has become crucial in driving performance and securing a competitive edge.

Market data* clearly reflects this shift:

  • Aftermarket services are growing more than 10% annually, outpacing new equipment sales
  • Service gross margins can be up to 2x higher than those of new machine sales
  • For complex equipment, service EBIT margins can be almost 4x higher
  • Only 4% of machine builders generate recurring revenue from digital services

At the same time, expectations among machine operators continue to evolve. They need instant remote support, real-time visibility of machine performance, and long-term, service-oriented relationships rather than one-off transactions.

The growing disconnect between market expectations and industrial capabilities highlights the need for secure, scalable connectivity as a critical foundation for modernisation. In this environment, user experience is becoming an increasingly important factor in technology adoption.

To address these evolving needs, HMS Networks introduces a scalable platform that simplifies secure remote access and lays the foundation for future digital services and industrial applications.

New generation of industrial remote access.
Industrial companies face increasing pressure to maintain uptime, manage complex machine fleets, and comply with stricter cybersecurity requirements, including IEC 62443, NIS2, and ISO 27001.

The new Ewon Edge & Cloud platform addresses these challenges with:

  • Secure, IT-aligned remote access with VPN, SSO (Single Sign-On), MFA (Multi-Factor Authentication), and comprehensive audit logs
  • High-speed remote access delivering up to three times faster performance than the previous generation
  • Centralised access governance for internal teams and external partners
  • Standardised connectivity across machines, production lines, and sites
  • Scalable deployment from a single machine to global operations
  • Seamless edge‑to‑cloud integration for future analytics and digital services

“Industrial companies need remote access that is secure, simple, and built for real operational environments,” said Marco Bulacher, Strategic Product Manager - Access at HMS Networks. “With Ewon Edge & Cloud, we are delivering a platform that aligns with IT expectations while remaining true to the realities of OT.”

Designed for Machine Builders - Trusted by End Users Ewon Edge & Cloud has been engineered to meet the needs of both machine builders and industrial end users. 

For machine builders.
Faster troubleshooting and reduced service costs
Secure, controlled access for service teams
A scalable platform that grows with evolving machine builder needs
A unified architecture that eliminates fragmented tools

For end users.

  • Full control over third‑party access
  • Standardised connectivity across multi‑vendor environments
  • Improved uptime through faster diagnostics
  • Compliance support for modern cybersecurity frameworks
  • A user-centric platform that provides full control over user access and permissions

“Machine builders want a reliable service tool. End users want control and security. The new Ewon platform finally brings both together,” added Marco Bulacher.

A future‑ready foundation.
The Ewon Edge & Cloud platform is designed to evolve alongside customers’ digitalisation journeys.

Organisations can start with secure remote access and expand toward:

  • Advanced edge computing
  • Machine data collection
  • Predictive maintenance
  • Integration with IIoT platforms
  • Fleet‑wide machine performance insights

This modular approach ensures organisations can scale without replacing their existing systems.

20+ Years of industrial expertise
With more than 600,000 Ewon gateways deployed worldwide, HMS Networks brings decades of expertise in industrial connectivity and secure remote access. Supported by more than 23 offices worldwide and a global industrial support network, HMS delivers local expertise with international reach. 

A unified Edge & Cloud architecture

  • Industrial‑grade hardware designed for harsh environments
  • Development processes backed by HMS Networks, certified to ISO 27001
  • Structured security lifecycle management
  • Long-term product and cloud support
  • Continuous platform evolution

The result is a secure and scalable platform that is robust enough for OT, aligned with IT, and ready for the next generation of industrial digitalisation.


* Source BGC : Aftermarket Services: Industrial Manufacturer Growth | BCG
* Source McKinsey: How digital can grow revenue from aftermarket services | McKinsey

@hmsnetworks @ewonrouters @mepaxIntPR #PAuto #Cybersecurity

Wednesday, 10 June 2026

Fully accredited cyber certification for security consultant.

Perseus Information Security Consulting has received full accreditation from the A2LA Accreditation Body to serve as an ISO/IEC 17065 accredited certification body (CB) for the globally recognised certification program ISASecure®. Perseus is also now the first accredited CB for ISASecure’s new Automation and Control System Security Assurance (ACSSA) for Asset Owners to ISA/IEC 62443-2-1, 62443-2-4, 62443-3-2 and 62443-3-3.

"We are pleased to have Perseus Information Security Consulting join the ISASecure program as an accredited ISASecure certification body and become the first approved ACSSA CB,” said Dr. Mark P. DeAngelo, program manager of ISASecure.

