• Products
  • Industries
  • IIoT & Solutions
  • Service
  • Company
  1. Overview
  2. Cybersecurity

Cybersecurity for mobile machines

The digitalisation of mobile machines is advancing rapidly. Networked controllers, telematics and software-based functions boost efficiency and productivity while expanding the attack surface for cyber threats.

ifm offers end-to-end cybersecurity, from component to system.

With the Cyber Resilience Act (CRA) and the new Machinery Regulation (MR), cybersecurity is becoming a mandatory requirement. From 2027 onwards, machines may only bear the CE marking if cybersecurity has been considered holistically across the entire product life cycle.

The corresponding requirements were already published in European legislation in 2023 and 2024:

  • Machinery Regulation (EC 2023/0123): legally binding as of January 2027
  • Cyber Resilience Act (EU 2024/2847): legally binding as of December 2027

This means that all products containing digital elements that are sold in the EU must comply with the requirements of the CRA. Manufacturers confirm such compliance through their EU Declaration of Conformity. 

To avoid delays in development or approvals, OEMs need to incorporate cybersecurity into the product life cycle at an early stage.

ifm is ready for both the MR and the CRA: With approved components and clear cybersecurity guidelines, ifm supports customers in the integration and commissioning of machines.

Contact us now

With standards-based support towards a certifiable machine

As under the former Machinery Directive, standards and technical regulations provide clarity when implementing regulatory requirements. The core requirements themselves are not new, only products that do not pose a risk to users, bystanders or the environment may be placed on the market.

In the context of mobile machines, particularly relevant standards are those relating to specific applications, for example:

  • Road legality in accordance with UNECE R155: ISO/SAE 21434
  • Off-road applications: IEC 62443
  • Framework for processes and organisation: ISO/IEC 27001
Comparison of standards for mobile machines, showing the applicable requirements for the integrator and ifm for road-legal and non-road-legal machines

Standards in the context of mobile machines

ifm’s mobile components are the result of a holistic innovation process, addressing every relevant stage of the product life cycle, from organisational measures and development process to market-ready components, including:

  • Certified information security management
  • End-to-end certified development processes in accordance with IEC 62443-4-1 and ISO/SAE 21434
  • Compliance with standards for the use in mobile machines in harsh environments

Your benefits as a customer

You can continue to integrate tested and certified components as usual, without having to assess them yourself in the context of the new regulations. This significantly reduces system design effort, provides transparency and helps avoid unnecessary delays in established approval procedures.

Components you can trust

Standards as the basis for an end-to-end development process

At ifm, cybersecurity is not achieved through isolated measures or individually approved products. Our TÜV Rheinland-certified development process has achieved Maturity Level 3 (“Defined – Practised”, i.e. established practice), meaning that our cybersecurity processes are applied in a transparent and reproducible manner as part of our day-to-day development work.

To meet cybersecurity regulatory requirements, every component developed under this process is consistently brought to market in compliance with the two most important sets of standards:

  • IEC 62443 (industrial applications)
  • ISO/SAE 21434 (automotive requirements)

Our promise to you: ifm’s ‘Security by Design’ strategy is a reproducible process firmly embedded throughout the product life cycle and consistently applied across all products – regardless of the specific application.

Cybersecurity starts with system design

How controllers, displays, communications, networks and applications interact

Defence-in-Depth

A secure component on its own is not enough, it is only through the interaction of all system components that a practical security concept can be created.

The key factor here is how controllers, displays, communication networks and users are intended to interact. It is therefore essential to design a multi-layered security architecture, featuring independent layers of protection, already during the planning phase. These layers serve as input to the TARA (Threat Analysis and Risk Assessment), while taking into account the integrity and availability of the overall system.

ifm relies on a multi-layered security concept for its security assessment:

  • Focus on availability and integrity (typical of OT)
  • Defence in depth: multi-layered, independent protection mechanisms
  • Network segmentation to mitigate risk and safeguard independence

A system designed in this way remains resilient even when individual vulnerabilities exist (see image above).

