Header image overlay

The Cyber Resilience Act is ticking away. Is your OT network ready?

The Cyber Resilience Act is putting OT security higher on the agenda. The EU Cyber Resilience Act, or CRA for short, has been in effect since 10 December 2024. Reporting obligations for actively exploited vulnerabilities and serious incidents will commence from 11 September 2026. Full application of the legislation will follow on 11 December 2027.

With the CRA, Europe wants to make digital products safer. Think of software, hardware, and connected devices that are ubiquitous today: from consumer applications to industrial technology.

Key insights

Legislation places more responsibility on manufacturers. They must focus more strongly on secure development, security updates, vulnerability management, and clear documentation.

That's good news for anything that comes onto the market tomorrow. But for your existing OT environment, the reality is more complex.

Nozomi Networks

Cyber Resilience Act OT-security: new rules, old infrastructure

In OT, systems aren't simply replaced because new legislation comes out. PLCs, HMIs, sensors, machines, and industrial network components often keep running for years.

Sometimes 10 years. Sometimes 15 years. Sometimes even longer.

And that's where the risk arises.

And what do you know exactly today:

  • What assets are active in your OT network?
  • What firmware versions are running on it?
  • Which ports and protocols are open?
  • What vulnerabilities are present?
  • Which systems communicate with each other?
  • Which behaviour is normal or abnormal?

Many organisations do not have a complete view of this, not because they are negligent, but because OT environments have grown organically over time. Machines, suppliers, couplings, and temporary solutions are added over the years.

What was once clear will become a blind spot.

The CRA makes new products safer. Not automatically your existing OT park.

The Cyber Resilience Act raises the bar for manufacturers. New digital products will need to be more secure, better documented, and supported for longer.

But your existing OT assets obviously won't disappear.

A production line is not replaced because legislation changes. A stable PLC often just keeps running. A machine that is crucial for production is not simply shut down for updates or modifications.

That is understandable. In OT, continuity is central.

But it does mean that you As an organisation, you need to get a grip on what is already active in your industrial environment today. Because you can't secure what you don't see.

OT security begins with visibility

A serious OT security journey Therefore, do not start with arbitrary interventions or complex projects. It begins with insight.

You need to know what's running, how systems communicate with each other, and where the biggest risks lie.

Specifically, you want an overview of:

  • your complete OT asset inventory;
  • communication between machines, PLCs, HMIs and sensors;
  • known vulnerabilities;
  • abnormal network behaviour;
  • risks per asset or segment;
  • supplier dependencies;
  • changes in your OT environment.

Then you can set your priorities.

Which systems are critical? Which vulnerabilities require attention first? Where is segmentation needed? Which suppliers should you approach? And where do you face the most risk today?

Without that visibility, OT security remains largely guesswork.

VanRoey and Nozomi Networks: visibility without disrupting your production

This is why VanRoey works with Nozomi Networks.

Nozomi maps out OT and industrial networks passively and non-intrusively. This means that you gain insight into your surroundings without active scans or interventions that could disrupt your production process.

With Nozomi, you gain insight into:

  • all active OT assets;
  • firmware, protocols and communication patterns;
  • vulnerabilities and risks;
  • abnormal behaviour;
  • Possible threats;
  • changes to your industrial network.

This is how you evolve from assumptions to facts.

You see what's *really* going on. You know where the risks lie. And you can make more targeted decisions about where action is needed.

Don't wait until 2027

The full application of the CRA will follow in 2027, but waiting until then is not a good idea. Reporting obligations will start as early as 2026, and the pressure for cyber resilience is only increasing.

For OT environments, now is the time to get the basics in order.

Not by wanting to solve everything at once.
However, by starting with visibility.

Because the main question is not just whether new technology will be CRA-compliant in the future.

The real question is: “Do you know today what's running on your OT network?”

Get a grip on your OT environment

The CRA is raising the bar for what you buy tomorrow. But your existing OT environment is already running today.

Together with Nozomi Networks, VanRoey helps you make your industrial network visible, manageable and more secure. Passively, non-intrusively and without disrupting your production processes.

Would you like to know which assets, vulnerabilities, and risks are present in your OT network today? Then visibility is the first step.

VAT no.

Author

Article written by

Thomas Willems
Team Lead, Network Solutions

Thomas joined us in 2013 as a Network Engineer. Partly thanks to his strong passion and broad knowledge in IT & Networking, he progressed to Team Lead Network Solutions. So it's fair to say he's a true expert in his field.

“You cannot secure what you cannot see.”

share this post:

OT security begins with visibility
Passively identify your assets, vulnerabilities and anomalous behaviour with VanRoey and Nozomi Networks

OT Security - Secure production environment with Nozomi (+Demo)

Nozomi is the market leader when it comes to OT-Security. In this recording, our specialist discusses cybersecurity capabilities & gives you a demo!

Receive our newsletter including invitations to events & interesting industry news!

Two Belgian IT players join forces in a single integrated IT group for managed IT services under the name Dynamate