Retrofit for CRA Readiness; Continue Operating Existing Machines
Retrofit systems for compliance and updates instead of replacing machines
Your machines will continue to operate at the customer's site for many years to come. But are they also equipped to meet the new cybersecurity requirements? With the Cyber Resilience Act (CRA), the requirements for software transparency, vulnerability management, and security updates—are increasing—and the responsibility for this lies with the manufacturer. Many existing machines were not designed with this in mind. At the same time, replacing the machines or completely redesigning the control system is hardly economically feasible.
Our brownfield solution closes this gap: It enhances existing machines with the necessary verification and update capabilities—without requiring machine replacement. CRA Readiness is provided as a complete, end-to-end solution—from gap analysis to edge retrofitting to update management.
- Evidence that supports the audit: SBOM, audit trails, and patch documentation are generated during ongoing operations and reduce liability risk for manufacturers
- Cost-effectively upgrade existing systems: Enhance upgradeability and security while ensuring investment and delivery capabilities
- Reduce service costs: Roll outsecurityupdates centrally across the fleet instead of sending a technician on-site for each machine
- Low-risk start: Identifyvulnerabilities, technical options, and the effort required for a representative machine—as a solid basis for deciding on the fleet rollout
The implementation of the Update Manager has significantly improved our ability to distribute updates efficiently and securely. Thanks to this solution, we can keep all of our networked systems up to date globally. This enhances the user experience and security, and improves our product’s performance thanks to new features in the rolled-out software. – Luca Lutsch, Product Owner at ZEISS Microscopy
When CRA Requirements Meet the Reality of Mechanical Engineering
The Cyber Resilience Act makes cybersecurity a responsibility that extends across the entire product lifecycle. For machine builders, there is a need for action, particularly in areas where transparency regarding software, vulnerabilities, and updates is not yet consistently ensured:
- Software components and vulnerabilities must be manageable throughout their lifecycle—using traceable processes and reliable documentation
- Many existing machines lack the technical foundation for this—but redesigning the control system or replacing the machines is not a viable economic option
Security updates must be reliably deployed to the installed fleet—even across heterogeneous machine and software configurations
- Manual on-site updates tie up service capacity and cannot scale across hundreds or thousands of machines
This text does not constitute legal advice. Please consult a professional to clarify deadlines and how this applies to your specific situation.
- New machines must be prepared to meet CRA requirements starting in 2027—from software transparency and vulnerability management to secure update capabilities
- Customers and auditors are already demanding SBOMs, security questionnaires, and documented patching processes—without this evidence, the manufacturer remains liable
- New and existing machines should not end up in separate security silos—what is needed is a scalable approach for both the product and the fleet
CRA Readiness as an Overall Process:
Retrofit, Verification, Updates
We help machine and plant manufacturers upgrade existing brownfield machines into secure, updatable, and CRA-ready products with digital elements—without the need for costly machine replacements.
The Cyber Resilience Act refers to "Products with Digital Elements" (PDE): machines in which software and connectivity are integral parts of the product.
Three building blocks go together:
- Brownfield Retrofit at the Edge:
Secure connectivity and protocol
translation to OPC UA or MQTT using partner hardware from secunet or Eurotech
- Device, OTA, and
Update Management:
Controlled updates, rollbacks, and auditable records—including SBOM—during operation
- Security and Lifecycle Processes:
From Gap Analysis to CRA Requirements to Scalable Routine Operations
Documentation can only be maintained over the long term if machines are capable of receiving updates and those updates are rolled out in a controlled manner. That is why analysis, retrofitting, and update management must all be part of a single solution.
Features, Operating Models, and Integration in Detail:
Device & Update Management
What You Can Achieve with CRA Readiness
Compliance, Security, and Risk:
Address CRA requirements with traceable security and lifecycle processes and reduce compliance, cyber, and liability risks
Planned Path:
from the Readiness Check through the pilot to fleet deployment, with a business case for internal approval.
Cost-Effectiveness and Investment Protection:
Modernize existing CRA-ready machines and extend the safe operation of the installed base without replacing the machines.
Operation and Scaling:
Reduce service costs through centralized device management and automated software and security updates.
Here's how we proceed:
check, upgrade, scale
The process consists of three steps: first, identify the gaps; then, retrofit a specific machine model; and finally, scale it up to the entire fleet.
- Assess
We examine machine types, control systems, and software versions and evaluate them against the mandatory CRA requirements. You’ll learn where the gaps are and in what order it makes sense to address them.
- Retrofit (Build)
A representative machine type is retrofitted and integrated into Update Management. The real-world device demonstrates whether the retrofit is successful before the rest of the fleet follows.
- Scaling (Scale)
The proven architecture is being extended to additional models and locations. SBOM, vulnerability, and update processes continue to run as part of regular operations, with operational partnerships available upon request.
Validation in Practice
Partner Edge Hardware
secunet and eurotech as co-selling options for retrofits. The gateway translates proprietary legacy protocols and transmits them securely, enabling existing machines to be updated.

What Companies Need to Know About CRA Readiness
What does CRA Readiness mean for existing machines?
Which CRA requirements apply to existing machines?
What are the CRA deadlines?
What Does the CRA Readiness Check Include?
Is a CRA checklist sufficient for the existing fleet?
Is SBOM software sufficient for compliance?
Our technicians are performing an on-site update today. What will change?
Do we need a machine replacement for the Cyber Resilience Act?
How does brownfield retrofitting with an edge gateway work?
How does this relate to device and update management?
Let's talk about your IoT opportunities together!
First, during a 30-minute initial consultation, we’ll determine whether the CRA and Brownfield scope are appropriate and whether the Readiness Check is the next logical step. If so, we’ll develop a gap analysis, security assessment, roadmap, and business case to serve as a basis for decision-making regarding your existing fleet.
- Narrow down the scope and machine types
- Develop a gap analysis and security assessment
- Deliver the roadmap, action plan, and business case
What you’ll need to bring: Contact persons from Engineering, Service, or IT/OT, and an overview of relevant product lines.
What you’ll receive: Clarity on the scope and, if needed, a decision-ready document for internal approval, with no obligation to proceed with an implementation project.