The ISASecure program — which currently has ISO/IEC 17065 accredited certification bodies in the U.S., Japan, Taiwan, Singapore, Italy, Germany and India — is rapidly expanding its global reach through additional agreements with certification bodies around the world.

The ISASecure certification program validates conformance to the ISA/IEC 62443 series of internationally adopted standards for industrial security, with additional certifications for Security Development Lifecycle Assurance (SDLA), Component Security Assurance (CSA), IIoT Component Security Assurance (ICSA) and System Security Assurance (SSA).

Perseus has now begun accepting product submittals for ISASecure certification at their United States office and their Istanbul, Türkiye office. Perseus Information Security Consulting contact details can be found on the ISASecure website at this link.

ISASecure assesses automation and control products and systems to ensure they are robust against network attacks, free from known vulnerabilities and meet the security capabilities defined in the ISA/IEC 62443 standards. All ISASecure certifications are conducted by globally recognised ISO/IEC 17065 accredited certification bodies.

In addition to being certified by the ISO/IEC 17065 Accreditation Body, ACSSA CBs are required to take the new ISASecure Automation and Control System Security Assurance for Evaluators (IC49) three-day training class and pass the IC49 proctored exam.

Perseus Information Security Consulting provides technology consultation in the field of cybersecurity for enterprise-level organisations, namely, providing technological advice regarding cybersecurity strategy and risk and analysis of technological goods of others to assure compliance with cybersecurity industry standards. Their services also include TISAX Consulting, conducting SWIFT CSP Assessments, ICS/SCADA consulting, authorised EPDK cybersecurity maturity assessments across all seven of Türkiye's energy subsectors and now ISASecure ACSSA, SDLA, CSA, SSA and ICSA certification to ISA/IEC 62443 standard.

As an ISA Security Compliance Institute (ISCI) member, Perseus has been involved in the technical development of ISASecure’s newest conformance scheme, the ISASecure Automation Control System Security Assurance (ACSSA) program. Perseus staff, including Deniz Kaya and Burak Bicer, were among the first in the world to complete the ISASecure ACSSA for Evaluators training and certification.

"ISASecure and the ISA/IEC 62443 standards have become the global benchmark for industrial cybersecurity. Becoming the first accredited ACSSA certification body lets Perseus give asset owners an independent, internationally recognised way to prove that their automation and control systems meet that benchmark,” Kaya says. “We're proud to bring this capability to organisations across the United States, Türkiye and beyond."


@ISA_Automation @automation_com #PerseusInfo  #ISA/IEC62443 #Cybersecurity 

Tuesday, 9 June 2026

Cyber-secure embedded applications certified.

Certification for development and support of embedded building blocks and tech stacks awarded.

congatec has been certified to IEC 62443-4-1:2018 for the development and support of its embedded building blocks and tech stacks. With the certification issued by TÜV NORD, customers using congatec’s portfolio gain a solid foundation for developing their own products quickly and efficiently under increasing security and compliance requirements, while also demonstrably securing their supply chains. Customers benefit from secure implementation, including coding guidelines, verification and validation, as well as vulnerability, patch and obsolescence management for congatec’s application-ready building blocks and aReady.COM technology stacks. This offers significant time-to-market advantages, particularly in regulated markets such as automation and robotics, medical and energy technology, as well as transportation.

The company’s certified development and support processes demonstrate that cybersecurity is an integral part of all development phases from the outset. The tech stacks, consisting of a computer-on-module, licensed operating systems such as Ubuntu Pro and ctrlX OS, as well as software building blocks such as conga-connect (aReady.IOT) and conga-zones (aReady.VT), are based on audited development and support processes. This is also an important prerequisite for OEMs seeking to place electronic devices on the EU market, making it easier to meet the upcoming regulatory requirements of the Cyber Resilience Act (CRA), which becomes mandatory from 11 December 2027.

“By achieving IEC 62443-4-1 certification, we are demonstrating in accordance with internationally applicable guidelines, that we integrate cybersecurity consistently and verifiably into our development and support processes,” Konrad Garhammer, COO & CTO of congatec explains. “This gives our customers application-ready embedded building blocks and tech stacks based on certified development and support processes. It further supports integration into their own applications, simplifies security verification for customers and regulatory authorities, and creates a robust foundation for CRA-relevant compliance processes.”

“Our tech stacks developed in accordance with IEC 62443-4-1, including licensed operating systems, hypervisor and IoT connectors, help customers build their own compliance and security evidence more efficiently and simplify and accelerate certification work,” Dominik Ressing, CEO of congatec adds. “Companies, already relying on our building blocks today are positioning themselves early and efficiently for the requirements of the CRA and comparable regulatory frameworks.”


