The Cyber Resilience Act will profoundly transform the way companies design, market and maintain their connected products. For industrial SMEs, this European regulation is not simply another regulatory constraint. It marks a major shift: cybersecurity is becoming a requirement that must be integrated from the very design stage of digital, connected or industrial products.
In an article dedicated to the challenges of the Cyber Resilience Act for industrial SMEs, Agoria cites MCG as one of the Belgian players capable of supporting companies through this transition. This recognition is important because it confirms our role within the Belgian cybersecurity ecosystem, particularly on issues related to industrial security, OT (Operational Technology) and the convergence between traditional IT and production environments.
The Cyber Resilience Act is a European regulation aimed at strengthening the cybersecurity of products with digital elements. It applies in particular to manufacturers, importers and distributors of connected products, software, industrial equipment, embedded systems and solutions incorporating network connectivity.
In practical terms, as soon as a product contains software, exchanges data, connects to a network or can be updated remotely, it may fall within the scope of the CRA.
The objective is clear: to prevent vulnerable products from being placed on the European market without sufficient cybersecurity requirements. Until now, security was still too often added as an afterthought, once the product had been developed, sold or installed. With the CRA, this approach is changing. Cybersecurity will have to be integrated from the earliest stages of design.
For industrial companies, this is a major development. It means rethinking the way products are designed, documented, maintained and patched throughout their entire lifecycle.
An industrial SME may be affected by the Cyber Resilience Act even if it does not consider itself a technology company. A connected machine, smart sensor, programmable logic controller, supervisory system, human-machine interface, business software application or network-connected piece of equipment may all fall within its scope.
This is precisely what Gregorio Matias highlights in Agoria’s article: OT, or Operational Technology, lies at the heart of the challenges posed by the Cyber Resilience Act. It refers to the technologies that control industrial environments.
For a long time, these systems were relatively isolated. Today, they are increasingly connected to IT networks, supervisory tools, cloud solutions, external service providers and remote maintenance systems. This interconnection brings numerous benefits in terms of productivity, control and efficiency. But it also increases the attack surface.
For an industrial SME, the risk is therefore far from abstract. A vulnerability in connected equipment can lead to a production shutdown, data leakage, loss of control over certain systems or service disruption. The consequences can be significant: financial losses, internal disruption, pressure on teams, reputational damage and loss of customer trust.
This is where MCG’s expertise comes into its own. We help companies identify real risks, prioritise actions and implement measures suited to their operational environment.
Is hiring a cybersecurity consultant essential for your business?
One of the major challenges of the Cyber Resilience Act concerns the convergence of IT and OT. As Gregorio Matias points out, these are “two distinct worlds”. “OT teams do not understand IT risks. They do not speak the same language. (...) And if no one builds a bridge between them, these two worlds remain vulnerable.”
IT encompasses traditional information systems: workstations, servers, email, networks, applications and user access. OT, on the other hand, concerns the industrial systems used to produce, measure, control or automate.
These two worlds do not always share the same priorities. IT often thinks in terms of confidentiality, access, patches, backups and compliance. OT focuses first and foremost on continuity, availability, physical safety and production stability.
In many industrial companies, IT and OT teams still work in silos. One side wants to patch vulnerabilities quickly. The other fears that an update could disrupt production. One approaches the issue from a cybersecurity perspective. The other from an industrial perspective.
Both perspectives are legitimate. But if they are not coordinated, the company remains exposed.
MCG’s role is precisely to build this essential bridge between IT and OT. MCG helps management teams, IT teams and operational managers speak the same language, understand shared risks and build a cybersecurity strategy that is compatible with operational realities.
The Cyber Resilience Act introduces several important obligations.
The first concerns security by design. Companies will have to integrate cybersecurity into the development of their products. This means reducing unnecessary access, securing data exchanges, limiting weak default configurations and providing reliable update mechanisms.
The second concerns vulnerability management. Manufacturers will need to be able to identify, address and patch vulnerabilities discovered in their products. This obligation requires clear processes, defined responsibilities and the ability to respond quickly.
The third concerns transparency. Users will need to be provided with clearer information about product security, support periods, available updates and any potential limitations. Cybersecurity is therefore also becoming an element of commercial trust.
Finally, certain actively exploited vulnerabilities and certain serious incidents will have to be reported within the required timeframes. For companies, this means being able to quickly detect, assess and document incidents.
For MCG, these obligations confirm one reality: cybersecurity can no longer be improvised. It must be structured before an emergency arises.
The Cyber Resilience Act deadlines may give the impression that there is still plenty of time. In practice, however, preparing requires substantial groundwork.
Companies need to identify the products concerned, map risks, analyse dependencies, document processes, organise vulnerability management, clarify responsibilities and implement the appropriate protective measures. In industrial environments, the specific constraints of OT must also be taken into account: legacy machinery, systems that are difficult to patch, critical availability requirements, long lifecycles and dependence on certain suppliers.
“Take the example of supply chain risk management in Central and Eastern European countries, as in the hospital sector. For European industrial players: if your product is not compliant with the CRA, you simply can no longer market it.”
Gregorio Matias
It is precisely to avoid this pressure that MCG advocates an approach based on anticipation. The objective is not to make companies’ day-to-day operations more complex. On the contrary, MCG helps its clients make the right decisions, at the right time, with a clear understanding of their priorities.
This approach means internal teams do not have to carry the burden of cybersecurity issues alone. They can continue focusing on their own responsibilities while MCG structures the analysis, recommendations and actions that need to be taken.
The Cyber Resilience Act may be perceived as a constraint, but for industrial SMEs that start preparing now, it can also become a competitive advantage.
A company that can demonstrate that its products are designed, maintained and secured to a high standard inspires greater trust. It reassures customers, partners and suppliers. It can more easily meet the requirements of major clients. It also reduces its exposure to cyberattacks.
In an increasingly connected industrial environment, cybersecurity is becoming a key criterion of credibility.
Companies do not have to face this transition alone. The Cyber Resilience Act requires technical, regulatory and operational expertise. It also requires the ability to turn sometimes complex obligations into concrete, realistic actions that are adapted to operational realities.
The Cyber Resilience Act is coming. The best-prepared companies will be those that understand that it is not only about compliance, but also about trust, continuity and resilience.