As of June 15, 2022, this site no longer supports Internet Explorer. Please use another browser for the best experience on our site.
Share

CRA Countdown: Assess Your OT Supply Chain's Cybersecurity Early

Sep 01, 2026
You can manage and share your saved list in My Moxa
Teaser Image
Share
You can manage and share your saved list in My Moxa

Imagine you have built an expensive automated production line, only to discover that the components with digital elements cannot meet the Cyber Resilience Act (CRA) cybersecurity requirements. The result? Costly redesigns, delayed market entry, or even the redesign of the system.

As the CRA countdown continues, many system integrators (SIs) and end users are still on the sidelines. The prevailing mindset is: "The CRA harmonized standards are not finalized—we will deal with supplier requirements once they are clear."

The reality: The CRA becomes enforceable in December 2027, leaving only about one year between standard finalization and enforcement.

For consumer electronics, one year may be enough. However, one year may not be enough for OT systems, given their focus on stability, longevity, and intricate interdependencies. The real risk is this: Will the equipment you buy and deploy today be ready for seamless CRA compliance? You might face production halts, unexpected replacement expenses, or an inability to place your products for sale in Europe if you find compliance gaps late in 2026. 

What’s more, checklists for static compliance are losing relevance. A more practical strategy involves proactively assessing “cybersecurity fitness” with your suppliers, rather than passively awaiting the final standards in 2026.

As a leader in industrial connectivity OT cybersecurity, we are sharing our evolving standards to help SIs and end users get ready. We suggest  three key criteria for assessing a supplier's readiness for future compliance:

  1. Secure development process
  2. Product security requirements, and
  3. Vulnerability management

These criteria are based on existing international standards and published EU drafts.

1: Is a secure development process in the supplier's DNA?

Corresponding to CRA Annex I Part I., forward-thinking manufacturers embed Secure by Design rather than adding it to completed products. 

A key question when evaluating equipment is whether the vendor possesses IEC 62443-4-1 certification, indicating that OT security is a core consideration in their approach to requirements, architecture, development, testing, version control, and life cycle management. Check whether your supplier is aware of and reviewing the public drafts of EN IEC 62443-4-1:2018/prAA:2026 and prEN 40000-1-2. This shows a supplier’s commitment to aligning secure development processes with the EU’s technical documentation and evidence requirements. Another important indicator is the maturity of the secure development life cycle. Maturity Level 3, for instance, signifies that the manufacturer has embedded security management into their fundamental business operations, ensuring a uniform security standard across product lines.

2: Does the product itself meet product security requirements?

Also referencing CRA Annex I Part I, IEC 62443-4-2 provides a practical method for assessing core security functions—identification and authentication, access control, system integrity, data protection, security event logging, and firmware protection—when performing system acceptance or vendor selection.

We also recommend closely monitoring two emerging standards for product security specifications: prEN 40000-1-4 and EN IEC 62443-4-2:2019/prAA:2026. These emerging EU standards provide more detailed guidance on how to systematically verify whether a product meets the required security functions. As a result, they raise expectations for OT manufacturers’ compliance validation capabilities and preparedness. 

The CRA is also driving the development of vertical standards for products with specific functions, including the EN 50770 Series for OT products. Does your vendor have all its products mapped to the CRA Product Categories and the applicable vertical standards?

3: Vulnerability management is the long-term test

Once a system is live, a zero-day vulnerability without a vendor patch is a bad scenario. Vulnerability management as described in CRA Annex I Part II is the ongoing ability to handle vulnerabilities through receipt, analysis, remediation, and disclosure, along with at least five years of support. To ensure customers get vulnerability and update information for quick reactions and prevention, the CRA also demands public security advisories.

When choosing partners, verify that the supplier has implemented internal vulnerability handling procedures according to ISO/IEC 30111 and a clear, coordinated vulnerability disclosure system as per ISO/IEC 29147. A reliable supplier monitors public draft standards, such as prEN 40000-1-3, to align with EU expectations for reporting and documentation, ensuring it can provide prompt support to integrators and operators during security incidents.

The Time to Assess Suppliers Is Now

To summarize, what integrators and end users will require is the translation of regulatory requirements into supplier criteria, rather than another temporary paper checklist.The time remaining before enforcement at the end of 2027 is not a waiting period; it is when the supply chain separates the strong from the weak. The earlier you assess your equipment suppliers against existing standards and public drafts, the better positioned you are to turn cybersecurity into market access and trusted competitiveness for your system integration solutions.

Related Standards Overview

Standard Full Title Status

Reference Links

IEC 62443-4-1:2018 Security for industrial automation and control systems—Part 4-1: Secure product development lifecycle requirements Published IEC Webstore
EN IEC 62443-4-1:2018/prAA:2026 Security for industrial automation and control systems—Part 4-1: Secure product development life-cycle requirements (CRA harmonization amendment) Public draft iTeh Standards
IEC 62443-4-2:2019 Security for industrial automation and control systems—Part 4-2: Technical security requirements for IACS components Published IEC Webstore
EN IEC 62443-4-2:2019/prAA:2026 Security for industrial automation and control systems—Part 4-2: Technical security requirements for IACS components (CRA harmonization amendment) Public Draft iTeh Standards
ISO/IEC 30111:2019 Information technology—Security techniques—Vulnerability handling processes Published ISO
ISO/IEC 29147:2018 Information technology—Security techniques—Vulnerability disclosure Published ISO
prEN 40000-1-2 Cybersecurity requirements for products with digital elements—Part 1-2: Principles, product risk management, and life-cycle activities Public draft (enquiry closed; approval stage) iTeh Standards
prEN 40000-1-3 Cybersecurity requirements for products with digital elements—Part 1-3: Vulnerability handling Public draft (enquiry closed; approval stage) iTeh Standards
prEN 40000-1-4 Cybersecurity requirements for products with digital elements—Part 1-4: Generic security requirements (provisional title) Public draft (public enquiry ongoing) CEN-CENELEC
prEN 50770-1 Security for OT—Part 1: Security profile for firewalls and intrusion detection and prevention systems Drafting (pre-enquiry) CEN-CENELEC
prEN 50770-2 Security for OT—Part 2: Security profile for network management systems Drafting (pre-enquiry) CEN-CENELEC
prEN 50770-3 Security for OT—Part 3: Security profile for physical and virtual network interfaces Drafting (pre-enquiry) CEN-CENELEC
prEN 50770-4 Security for OT—Part 4: Security profile for products with digital elements with the function of virtual private network Drafting (pre-enquiry) CEN-CENELEC
prEN 50770-5 Security for OT—Part 5: Security profile for routers, modems intended for connection to the internet, and switches Drafting (pre-enquiry) CEN-CENELEC
prEN 50770-6 Security for OT—Part 6: Security profile for security Information and event management (SIEM) systems Drafting (pre-enquiry) CEN-CENELEC

Note: At the time of writing, EN IEC 62443-4-1:2018/prAA:2026, EN IEC 62443-4-2:2019/prAA:2026, the prEN 40000 Series, and the prEN 50770 Series remain at the drafting or public-enquiry stage. Official titles, scope, and final applicability are subject to change.

More Articles

Added To Bag
You have some items waiting in your bag; click here to finish your quote!
Feedback