@congatecAG @UnnGmbh #PAuto

Tuesday, 26 May 2026

Ready for Cyber Resilience Act CRA.

An easy way for industrial manufacturers, system integrators, and factory owners to meet EU cybersecurity requirements for connected industrial products.

Under the EU Cyber Resilience Act, connectivity is no longer just a functional component of a product. It becomes a regulated part that must support long term security, secure updates, documentation, and compliance evidence throughout the product lifecycle. To address these requirements, HMS Networks has updated its Anybus Communicator portfolio with enhanced hardware and software security features developed under IEC 62443 certified secure product development processes.

“With the Cyber Resilience Act, cybersecurity becomes a purchasing requirement, not just a technical consideration,” said Fredrik Brynolf, Gateway Business Line Director at HMS Networks. “By making Anybus Communicators CRA ready, we help our customers reduce compliance effort and risk, while continuing to rely on a proven, industrial grade connectivity solutions.”

To strengthen long term security and lifecycle robustness, Anybus Communicators now include several key updates.

Hardware updates supporting long term security

Real time clock and supercapacitor - These ensure reliable timestamps for certificates, logs, and diagnostics, even during extended power off periods such as weekend shutdowns.

Dedicated security chip - Cryptographic keys and sensitive data are stored securely, enabling strong encryption and protection against tampering. Together, the real time clock with backup power and the security chip provide a stronger hardware foundation for secure operation and long term lifecycle support under CRA.

Software features aligned with CRA relevant security needs:

Secure configuration - Configuration access is protected using HTTPS, preventing man in the middle attacks during commissioning and maintenance. Certificates are user managed to support secure configuration in different environments.

Role based access control - Password protection is activated directly in the web user interface. Each device is delivered with a unique default Admin password, laser marked on the product during production and used for first time login.

Three standard roles are supported:

  • Admin – full access
  • User – slave network configuration
  • Operator – read only access

This ensures that configuration access matches operational responsibility.

Controlled updates and lifecycle protection.
The Anybus Communicator supports a controlled firmware lifecycle. On CRA ready devices with updated hardware, safeguards are in place to prevent downgrading to firmware versions released prior to the hardware update, ensuring that CRA relevant security capabilities are not removed.

Protection of intellectual property.
Machine builders and device makers can simplify configuration for end users and protect intellectual property by hiding Master configuration details.

Meeting customer requirements.

By integrating these hardware and software updates, the Anybus Communicator provides CRA ready connectivity out of the box. This helps device makers, machine builders, system integrators, and factory operators respond to growing cybersecurity, compliance, and purchasing requirements from customers.

Manufacturers and integrators can continue to rely on the Anybus Communicator for both industrial network connectivity and cybersecurity. Units in the field remain supported, while new units are delivered with CRA ready hardware and software, providing a clear, non disruptive path to meet CRA and customer cybersecurity requirements.

The company builds and maintains connectivity, security tooling, and compliance over the product lifecycle, so customers don’t have to. For many use cases, implementing an Anybus Communicator is the simplest, lowest effort way to meet CRA expectations while preserving uptime, performance, and market access.

CRA ready Anybus Communicators start shipping during spring 2026, approximately 1.5 years before the Cyber Resilience Act is enforced.


@hmsnetworks @HMSAnybus @ec.europa.eu @mepaxIntPR #PAuto #DigitalEU #Cybersecurity #Standards

Friday, 1 May 2026

Secure accreditation.

Palindrome Technologies has received full accreditation from the International Accreditation Service (IAS) and ANSI National Accreditation Board (ANAB) to serve as an ISO/IEC 17065 accredited certification body for the globally recognised certification program ISASecure®*.

"We are pleased to have Palindrome Technologies join the ISASecure program as an accredited ISASecure certification body,” said Dr. Mark P. DeAngelo, program manager of ISASecure®.

The ISASecure certification program validates conformance to the ISA/IEC 62443 series of internationally adopted standards for industrial security. Palindrome is now accepting product submittals for ISASecure certification.

ISASecure assesses automation and control products and systems to ensure they are robust against network attacks, free from known vulnerabilities and meet the security capabilities defined in the ISA/IEC 62443 standards. All ISASecure certifications are conducted by globally recognised ISO/IEC 17065 accredited certification bodies.

