Key insights
- CRA fully applicable from 11 December 2027
- Reporting obligations start as early as 11 September 2026
- Existing OT assets often remain a blind spot.
- VanRoey and Nozomi Networks make your OT network visible
Legislation places more responsibility on manufacturers. They must focus more strongly on secure development, security updates, vulnerability management, and clear documentation.
That's good news for anything that comes onto the market tomorrow. But for your existing OT environment, the reality is more complex.
Cyber Resilience Act OT-security: new rules, old infrastructure
In OT, systems aren't simply replaced because new legislation comes out. PLCs, HMIs, sensors, machines, and industrial network components often keep running for years.
Sometimes 10 years. Sometimes 15 years. Sometimes even longer.
And that's where the risk arises.
And what do you know exactly today:
- What assets are active in your OT network?
- What firmware versions are running on it?
- Which ports and protocols are open?
- What vulnerabilities are present?
- Which systems communicate with each other?
- Which behaviour is normal or abnormal?
Many organisations do not have a complete view of this, not because they are negligent, but because OT environments have grown organically over time. Machines, suppliers, couplings, and temporary solutions are added over the years.
What was once clear will become a blind spot.
The CRA makes new products safer. Not automatically your existing OT park.
The Cyber Resilience Act raises the bar for manufacturers. New digital products will need to be more secure, better documented, and supported for longer.
But your existing OT assets obviously won't disappear.
A production line is not replaced because legislation changes. A stable PLC often just keeps running. A machine that is crucial for production is not simply shut down for updates or modifications.
That is understandable. In OT, continuity is central.
But it does mean that you As an organisation, you need to get a grip on what is already active in your industrial environment today. Because you can't secure what you don't see.
OT security begins with visibility
A serious OT security journey Therefore, do not start with arbitrary interventions or complex projects. It begins with insight.
You need to know what's running, how systems communicate with each other, and where the biggest risks lie.
Specifically, you want an overview of:
- your complete OT asset inventory;
- communication between machines, PLCs, HMIs and sensors;
- known vulnerabilities;
- abnormal network behaviour;
- risks per asset or segment;
- supplier dependencies;
- changes in your OT environment.
Then you can set your priorities.
Which systems are critical? Which vulnerabilities require attention first? Where is segmentation needed? Which suppliers should you approach? And where do you face the most risk today?
Without that visibility, OT security remains largely guesswork.
VanRoey and Nozomi Networks: visibility without disrupting your production
This is why VanRoey works with Nozomi Networks.
Nozomi maps out OT and industrial networks passively and non-intrusively. This means that you gain insight into your surroundings without active scans or interventions that could disrupt your production process.
With Nozomi, you gain insight into:
- all active OT assets;
- firmware, protocols and communication patterns;
- vulnerabilities and risks;
- abnormal behaviour;
- Possible threats;
- changes to your industrial network.
This is how you evolve from assumptions to facts.
You see what's *really* going on. You know where the risks lie. And you can make more targeted decisions about where action is needed.
Don't wait until 2027
The full application of the CRA will follow in 2027, but waiting until then is not a good idea. Reporting obligations will start as early as 2026, and the pressure for cyber resilience is only increasing.
For OT environments, now is the time to get the basics in order.
Not by wanting to solve everything at once.
However, by starting with visibility.
Because the main question is not just whether new technology will be CRA-compliant in the future.
The real question is: “Do you know today what's running on your OT network?”
Get a grip on your OT environment
The CRA is raising the bar for what you buy tomorrow. But your existing OT environment is already running today.
Together with Nozomi Networks, VanRoey helps you make your industrial network visible, manageable and more secure. Passively, non-intrusively and without disrupting your production processes.
Would you like to know which assets, vulnerabilities, and risks are present in your OT network today? Then visibility is the first step.
VAT no.
Author
Article written by
share this post: