Cyber resilience act in the off-highway industry: ETAS supports manufacturers on the path to CRA compliance
The Cyber Resilience Act (CRA) establishes mandatory cybersecurity standards for products with digital elements throughout the European Union. Although the automotive industry is subject to regulations such as UN-R155 and ISO/SAE 21434, these exemptions do not apply to the off-highway (OHW) sector. Consequently, manufacturers of agricultural, construction, and specialty machinery must address new cybersecurity obligations throughout the entire product lifecycle. In the latest ETAS white paper, “Navigating the Cyber Resilience Act in the off-highway industry”, ETAS experts explain how companies can implement these regulatory requirements and establish scalable security architectures.
A holistic security approach throughout the entire product lifecycle
The CRA requires a comprehensive security-by-design approach that covers development, deployment, and operation. This approach incorporates cybersecurity measures throughout the product lifecycle, allowing manufacturers to respond to evolving threats. The white paper identifies several key enablers:
Risk-Based Cybersecurity
The CRA requires a risk-based cybersecurity lifecycle that includes risk assessments, security-by-default principles, data and interface protection, incident logging, and secure software updates.
Cryptographic Security Infrastructure
Modern cybersecurity relies on cryptographic identities and device-specific keys for secure authentication, software updates, and data protection. Robust key management helps prevent attacks from spreading and supports regulatory compliance.
SBOM & Vulnerability Management
Software Bills of Materials (SBOMs) provide transparency about all software components within a product. They enable vulnerability management, dependency tracking, and continuous monitoring of cybersecurity risks across the supply chain.
Secure Updates & Fleet Monitoring
Cybersecurity must be maintained throughout the product lifecycle. Secure OTA updates, logging, and monitoring capabilities help manage access rights, detect anomalies, and deploy security patches efficiently.
Practical support for CRA compliance
ETAS supports manufacturers with a comprehensive portfolio of services, including consulting, starter kits, key management, SBOM services, and vulnerability management services. The goal is to help organizations establish efficient product cybersecurity lifecycles and secure development and operational processes. ETAS leverages its extensive expertise in the highly regulated automotive industry to provide solutions for the off-highway sector.
For off-highway manufacturers, the CRA is becoming a critical requirement for maintaining market access within the European Union. At the same time, modern cybersecurity concepts enable capabilities such as OTA updates, remote diagnostics, and fleet management. This white paper shows how to address regulatory requirements through scalable security architectures and integrated diagnostic platforms.
Contact us
Do you have any questions? Feel free to send us a message. We will be more than happy to help. Contact us today!