Palindrome Technologies is a cybersecurity research and testing firm, established in 2005, which provides security assurance services to Fortune 500 companies and growing organisations. Palindrome is an accredited ISO/IEC 17025 laboratory and can guide customers through product certifications including IEEE, NIST, HITRUST, HIPAA and now ISASecure SDLA, CSA, SSA and ICSA certification to ISA/IEC 62443 standard.

As an ISA Security Compliance Institute (ISCI) member, Palindrome has been involved in the technical development of ISASecure’s newest conformance scheme, the ISASecure Automation Control System Security Assurance (ACSSA) program. Palindrome staff were among the first to complete the ISASecure ACSSA for Evaluators training and certification.

“The ISASecure certification program gives product suppliers a clear, globally recognised path to demonstrate conformance to the ISA/IEC 62443 standard and provides asset owners greater confidence that the technologies they deploy are robust against real-world threats. Palindrome is proud to support this mission with rigorous, repeatable evaluations that help teams build security in from the start and differentiate trusted products in the marketplace,” said Mike Stauffer, vice president of product testing and certification at Palindrome Technologies.


* The ISASecure program — which currently has ISO/IEC 17065 accredited certification bodies in the U.S., Japan, Taiwan, Singapore, Italy, Germany and India — is rapidly expanding its global reach through additional agreements with certification bodies around the world. 

@PalindromeTech @ISA_Automation  @automation_com #ISA/IEC62443 #PAuto #Cybersecurity

Thursday, 30 April 2026

Cyber Resilience in Industry and OT.

A new technical guide explaining the Cyber Resilience Act (CRA), aimed at helping businesses understand what the regulation may mean in practice for industrial computing and networking projects has been published.

The new guide, from Impulse Embedded, outlines the purpose of the regulation, the types of products with digital elements it may affect when made available on the EU market, and the key dates businesses should be aware of as the CRA moves closer to full application.

It is aimed at readers involved in specifying, integrating and deploying connected industrial systems, including industrial PCs, embedded computers, industrial networking devices and related hardware. The guide also examines some of the practical issues the CRA may bring into sharper focus, such as product security information, vulnerability handling, support periods, technical documentation and lifecycle planning.

It also considers how IEC 62443-4-2 can support the assessment of industrial hardware in projects with higher cybersecurity expectations. While IEC 62443-4-2 is not the same as CRA conformity, it can provide a useful reference point when reviewing the security characteristics of products during earlier stages of selection.

Its publication comes at a time of growing industry interest in how the CRA may influence product evaluation and supplier expectations across industrial and OT environments, especially where long service lives, remote access requirements and ongoing supportability are important factors.

“The aim of this guide is to give readers a clear, practical introduction to the Cyber Resilience Act in the context of industrial computing and networking,” said Chris Durose, Head of Technology and R&D at Impulse Embedded. “There is a lot of discussion around the regulation, but many businesses are still working out what it may mean for product selection and project planning. We wanted to offer something straightforward, useful and relevant to real industrial applications.”


@ImpulseEmbedded  @EU_Commission @proactivefleet #DigitalEU #Cybersecurity #PAuto 

Cybersecurity certification achieved.

The PcVue platform from ARC Informatique has successfully achieved IEC 62443-4-2 SL2 certification, a key milestone in our cybersecurity strategy. Following their IEC 62443-4-1 certification, this new achievement confirms our commitment to secure our product. It places PcVue among a select group of solutions that meet the cybersecurity requirements for critical infrastructure.

Already certified under ISO 9001, ISO 14001 and ISO 27001, ARC Informatique continues to strengthen its governance model by integrating cybersecurity at every level.

While IEC 62443-4-1 focuses on secure development practices, IEC 62443-4-2 ensures that the components of the PcVue platform meet strict security requirements, addressing risks directly at the product level

For PcVue users and partners, this certification provides greater confidence by delivering a platform that is not only high performing, but also secure, trusted and resilient against evolving cyber threats.

"We remain committed to supporting operations with reliable and cyber-resilient solutions," said a statement from the company.


@arcinformatique @mepaxIntPR #PAuto #ISA62443 

Wednesday, 22 April 2026

Stringent security requirements confirmed.

The SEMI E187 certification has been received by Antaira Technologies. This certification confirms that Antaira’s industrial network switch solutions meet the stringent security requirements of modern manufacturing.

