MB Sets the Course for the Cyber Resilience Act:
Security by Design as a Best Practice
European regulation regarding cybersecurity in industrial products is gaining momentum: The Cyber Resilience Act (CRA) has been in effect since December 2024 and establishes mandatory requirements for products with digital components.
For companies, this means not only new regulatory requirements but also the need to systematically integrate cybersecurity throughout the entire product lifecycle.
For us at MB connect line, this approach is not a paradigm shift, but rather the logical continuation of an already established understanding of IT security. As a manufacturer of industrial remote access and networking solutions, we view the CRA as confirmation of a path we have been pursuing for years, both technically and organizationally: Security by Design and Security by Default.
IT Security as a Comprehensive Approach
For us, security is not a single feature, but a transparent, systematic, holistic concept. Security must be approached from an architectural perspective – from controlled communication channels and segmented networks to clearly defined operational and lifecycle processes.
The CRA emphasizes regulatory requirements that MB connect line has already been incorporating into its product development and business processes for years. This includes, in particular, the understanding that cybersecurity does not end with the delivery of a device, but must be actively managed throughout the entire product lifecycle.
Certified Processes as the Foundation
Our Information Security Management System (ISMS), which has been certified to ISO/IEC 27001:2022 since March 2026, serves as an important foundation. It ensures that key organizational requirements – such as risk and countermeasure management, vulnerability and incident management processes, backup and recovery processes, roles and responsibilities, and supply chain aspects – are structurally embedded.
MB connect line also relies on established industry standards at the development level. The development process for new products has been certified according to IEC 62443-4-1 since 2024. The goal is to ensure the secure, traceable, and risk-mitigating development of digital products.
In addition, the company is preparing product certifications in accordance with IEC 62443-4-2 for the new hardware platforms (scheduled for release in mid-2026) and is already taking into account the additional requirements arising from the Cyber Resilience Act and related standards. The goal is to ensure that regulatory compliance can be demonstrated comprehensively and robustly.
Security features are already integrated today
From a technical standpoint, we rely on a wide range of established security mechanisms in both current and new product generations. These include, among other things, secure boot and firmware concepts, signed and encrypted updates, role-based access controls, and segmented network architectures.
The security concept also includes controlled communication paths based on the “least privilege” principle, as well as logging and traceability features to meet audit and operational requirements. The goal is to reduce the attack surface, provide secure default configurations, and ensure that implemented measures are documented in a traceable manner.
Multi-Year Roadmap to CRA Compliance
For MB connect line, the CRA is not a one-time compliance task, but rather a multi-year development process. The organizational and technical foundations have already been laid in recent years. This includes establishing certified processes and developing new platforms that take future regulatory requirements into account.
In the coming years, we will continue to expand our technical validation, documentation, and lifecycle and vulnerability management in particular. At the same time, we will carry out product certifications and continuously refine our security concepts.
CRA Milestones
June 11, 2026:
Regulations regarding notified bodies will take effect.
September 11, 2026:
Reporting requirements for actively exploited vulnerabilities and serious security incidents will take effect.
December 11, 2027:
Full application of conformity assessment, technical documentation, and the CE marking requirement.
MB connect line is already preparing for these deadlines. In particular, the processes for reporting vulnerabilities are already structurally embedded in our certified ISMS.
With the mandatory CRA requirements now in effect, MB connect line is committed to transparency with customers and partners – for example, regarding support and maintenance periods, as well as continuous adaptation to new threat landscapes.
CRA does not replace system responsibility
At the same time, we would like to highlight an important point: The Cyber Resilience Act primarily addresses individual products with digital elements. When components are assembled into new products – for example, in machinery or plant systems—the integrator typically becomes the manufacturer under the CRA and thus assumes responsibility for the conformity of the resulting product. Where other EU regulations (such as the Machinery Regulation (EU) 2023/1230) stipulate their own cybersecurity requirements, Article 2 of the CRA governs the relationship between these regulatory frameworks. For practical implementation, the IEC 62443 series of standards is also recommended.
Secure integration, configuration, and operation remain a shared responsibility of manufacturers, OEMs, and operators. To support our customers in this regard, we at MB connect line provide security guidelines, architectural examples, and technical documentation.
Conclusion
With regard to the Cyber Resilience Act, we consider ourselves very well prepared. For MB, the regulatory framework confirms an approach we have been following for years: cybersecurity as a verifiable component of development, operations, and product maintenance -implemented in a traceable manner throughout the entire lifecycle.
“At MB connect line, cybersecurity is not just a marketing promise, but an integral part of our daily work.”
CTO Alexander Kamm





