With the implementation of the Cyber Resilience Act (CRA) in December 2024, European regulation has introduced mandatory cybersecurity requirements for products with digital components. This legislative change necessitates the incorporation of systematic cybersecurity practices throughout the entire lifecycle of such products, affecting multiple companies in the industry.
For MB connect line, a provider of industrial remote access and networking solutions, this regulation aligns with their long-established practices. They have consistently upheld the principles of Security by Design and Security by Default, viewing cybersecurity as an integral part of their product architecture. Their approach includes creating controlled communication channels and segmented networks to ensure robust security from the ground up.
Lifecycle cybersecurity management
The CRA reinforces practices already ingrained within MB connect line’s product development and organisational processes. The company manages cybersecurity throughout the entire product lifecycle, rather than only at delivery. Their Information Security Management System (ISMS), certified to ISO/IEC 27001:2022 in March 2026, underpins these efforts. This system addresses essential organisational requirements, including risk management, incident management procedures, and supply chain security.
MB connect line’s commitment to secure product development is further evidenced by their adherence to industry standards such as IEC 62443-4-1, certified since 2024. They aim to ensure development processes mitigate risk and enhance traceability. Moreover, preparations are underway for product certifications per IEC 62443-4-2, particularly as they prepare to launch new hardware platforms in mid-2026, in accordance with the CRA and related standards.
Technical security measures
Technically, MB connect line employs a variety of security mechanisms across their product lines
Technically, MB connect line employs a variety of security mechanisms across their product lines. These include secure boot processes, encrypted updates, and role-based access controls, alongside segmented network architectures. By adhering to the “least privilege” principle and implementing comprehensive logging features, the company seeks to minimise attack surfaces while ensuring all measures are thoroughly documented and traceable.
For MB connect line, adapting to the CRA is recognised as an ongoing progression rather than a finite task. Over the next few years, they plan to enhance their technical validation, lifecycle management, and product certifications. Additionally, the CRA's scope, which emphasises individual products with digital elements, assigns more responsibility to integrators when components are assembled, as per Article 2 of the act and complementary regulations such as the Machinery Regulation (EU) 2023/1230.
Educational support for integration
MB connect line emphasises the shared responsibility among manufacturers, OEMs, and operators for ensuring secure integration and operation of products. To support this process, the company provides comprehensive security guidelines, architectural examples, and technical documentation to its customers.
CTO Alexander Kamm notes, "At MB connect line, cybersecurity is not just a marketing promise, but an integral part of our daily work." This approach, confirmed by the CRA, highlights cybersecurity as a verifiable element in product development, operation, and maintenance.
European regulation regarding cybersecurity in industrial products is gaining momentum: The Cyber Resilience Act (CRA) has been in effect since December 2024 and establishes mandatory requirements for products with digital components.
For companies, this means not only new regulatory requirements but also the need to systematically integrate cybersecurity throughout the entire product lifecycle.
Controlled communication channels
For them at MB connect line, this approach is not a paradigm shift, but rather the logical continuation of an already established understanding of IT security. As a manufacturer of industrial remote access and networking solutions, they view the CRA as confirmation of a path they have been pursuing for years, both technically and organisationally: Security by Design and Security by Default.
For them, security is not a single feature, but a transparent, systematic, holistic concept. Security must be approached from an architectural perspective – from controlled communication channels and segmented networks to clearly defined operational and lifecycle processes.
Entire product lifecycle
The CRA emphasises regulatory requirements that MB connect line has already been incorporating into its product development and business processes for years. This includes, in particular, the understanding that cybersecurity does not end with the delivery of a device, but must be actively managed throughout the entire product lifecycle.
Their Information Security Management System (ISMS), which has been certified to ISO/IEC 27001:2022 since March 2026, serves as an important foundation. It ensures that key organisational requirements – such as risk and countermeasure management, vulnerability and incident management processes, backup and recovery processes, roles and responsibilities, and supply chain aspects – are structurally embedded.
Risk-mitigating development
MB connect line also relies on established industry standards at the development level. The development process for new products has been certified according to IEC 62443-4-1 since 2024. The goal is to ensure the secure, traceable, and risk-mitigating development of digital products.
In addition, the company is preparing product certifications in accordance with IEC 62443-4-2 for the new hardware platforms (scheduled for release in mid-2026) and is already taking into account the additional requirements arising from the Cyber Resilience Act and related standards. The goal is to ensure that regulatory compliance can be demonstrated comprehensively and robustly.
Segmented network architectures
From a technical standpoint, we rely on a wide range of established security mechanisms in both current and new product generations. These include, among other things, secure boot and firmware concepts, signed and encrypted updates, role-based access controls, and segmented network architectures.
The security concept also includes controlled communication paths based on the “least privilege” principle, as well as logging and traceability features to meet audit and operational requirements. The goal is to reduce the attack surface, provide secure default configurations, and ensure that implemented measures are documented in a traceable manner.
Developing new platforms
For MB connect line, the CRA is not a one-time compliance task, but rather a multi-year development process. The organisational and technical foundations have already been laid in recent years. This includes establishing certified processes and developing new platforms that take future regulatory requirements into account.
In the coming years, they will continue to expand our technical validation, documentation, and lifecycle and vulnerability management in particular. At the same time, they will carry out product certifications and continuously refine their security concepts.
Providing security guidelines
At the same time, they would like to highlight an important point: The Cyber Resilience Act primarily addresses individual products with digital elements. When components are assembled into new products – for example, in machinery or plant systems—the integrator typically becomes the manufacturer under the CRA and thus assumes responsibility for the conformity of the resulting product.
Where other EU regulations (such as the Machinery Regulation (EU) 2023/1230) stipulate their own cybersecurity requirements, Article 2 of the CRA governs the relationship between these regulatory frameworks. For practical implementation, the IEC 62443 series of standards is also recommended.
Secure integration, configuration, and operation remain a shared responsibility of manufacturers, OEMs, and operators. To support the customers in this regard, they at MB connect line provide security guidelines, architectural examples, and technical documentation.
Verifiable component of development
With regard to the Cyber Resilience Act, they consider themselves very well prepared.
For MB, the regulatory framework confirms an approach they have been following for years: cybersecurity as a verifiable component of development, operations, and product maintenance -implemented in a traceable manner throughout the entire lifecycle. “At MB connect line, cybersecurity is not just a marketing promise, but an integral part of our daily work,” said CTO Alexander Kamm.