LtoR: Kelvin Yen, IT Director of SGS Cybersecurity Lab
& Frank Hou, Global CEO of Antaira
.
Kelvin Yen, IT Director of SGS Cybersecurity Lab and General Management Office, stated: "As the semiconductor industry’s cybersecurity requirements for equipment continue to escalate, SEMI E187 is emerging as a pivotal security benchmark for the global supply chain. Through third-party verification mechanisms, manufacturers can not only establish cybersecurity capabilities that earn market trust but also contribute to the security maturity of the entire industrial chain. SGS is honored to have assisted Antaira in completing this verification, as we work together to drive the implementation of these critical industry standards."

"Achieving SEMI E187 compliance is a testament to our ‘Resilience-first' engineering philosophy," said Frank Hou, CEO at Antaira Technologies. "We understand that in the semiconductor world, a single hour of downtime can cost millions. By securing the network layer, we are providing our partners with the hardened infrastructure they need to build with confidence."

In the fast-evolving world of semiconductor manufacturing, cybersecurity is a necessity for operational success. SEMI E187 is widely recognized as a key industry benchmark for equipment security, specifically focusing on how devices connect and communicate safely. By meeting these demanding requirements, Antaira provides a powerful defense for modern fabrication facilities through its certified industrial networking solutions. For fab operators, selecting SEMI E187-certified network devices represents a commitment to a secure networking backbone that safeguards sensitive data and maintains uninterrupted production.

Antaira’s SEMI E187-certified industrial Ethernet switches embed security at the architectural level and not as an add-on layer. By integrating SEMI E187 compliance directly into its core firmware development and lifecycle management processes, Antaira delivers a high-trust network environment where cybersecurity is intrinsic to every deployment within a semiconductor manufacturing facility.

Certified Antaira solutions feature:

  • Validated Endpoint Protection — Every connection point across the facility is authenticated and hardened against unauthorized access.
  • Secure-by-Default Configurations — Factory-default security postures eliminate misconfiguration vulnerabilities from initial deployment.
  • Proactive Vulnerability Management & Long-Term Support Roadmap — Structured security patching cycles ensure network defenses evolve in step with the threat landscape.

As the global semiconductor supply chain faces increasing scrutiny over cybersecurity posture and vendor accountability, Antaira’s adherence to this standard, as it is phased in across switch models, establishes a transparent, verifiable security baseline across the manufacturing ecosystem. For system integrators, OEM partners, and fab operators alike, Antaira-certified infrastructure is the foundation upon which resilient, future-proof semiconductor production is built.


@AntairaTech @SGS_SA @OConnell_PR #PAuto #Cybersecurity

Wednesday, 1 April 2026

Cybersecurity standard achieved.

ARC Informatique has successfully achieved ISA/IEC 62443-4-1 certification, a globally recognised cybersecurity standard for secure product development in industrial automation and control systems.

Already certified under ISO 9001, ISO 14001 and ISO 27001, ARC Informatique now elevates its governance model by reinforcing cybersecurity directly into its product development lifecycle.

While ISO 27001 ensures the protection of organisational information and processes, ISA/IEC 62443-4-1 specifically addresses secure product development requirements for critical infrastructure.

This certification marks a strategic evolution: embedding cybersecurity not only at the organisational level, but at the very core of PcVue platform engineering.

For PcVue users and partners, ISA/IEC 62443-4-1 certification delivers operational confidence by reducing cybersecurity risks. It accelerates system qualification and deployment while ensuring continuous protection through structured vulnerability management and timely security updates.The result is a platform built not only to perform, but to remain secure, trusted and cyber-resilient.

“Achieving IEC 62443-4-1 certification is an important milestone in the PcVue compliance strategy roadmap” said Mostapha ELANSALI, Head of quality and performances at ARC Informatique.

“It reflects our long-term commitment to supporting customers operating in critical and highly regulated environments, while continuously strengthening the security, reliability, and cyber-resilience of the PcVue platform.”


@arcinformatique @mepaxIntPR #PAuto #ISA62443

Wednesday, 25 March 2026

Major OT-Cybersecurity event programme.

Prague conference to include two breakfast forums and an expo, as well as many speaker sessions and training opportunities.

ISA's fourth annual OT Cybersecurity Summit
Prague (CZ) on 16-18 June 2026.
The ISA OT-Cybersecurity Summit will draw hundreds of experts in operational technology (OT) cybersecurity at the management level or higher in the energy, manufacturing, water/wastewater, oil and gas and maritime/transportation industries. This two-track, multi-day event will be organised around two major topics: threat intelligence in supply chain security and cyber-physical safety risk management. The keynote address will offer perspectives on transatlantic cyber cooperation from Berta Jarosova, cyber attachée to the United States and Canada for Czechia and co-founder of Women4Cyber Czechia.

