FraunhoferFraunhoferICNAPICNAP

ICNAP Login

A futuristic industrial setting features robotic arms operating on assembly lines amidst large metal storage tanks in the background. The scene is dominated by a digital shield icon with a checkmark and gears, symbolizing security and technology integration. Bright light connections form a network above the factory, suggesting advanced technology support. The floor is polished, with numerous safety cones and crates scattered around. The overall color palette includes metallic grays, blues, and glowing accents, creating a high-tech, automated manufacturing environment.

Manufacturing Secured by Design - A Zero-Trust Approach to Industrial Product Development


Show Full StudyOnly for ICNAP Members
Summary

Manufacturing’s move to Industry 4.0 and AI in OT expands the attack surface and makes supply chains a prime target, increasing safety, availability, and financial risks. The EU Cyber Resilience Act (CRA) makes cybersecurity a CE‑mark market access requirement for all products with digital elements from December 2027, with stricter assessment for higher‑risk products and fines up to €15M or 2.5% of global revenue. CRA demands security by design from the start, secure defaults and access control, timely vulnerability handling with an SBOM and updates, and monitoring with incident reporting. Manufacturers must provide an EU Declaration of Conformity, technical documentation (including risk analysis and vulnerability processes), and clear user instructions. OT needs a tailored approach that prioritizes availability and safety, applying defense‑in‑depth and zero‑trust principles. IEC 62443 offers a practical path: IEC 62443‑4‑1 defines a secure development lifecycle and update/vulnerability processes, and IEC 62443‑4‑2 defines technical controls across seven foundational requirements with graded security levels. Embedding these practices reduces attack surface, strengthens products, and enables CRA compliance.

Topic Fields
ConnectivityIT Architectures
Published2025
Involved Institutes
Project TypeICNAP Community Study
Result Type
Responsibles

© Fraunhofer 2026

ContactTerms of useData ProtectionEditorial Notes