Practical knowledge for IT and OT

Answer-first guidance for teams that need to discover, understand, and secure IT and OT assets. Built with clear boundaries, visible sources, and directly usable models.

CRA, CE, and asset discovery for machinery

The main CRA obligations apply from 11 December 2027 to new products with digital elements. Where their product falls within scope, machine builders need to assess cybersecurity risks, maintain technical evidence, handle vulnerabilities throughout the support period, and declare conformity before placing the product on the market. The CRA does not literally mandate an automated inventory of every network device. A current OT asset inventory does, however, provide operational data for checking product scope, firmware states, and change.

Read the guide

ITAM vs. OTAM in operations

ITAM and OTAM need a shared data model but different collection and operating rules. CISA structures OTAM as a maintained asset inventory plus a taxonomy for function, criticality, communication paths, and dependencies. For critical infrastructure operators, the BSI catalogue adds expectations for completeness, accuracy, currency, consistency, accountability, and traceable change.

Read the guide