Two breakfast forums — a new offering this year — will include thoughtful discussion panels with top cybersecurity experts. Those who attend these forums can expect to leave with practical insights on bridging IT and OT and turning cyber directives into actionable plans.

The Cyber Empowerment Forum features:

  • Megan Samford, VP, chief security officer, U.S. National Security Agreements and U.S. Federal Business, Schneider Electric
  • Berta Jarošová, cyber attachée to the United States and Canada, Embassy of the Czech Republic and co-founder of Women4Cyber Czechia
  • Dr. Marina Krotofil, independent expert evaluator and reviewer, European Commission
  • Cheri Caddy, senior cybersecurity advisor, Savannah River National Laboratory
  • Tatyana Bolton, principal, head of cyber practice, Monument Advocacy

The Countdown to Compliance Forum features:

  • Steve Mustard, president, au2mation
  • Ilja David, co-founder, IT/OT cybersecurity manager and architect, Iron OT
  • Gustav Martin Bartel, senior expert, cybersecurity industrial IT, Robert Bosch GmbH
  • Lukasz Kister, Ph.D., Cyber Resilience Act (CRA) Expert Group member, European Commission
  • Petr Kopřiva, senior consultant, BDO Consulting s.r.o.

This conference will continue to demonstrate how consensus standards and conformity assessment can meet the critical needs arising from current events and new regulation, including the EU Cyber Resilience Act (CRA). ISA sets many of the technical standards used in industrial automation, including ISA/IEC 62443, the world’s only consensus-based automation and control systems cybersecurity standards. In addition to developing and maintaining these standards, the organisation offers training and credentialing on cybersecurity; certifies products, processes and systems through its ISASecure® certification; and raises awareness about the importance of OT cybersecurity through its membership consortium, the ISA Global Cybersecurity Alliance (ISAGCA).

“The ISA community brings together many of the world’s top industrial cybersecurity experts, and we are proud to have developed ISA/IEC 62443, the standards that set the most secure operational technologies,” said Claire Fallon, CEO of ISA. “What sets apart the ISA OT Cybersecurity Summit is its focus on sharing real-world insight into ISA/IEC 62443 and effective approaches for putting those standards into practice.”

In addition to a robust technical program, the 2026 OT Cybersecurity Summit will offer multiple additional workshops, special events and industry-leading training opportunities for attendees:

  • Training: Using the ISA/IEC 62443 Standards to Secure Your Control Systems (IC32) and IACS Cybersecurity Design and Implementation (IC34)
  • Incident Command Systems for Industrial Control Systems (ICS4ICS) workshop: A tutorial for ICS4ICS, which combines OT/ICS, incident command and cybersecurity work into one framework to improve cyber incident response capabilities at companies and organisations.

Early-bird registration for the 2026 OT Cybersecurity Summit in Prague is now open at a reduced price until 17 April 2026, at which point standard pricing will take effect. Early-bird tickets to the breakfast forums and expo start at $125,00US (€108,00) Early-bird tickets to the conference — including the breakfast forums and expo in addition to networking receptions and program stages — start at $940,00US (€810,00) for ISA members.


@ISA_Automation @DigitalEU  @automation_com #CRA #PAuto #Europe

Wednesday, 11 March 2026

Cyber resilience in European industry.

Strengthening industrial automation in OT environments by monitoring and tracking vulnerabilities across software supply chains.

The European research and innovation project ENFORCERS (Enhanced Cooperation for Cybersecurity)* has officially started, bringing together a strong consortium of industrial manufacturers and cybersecurity technology providers, supported by applied research organisations to address one of Europe’s most pressing challenges: ensuring resilient, trustworthy software throughout the lifecycle of industrial automation systems.

Consortium partners at the ENFORCERS project kickoff meeting, February 2026

The project’s official kickoff took place during February 2026 at WIBU-SYSTEMS AG in Karlsruhe (D), where consortium partners met in person for the first time to align on the strategic roadmap for the coming three years. The meeting marked the operational starting point of ENFORCERS and set the stage for close cross-border collaboration enabled by EU funding.

From incident detection to secure recovery: closing the cybersecurity loop.
ENFORCERS is designed to go beyond isolated security measures. Its central objective is to close the loop between cybersecurity incident detection, coordinated response, certification, and secure software redistribution in industrial environments. This is particularly relevant for automation and manufacturing, where software must often be updated across segmented, partially disconnected, or heterogeneous Operational Technology (OT) networks.

