With the Cyber Resilience Act (CRA) coming into full effect since December 2024, new regulatory demands for industrial products with digital components have been established.
Companies now face the challenge of systematically incorporating cybersecurity throughout every phase of the product lifecycle. At MB connect line, this is seen as a reaffirmation of their longstanding practices in IT security.
Security by Design and Default
MB connect line, a provider of industrial remote access and networking solutions, embraces Security by Design and Security by Default as part of their core operations. They treat security not as an isolated feature, but as a comprehensive and transparent approach, ingrained in their architectural strategies including controlled communication channels and segmented networks.
Long before the CRA's regulatory framework was established, MB connect line had been integrating essential cybersecurity measures into each stage of their product development process. Their certified Information Security Management System (ISMS), compliant with ISO/IEC 27001:2022 since March 2026, underpins their strategy. It encompasses risk management, incident processes, and supplier chain aspects.
Certified Development Processes
Their adherence to industry standards is affirmed by the IEC 62443-4-1 certification since 2024
Their adherence to industry standards is affirmed by the IEC 62443-4-1 certification since 2024, ensuring the secure and accountable development of digital products. Furthermore, preparations for product certifications under IEC 62443-4-2 are underway for new hardware platforms expected in mid-2026. These measures aim to demonstrate robust compliance with the CRA's requirements.
MB connect line employs established security techniques across their product lineup, including secure booting, firmware encryption, role-based access controls, and network segmentation. Key elements like controlled communication paths and logging features are utilized to minimize vulnerabilities and maintain secure default configurations.
Ongoing Regulatory Adaptation
The implementation of the CRA is perceived by MB connect line as an ongoing process rather than a singular compliance task. They continue to develop and refine processes, aiming to meet future standards while enhancing technical validations and security measures. This long-term strategy includes expanding lifecycle management and refining their security architecture.
It's crucial to note that the CRA’s focus on products with digital elements shifts responsibility to integrators when these components become part of larger systems. Guidelines from MB connect line assist manufacturers and OEMs in secure product integration, configuration, and operation, emphasizing shared responsibility in line with the IEC 62443 standards.
Confirming their preparedness, MB connect line regards cybersecurity as a fundamental aspect of their product development and operational strategies, rather than a mere marketing tool. CTO Alexander Kamm emphasized this commitment, stating, "At MB connect line, cybersecurity is not just a marketing promise, but an integral part of our daily work."
European regulation regarding cybersecurity in industrial products is gaining momentum: The Cyber Resilience Act (CRA) has been in effect since December 2024 and establishes mandatory requirements for products with digital components.
For companies, this means not only new regulatory requirements but also the need to systematically integrate cybersecurity throughout the entire product lifecycle.
Controlled communication channels
For them at MB connect line, this approach is not a paradigm shift, but rather the logical continuation of an already established understanding of IT security. As a manufacturer of industrial remote access and networking solutions, they view the CRA as confirmation of a path they have been pursuing for years, both technically and organizationally: Security by Design and Security by Default.
For them, security is not a single feature, but a transparent, systematic, holistic concept. Security must be approached from an architectural perspective – from controlled communication channels and segmented networks to clearly defined operational and lifecycle processes.
Entire product lifecycle
The CRA emphasises regulatory requirements that MB connect line has already been incorporating into its product development and business processes for years. This includes, in particular, the understanding that cybersecurity does not end with the delivery of a device, but must be actively managed throughout the entire product lifecycle.
Their Information Security Management System (ISMS), which has been certified to ISO/IEC 27001:2022 since March 2026, serves as an important foundation. It ensures that key organizational requirements – such as risk and countermeasure management, vulnerability and incident management processes, backup and recovery processes, roles and responsibilities, and supply chain aspects – are structurally embedded.
Risk-mitigating development
MB connect line also relies on established industry standards at the development level. The development process for new products has been certified according to IEC 62443-4-1 since 2024. The goal is to ensure the secure, traceable, and risk-mitigating development of digital products.
In addition, the company is preparing product certifications in accordance with IEC 62443-4-2 for the new hardware platforms (scheduled for release in mid-2026) and is already taking into account the additional requirements arising from the Cyber Resilience Act and related standards. The goal is to ensure that regulatory compliance can be demonstrated comprehensively and robustly.
Segmented network architectures
From a technical standpoint, we rely on a wide range of established security mechanisms in both current and new product generations. These include, among other things, secure boot and firmware concepts, signed and encrypted updates, role-based access controls, and segmented network architectures.
The security concept also includes controlled communication paths based on the “least privilege” principle, as well as logging and traceability features to meet audit and operational requirements. The goal is to reduce the attack surface, provide secure default configurations, and ensure that implemented measures are documented in a traceable manner.
Developing new platforms
For MB connect line, the CRA is not a one-time compliance task, but rather a multi-year development process. The organizational and technical foundations have already been laid in recent years. This includes establishing certified processes and developing new platforms that take future regulatory requirements into account.
In the coming years, they will continue to expand our technical validation, documentation, and lifecycle and vulnerability management in particular. At the same time, they will carry out product certifications and continuously refine their security concepts.
Providing security guidelines
At the same time, they would like to highlight an important point: The Cyber Resilience Act primarily addresses individual products with digital elements. When components are assembled into new products – for example, in machinery or plant systems—the integrator typically becomes the manufacturer under the CRA and thus assumes responsibility for the conformity of the resulting product.
Where other EU regulations (such as the Machinery Regulation (EU) 2023/1230) stipulate their own cybersecurity requirements, Article 2 of the CRA governs the relationship between these regulatory frameworks. For practical implementation, the IEC 62443 series of standards is also recommended.
Secure integration, configuration, and operation remain a shared responsibility of manufacturers, OEMs, and operators. To support the customers in this regard, they at MB connect line provide security guidelines, architectural examples, and technical documentation.
Verifiable component of development
With regard to the Cyber Resilience Act, they consider themselves very well prepared.
For MB, the regulatory framework confirms an approach they have been following for years: cybersecurity as a verifiable component of development, operations, and product maintenance -implemented in a traceable manner throughout the entire lifecycle. “At MB connect line, cybersecurity is not just a marketing promise, but an integral part of our daily work,” said CTO Alexander Kamm.