Imagine you have built an expensive automated production line, only to discover that the components with digital elements cannot meet the Cyber Resilience Act (CRA) cybersecurity requirements. The result? Costly redesigns, delayed market entry, or even the redesign of the system.
As the CRA countdown continues, many system integrators (SIs) and end users are still on the sidelines. The prevailing mindset is: "The CRA harmonized standards are not finalized—we will deal with supplier requirements once they are clear."
The reality: The CRA becomes enforceable in December 2027, leaving only about one year between standard finalization and enforcement.
For consumer electronics, one year may be enough. However, one year may not be enough for OT systems, given their focus on stability, longevity, and intricate interdependencies. The real risk is this: Will the equipment you buy and deploy today be ready for seamless CRA compliance? You might face production halts, unexpected replacement expenses, or an inability to place your products for sale in Europe if you find compliance gaps late in 2026.
What’s more, checklists for static compliance are losing relevance. A more practical strategy involves proactively assessing “cybersecurity fitness” with your suppliers, rather than passively awaiting the final standards in 2026.
As a leader in industrial connectivity OT cybersecurity, we are sharing our evolving standards to help SIs and end users get ready. We suggest three key criteria for assessing a supplier's readiness for future compliance:
- Secure development process
- Product security requirements, and
- Vulnerability management
These criteria are based on existing international standards and published EU drafts.
1: Is a secure development process in the supplier's DNA?
Corresponding to CRA Annex I Part I., forward-thinking manufacturers embed Secure by Design rather than adding it to completed products.
A key question when evaluating equipment is whether the vendor possesses IEC 62443-4-1 certification, indicating that OT security is a core consideration in their approach to requirements, architecture, development, testing, version control, and life cycle management. Check whether your supplier is aware of and reviewing the public drafts of EN IEC 62443-4-1:2018/prAA:2026 and prEN 40000-1-2. This shows a supplier’s commitment to aligning secure development processes with the EU’s technical documentation and evidence requirements. Another important indicator is the maturity of the secure development life cycle. Maturity Level 3, for instance, signifies that the manufacturer has embedded security management into their fundamental business operations, ensuring a uniform security standard across product lines.
2: Does the product itself meet product security requirements?
Also referencing CRA Annex I Part I, IEC 62443-4-2 provides a practical method for assessing core security functions—identification and authentication, access control, system integrity, data protection, security event logging, and firmware protection—when performing system acceptance or vendor selection.
We also recommend closely monitoring two emerging standards for product security specifications: prEN 40000-1-4 and EN IEC 62443-4-2:2019/prAA:2026. These emerging EU standards provide more detailed guidance on how to systematically verify whether a product meets the required security functions. As a result, they raise expectations for OT manufacturers’ compliance validation capabilities and preparedness.
The CRA is also driving the development of vertical standards for products with specific functions, including the EN 50770 Series for OT products. Does your vendor have all its products mapped to the CRA Product Categories and the applicable vertical standards?
3: Vulnerability management is the long-term test
Once a system is live, a zero-day vulnerability without a vendor patch is a bad scenario. Vulnerability management as described in CRA Annex I Part II is the ongoing ability to handle vulnerabilities through receipt, analysis, remediation, and disclosure, along with at least five years of support. To ensure customers get vulnerability and update information for quick reactions and prevention, the CRA also demands public security advisories.
When choosing partners, verify that the supplier has implemented internal vulnerability handling procedures according to ISO/IEC 30111 and a clear, coordinated vulnerability disclosure system as per ISO/IEC 29147. A reliable supplier monitors public draft standards, such as prEN 40000-1-3, to align with EU expectations for reporting and documentation, ensuring it can provide prompt support to integrators and operators during security incidents.
The Time to Assess Suppliers Is Now
To summarize, what integrators and end users will require is the translation of regulatory requirements into supplier criteria, rather than another temporary paper checklist.The time remaining before enforcement at the end of 2027 is not a waiting period; it is when the supply chain separates the strong from the weak. The earlier you assess your equipment suppliers against existing standards and public drafts, the better positioned you are to turn cybersecurity into market access and trusted competitiveness for your system integration solutions.
Related Standards Overview
| Standard |
Full Title |
Status |
Reference Links
|
| IEC 62443-4-1:2018 |
Security for industrial automation and control systems—Part 4-1: Secure product development lifecycle requirements |
Published |
IEC Webstore |
| EN IEC 62443-4-1:2018/prAA:2026 |
Security for industrial automation and control systems—Part 4-1: Secure product development life-cycle requirements (CRA harmonization amendment) |
Public draft |
iTeh Standards |
| IEC 62443-4-2:2019 |
Security for industrial automation and control systems—Part 4-2: Technical security requirements for IACS components |
Published |
IEC Webstore |
| EN IEC 62443-4-2:2019/prAA:2026 |
Security for industrial automation and control systems—Part 4-2: Technical security requirements for IACS components (CRA harmonization amendment) |
Public Draft |
iTeh Standards |
| ISO/IEC 30111:2019 |
Information technology—Security techniques—Vulnerability handling processes |
Published |
ISO |
| ISO/IEC 29147:2018 |
Information technology—Security techniques—Vulnerability disclosure |
Published |
ISO |
| prEN 40000-1-2 |
Cybersecurity requirements for products with digital elements—Part 1-2: Principles, product risk management, and life-cycle activities |
Public draft (enquiry closed; approval stage) |
iTeh Standards |
| prEN 40000-1-3 |
Cybersecurity requirements for products with digital elements—Part 1-3: Vulnerability handling |
Public draft (enquiry closed; approval stage) |
iTeh Standards |
| prEN 40000-1-4 |
Cybersecurity requirements for products with digital elements—Part 1-4: Generic security requirements (provisional title) |
Public draft (public enquiry ongoing) |
CEN-CENELEC |
| prEN 50770-1 |
Security for OT—Part 1: Security profile for firewalls and intrusion detection and prevention systems |
Drafting (pre-enquiry) |
CEN-CENELEC |
| prEN 50770-2 |
Security for OT—Part 2: Security profile for network management systems |
Drafting (pre-enquiry) |
CEN-CENELEC |
| prEN 50770-3 |
Security for OT—Part 3: Security profile for physical and virtual network interfaces |
Drafting (pre-enquiry) |
CEN-CENELEC |
| prEN 50770-4 |
Security for OT—Part 4: Security profile for products with digital elements with the function of virtual private network |
Drafting (pre-enquiry) |
CEN-CENELEC |
| prEN 50770-5 |
Security for OT—Part 5: Security profile for routers, modems intended for connection to the internet, and switches |
Drafting (pre-enquiry) |
CEN-CENELEC |
| prEN 50770-6 |
Security for OT—Part 6: Security profile for security Information and event management (SIEM) systems |
Drafting (pre-enquiry) |
CEN-CENELEC |
Note: At the time of writing, EN IEC 62443-4-1:2018/prAA:2026, EN IEC 62443-4-2:2019/prAA:2026, the prEN 40000 Series, and the prEN 50770 Series remain at the drafting or public-enquiry stage. Official titles, scope, and final applicability are subject to change.