Towards a cybersecure machine together

Cybersecurity is not limited to individual entities. As part of their legal obligations, all economic operators must initiate various activities and implement appropriate measures:

Manufacturer (ifm)

  • Develops devices that comply with directives and bear CE marking
  • Provides updates and documents security-related features
  • Supports its customers through documentation and training
  • Provides a dedicated platform for reporting cybersecurity vulnerabilities

OEM / system integrator

  • Is responsible for the safety, security and integrity of the overall system
  • Integrates components into the overall system, commissions it and places it on the market

Operator

  • Ensures safe operation in the field
  • Manages updates and access
  • Conducts regular risk assessments

Your benefits with ifm as a system partner

ifm supports these activities, provides the required device portfolio and the knowledge base needed for a compliant system integration.

Viewing legal requirements as an opportunity

The CRA will become mandatory in 2027, while cybersecurity incident reporting obligations already came into force as early as 2026. As a result, cybersecurity is becoming an obligatory requirement for placing mobile machines on the European market.

The key point here is that security requirements cannot be fully met at component level alone. A substantial part is created through the system architecture by connecting controllers, communications and applications.

ifm provides actionable indicators through

  • Clearly defined security levels in the context of functional safety

  • Clearly defined security level in the context of cybersecurity

This enables OEMs to clearly understand

  • Which protection levels can be achieved

  • Where system measures are required

  • When responsibility must be assumed at system level

ifm ensures that your machines remain fit for future updates, despite evolving threats and regulatory requirements. 

Your benefits from regulatory confidence with ifm

By adopting and integrating new regulatory requirements at an early stage, you can create a measurable competitive advantage for your application. Rather than merely achieving compliance, you can leverage demonstrable safety and cybersecurity measures to position safety and security as a clear competitive advantage over your competitors.

Everything you need for cybersecurity from a single source

With ifm, you receive a comprehensive, documented framework for cybersecurity:

Defined cybersecurity status

Specific security levels (IEC 62443 / prEN 50742*)

*prEN 50742 will be harmonised under the Machinery Regulation

Clear system responsibilities

Vulnerability management (PSIRT)

Update capability throughout the entire life cycle

All concisely summarised in the cybersecurity manual and product documentation

Security throughout the entire life cycle

TARA (Threat Analysis and Risk Assessment) identifies threats and risks at an early stage and forms the basis for security zones, protective measures and compliance documentation

TARA (Threat Analysis and Risk Assessment)

ifm ensures that your machines remain protected over the long term, despite evolving threats and regulatory requirements.

  • Updatable firmware for long-term security
  • Structured vulnerability management process (PSIRT)
  • Continuous development in line with current standards

Your benefits from long-term security and regulatory confidence

A clear and documented path to compliance with the CRA, the Machinery Regulation and UNECE R155, delivering not only regulatory confidence but also a sustainable competitive advantage.

Secure remote access to mobile machines

For connected machines, a secure way to perform diagnostics, updates and service tasks is required. With remoteConnect, ifm extends its cybersecurity strategy to include secure remote access to controllers, HMIs and other IP-based devices.

End-to-end encryption, zero trust, role-based access rights and local connection authorisation directly at machine level provide the foundation for secure remote maintenance.

Your benefits from secure and controlled remote access

Fewer on-site visits, faster response times and full control over every remote access session.

Cybersecurity certificates and documentation

ifm applies Security by Design from the very beginning of product development: certifications in accordance with IEC 62443-4-1 and ISO/SAE 21434 ensure the highest security standards throughout the development process. 

This cybersecurity strategy is complemented by a comprehensive information security management approach. Since 2012, ifm has operated an ISO/IEC 27001-certified Information Security Management System (ISMS), which is continuously being rolled out to additional locations and aligned with the requirements of the TISAX standard for information security in the automotive industry.

Explore all certificates and additional information here

FAQs