At the heart of the project is a Cybersecurity System Platform that links multiple trusted instances into a securely chained “system circle.” This includes:

  • Private Security Operation Centers (SOCs) that collect, correlate, and classify incident and vulnerability data,
  • Secure Elements that act as trust anchors at OT edges and gateways,
  • Automated playbooks for vulnerability mitigation, certification, and secure software updates,
  • and cross-border data exchange mechanisms that allow SOCs and stakeholders to cooperate while respecting data sovereignty.

The technical approach directly supports compliance with NIS2 and anticipates requirements of the Cyber Resilience Act, while remaining adaptable to future regulatory and technological developments.

“ENFORCERS brings together technologies, processes, and stakeholders into an operational cybersecurity framework,” explained Alvaro Forero, Project Coordinator at WIBU-SYSTEMS AG. “As coordinator, our responsibility is to ensure that we are building a cooperative system where incident handling, trust anchors, and secure software deployment work together across organisational and national boundaries. The kickoff meeting confirmed a shared understanding that cybersecurity resilience must be engineered into the full lifecycle of industrial software.”

Clearly defined roles across a strong European consortium.
ENFORCERS brings together partners with complementary expertise across Europe. As project coordinator, Wibu-Systems contributes its long-standing expertise in software protection, licensing, and secure update mechanisms for industrial environments, while ensuring technical coherence and cross-partner integration across the project. Industrial companies such as Balluff (Germany and Hungary), Schneider Electric (France), TTTECH Computertechnik (Austria), and Technology Nexus Secured Business Solutions (Sweden) contribute real-world requirements from automation, manufacturing, and industrial networking. Technology and cybersecurity specialists including Infineon Technologies (Germany), Langlauf Security Automation (Germany), DYNAMIKI (Greece), AITAD (Germany), and ResilTech (Italy) provide expertise ranging from AI and embedded systems to secure elements and cryptography to SOC operations and incident response. Applied research is supported by subcontractors such as Fraunhofer SIT, while VDMA contributes its industrial network and policy interface.

From a partner perspective, the project is also seen as a commitment to European cooperation.

“At ResilTech, we look forward to contributing with full commitment and to working alongside such high-level partners to strengthen Europe’s industrial cybersecurity,” said Francesco Brancati, Security Solution Manager and R&D Program Manager at ResilTech Srl, underlining the importance of cross-border collaboration as a prerequisite for resilient industrial systems.

The project effectively integrates three essential layers of work, ranging from structural activities such as system requirements and architecture design, through practical implementation efforts including SOC integration, digital elements, and secure connectors, to quality-oriented tasks focused on dissemination, standards compliance monitoring and training.

Early milestones include the definition of legal and technical requirements, the design of the Cybersec System architecture, and the setup of initial SOC and platform components, followed by demonstrators and validation in later phases.

Industrial partners see ENFORCERS as a strategic investment in long-term resilience. Dr. Markus Jung, VP Engineering at Balluff GmbH emphasised during the project launch, “ENFORCERS is a great opportunity for Balluff to build a strong network with leading partners in the cybersecurity domain. The project will support us in further strengthening our cybersecurity measures and enhancing best practices across our industrial automation products, processes, and manufacturing sites. The strong consortium enables us to anticipate emerging trends in the coming years, well beyond the requirements of the Cyber Resilience Act, and ultimately helps us empower our customers to increase their own cybersecurity.”

Over the next three years, ENFORCERS will deliver technical demonstrators, best practices, training activities, and contributions to standardisation and certification discussions. By combining industrial deployment experience with cybersecurity expertise, the project aims to create results that are replicable across sectors and that strengthen Europe’s digital sovereignty in industrial software and automation.


* Co-funded by the European Union, under the Grant Agreement No. 101249745, the project is supported by the European Cybersecurity Competence Centre (ECCC). Views and opinions expressed here do not necessarily reflect those of the European Union or the European Cybersecurity Competence Centre.

Additional Dedicated Resource: R&D project dedicated web page.

@WibuSystems  @Balluff #Cybersecurity #PAuto



Tuesday, 10 March 2026

Information security.

As scientific collaboration becomes increasingly digital and globally interconnected, amid rising cybersecurity threats and evolving AI-driven risks, biopharmaceutical companies are demanding more robust data protection protocols from outsourcing partners.

Symeres has been awarded ISO/IEC 27001 certification, the internationally recognised standard for information security management systems (ISMS). This certification reinforces the company’s proactive commitment to safeguarding sensitive client data across its global operations.

