
The EU CRA and OEMs
How can industrial device OEMs comply with the new EU CRA and its requirements for digital devices sent to the European market? In this episode of OT After Hours, Ken Kully (Delivery Readiness at Rockwell Automation) is joined by Lance Lamont (Special Projects & Protocols Team Lead at Rockwell Automation), Tyler Bergman (Principal Security Consultant at Rockwell Automation), Zach Woltjer (Technical Account Manager), and by special guests Maria Else (Global Product Manager for Industrial Cybersecurity) and Stefan Turi (EMEA Cybersecurity Lead for OEMs) to discuss the EU Cyber Resilience Act (CRA), its implications for industrial device original equipment manufacturers (OEMs), and how the SecureOT™ solution suite can help drive both compliance and security in response. Key Takeaways EU Cyber Resilience Act Scope: The CRA applies broadly to products with digital elements placed on the EU market, including industrial machines. These responsibilities extend across manufacturers, OEMs, system integrators, importers, distributors, and end users. OEM Compliance And Product Lifecycle: CRA obligations include having a secure-by-design processes, vulnerability handling, documentation, risk analysis, and support throughout the product lifecycle. OEMs must establish repeatable processes rather than simply purchase security technology. Asset Inventory And Vulnerability Traceability: Under the CRA, maintaining a durable record of shipped equipment, its configuration, ownership, location, and software or firmware versions so OEMs can identify affected customers and respond to newly disclosed vulnerabilities across their installed base. Vulnerability Remediation And Patching: Vulnerability findings should be prioritized and remediated without disrupting industrial production, including update limitations for embedded devices, vendor dependencies, maintenance windows, and the need for tested procedures. Digital Twins And Security Validation: Digital twins can be used to model manufacturing lines and test patches before deployment. Rockwell's Emulate3D and associated consulting capabilities provide a solution for validating dependencies and developing secure operational procedures. Cybersecurity Governance And Safety: CRA compliance requires sustained organizational ownership and collaboration, while cybersecurity must be treated as part of machine safety because exploitation can affect operators, equipment, production, and the surrounding environment. Subscribe Follow and subscribe for more episodes on Apple Podcasts, Spotify, YouTube, or wherever you get your podcasts. Get in Touch 🔗 LinkedIn | YouTube | X | Contact Us


















