News & Articles Articles

Cyber Resilience Act: Be prepared together.  

FeliPorath 05 October 2026 min. read
19 views 0 comments LoadingSave
Articles

Cyber Resilience Act: Be prepared together.  

Cyber Resilience Act: Be prepared together.  
Cyber Resilience Act: Be prepared together.  

With the Cyber Resilience Act (CRA), the European Union is introducing mandatory cybersecurity requirements for products with digital elements. From December 11, 2027, affected products must comply with the CRA requirements. The CRA considers the entire product life cycle and sets out specific requirements for development, vulnerability management, and documentation. To mark this year’s Cybersecurity Awareness Month, we are therefore taking a closer look: What does the CRA actually mean for the selection and integration of components? After all, cybersecurity does not end at the boundaries of your own product. Anyone looking to develop secure and CRA-compliant products must also keep an eye on dependencies, components, and software.

Cybersecurity is a matter for the entire supply chain

Today, industrial products rarely consist exclusively of components developed in-house. Semiconductors, communication modules, software libraries, open-source components, or complete assemblies can all be part of a solution. For manufacturers, this means that the cybersecurity of the end product also depends on which components are used and how they are integrated into the overall system. The key question is therefore not simply whether a component is “secure” in itself. Rather, it must be suitable for its specific intended use and capable of being securely integrated into the end product. This makes the selection of suitable components and reliable suppliers an important part of a company’s own cybersecurity strategy. 

The right component for the right application

A component may meet high security standards and still not be suitable for every application scenario. The decisive factor is therefore whether its security characteristics match the intended use and the security concept of the overall system. IEC 62443, among other standards, provides guidance in this regard. It addresses the different roles of manufacturers, integrators, and operators and defines requirements for areas such as secure development processes and the technical security characteristics of components. Transparency and documentation are equally important. Manufacturers need information about the intended purpose and potential risks, as well as guidance on secure integration and operation.  

Only with this information is it possible to make a sound assessment of whether a component fits the company’s own security concept. 

Security by Design: Security starts with development

Cybersecurity is difficult to integrate into a product after the fact. That is why it should be an integral part of product development from the outset. This is precisely where the Security-by-Design approach comes in: Security is taken into account as early as the development of hardware and software. At Phoenix Contact, this approach has been firmly established in the development process for many years. Our development process has been certified in accordance with IEC 62443-4-1 since 2018.

Cybersecurity does not end with delivery

Products and machines are often in use for many years. New vulnerabilities can therefore become known long after development has been completed. It is therefore important to consider security throughout the entire product life cycle. This includes structured processes for identifying and analyzing vulnerabilities, as well as providing information about confirmed vulnerabilities and appropriate measures. This is exactly the purpose of the Product Security Incident Response Team (PSIRT) at Phoenix Contact. It identifies and analyzes security vulnerabilities, coordinates the product experts involved, and publishes security advisories. For users, this means that security is considered not only during development, but also throughout the rest of the product life cycle. 

PSIRT by Phoenix Contact

CRA-ready: Make decisions today, plan for tomorrow

This long-term perspective is also crucial for investment decisions. December 11, 2027, may still seem a long way off. However, machines and systems developed today may remain in use well beyond this date. Components selected today must therefore fit into a strategy that also takes future CRA requirements into account. This raises a very practical question today: Which products can I plan to use for my future machines and systems? To provide guidance at an early stage, we label corresponding products in the E-Shop with the “CRA-ready” icon. The label indicates which products are being prepared for the requirements of the Cyber Resilience Act, thereby providing transparency for today’s investment and development decisions.  

Conclusion

The Cyber Resilience Act strengthens cybersecurity throughout the entire value chain. In the future, manufacturers will not only have to secure their own products, but also systematically assess and document the risks associated with integrated components. Transparency, secure development processes, and long-term security support will therefore become key success factors. 

Would you like to take a holistic approach to cybersecurity or do you have specific questions about the Cyber Resilience Act? With our 360° security concept, we support you in considering security from the outset and embedding it throughout the entire life cycle. You can find more information on our website: www.phoenixcontact.com/cybersecurity  

19 views 0 comments LoadingSave

Discussion

Please login/register to comment

Login/Register

Leave a Reply

Newsletter
Never miss a new article
Sign up for the newsletter
Never miss news about PLCnext Technology
Get interesting content via newsletter four times a year
Receive exclusive information before all other users