Gabriella Gentile
“Cybersecurity is no longer a back-office issue; it is central to the success of every client program,” said Gabriella Gentile, Chief Operating Officer at Symeres. “Our ISO 27001 certification gives clients, from biotech startups to large pharmaceutical companies, the assurance that their proprietary data, often the ‘crown jewels’ of development, is protected within a robust and continuously improving security framework.”

While Symeres has long operated with strong internal protocols, the decision to pursue formal certification arose from a rising volume of security questionnaires from clients, financial institutions, and regulators.

For many large pharmaceutical companies, information security assessments are now a standard part of onboarding. ISO 27001 certification allows Symeres to address the majority of these requirements upfront, significantly streamlining due diligence processes. By reducing administrative friction, project teams can focus more quickly on what matters most: advancing client programs and delivering scientific impact.

“This journey began two years ago as part of our continuous improvement culture,” added Mark Verhaar, Project Manager at Symeres. “We identified our highest information risk areas, developed risk-based policies, and created a formal, auditable system for managing access, backups, and incident response. It’s not just about compliance, it’s about building a culture of vigilance and continuous improvement, ensuring that our security practices evolve alongside the scientific and digital complexity of our clients’ programs.”

Symeres is well-positioned to support the needs of both established pharmaceutical clients and smaller biotechs that may rely on its expertise to navigate complex data governance now that ISO 2700 is in place. The certification also supports broader industry compliance efforts, including the EU’s NIS2 Directive, which identifies healthcare organizations as vital operators.

Key elements of Symeres’s information security framework include:

  • Formalised, audited policies for data access, backup, and breach response
  • Continuous employee awareness programs to mitigate human error
  • Controlled information sharing protocols with third-party partners and clients
  • Ongoing internal audits and yearly external surveillance to maintain certification

The company is progressing with the rollout of ISO 27001 certification across its sites globally, with completion targeted before the end of the year. This phased implementation ensures consistent standards across the Group while maintaining operational continuity.

As cyber threats grow more sophisticated, maintaining high security standards will remain a priority. Guillaume Jetten, Chief Executive Officer at Symeres, commented: “In today’s environment, ISO 27001 is a non-negotiable foundation for doing business with large pharmaceutical companies and innovative biotechs. Achieving this certification cements Symeres’ status as a leading global CDMOs operating with full transparency and accountability.”


#symeres #Pharma #CyberSecurity 

Friday, 20 February 2026

Industrial communications' Cyber resilience.

The EU Cyber Resilience Act (CRA) will require all manufacturers of products with digital elements to implement comprehensive security measures starting in December 2027. After thoroughly reviewing its technologies, PI has come to the following conclusion: PROFINET already provides the basis for CRA compliance today. Manufacturers can use existing installations and expand them step by step depending on their risk assessment. The PROFINET specification provides additional building blocks for extended security requirements.

“The CRA requirements pose major challenges for companies,” says PI Chairman Xaver Schmidt. “Our analysis shows that manufacturers who rely on PROFINET already have a solid basis for CRA compliance today. If higher security requirements are needed, manufacturers can gradually expand their products with PROFINET security features in the future – from authenticated secure communication to complete encryption.”

It requires manufacturers to assess the cybersecurity risks of their products. In doing so, they analyze possible attack scenarios and evaluate the necessary protection for industrial communication. Depending on the risk assessment, manufacturers can implement individual or multiple building blocks from the PROFINET security architecture to meet the CRA requirements for secure communication:

Secure Cell:
Network segmentation and access control (cell protection concept) can already be implemented with today’s PROFINET installations. Additional hardening measures are available with the PROFINET specification V2.5.

Secure Access:
Direct, secure access to devices from higher-level networks for applications ranging from asset management to artificial intelligence.

Secure Realtime:
Integrity, authentication and, if required, confidentiality through cryptographic protection of acyclic and cyclic real-time communication for critical infrastructures.

The Secure Access and Secure Realtime building blocks are described in the PROFINET specification V2.5, which will be published in mid-2026.

“Cybersecurity is not a one-size-fits-all approach but must be scalable – from small standalone machines to installations spread over kilometers,” says Schmidt. “The PROFINET architecture covers the entire spectrum: from network segmentation to cryptographically secured real-time communication – all while maintaining consistent performance. The key point is that many manufacturers can use their existing PROFINET installations as a basis and expand them as needed. This enables the CRA to be implemented in line with requirements without compromising data access.”

PI is developing the PROFINET specification in close cooperation with TÜV SÜD, based on the IEC 62443 industry standard.


• See also CiA Statement on European CRA (16/2/2026)

@AllThingsPROFI #DigitalEU #Cybersecurity #Standards