secnostic sensor
captures the reachable digital components, their firmware levels, and communication relationships directly at the machine, at the FAT and, with the operator's approval, during operation as well.
secnostic registered trademark documents which digital components are installed in every delivered machine, at which firmware level, and with which communication relationships. That creates a reference state at delivery, and from it one central view of the installed machine base.
For machine and plant builders, special-purpose machinery, system integrators, and OEM service.
From 20 January 2027, Machinery Regulation 2023/1230 requires that relevant interventions in hardware, software, and configuration become traceable. The Cyber Resilience Act requires vulnerability handling during the support period for products within its scope. Both kinds of evidence start from the real state of every delivered machine, which the sensor records passively.
The EU Machinery Regulation 2023/1230 applies from 20 January 2027 and adds cyber safety to the essential requirements. The main obligations of the Cyber Resilience Act apply from 11 December 2027 to new products with digital elements within its scope, including vulnerability handling during the support period. The basis for both is the real state of every delivered machine; OT asset inventory guidance describes how to capture it without disrupting operations.
Between design, control cabinet assembly, software development, and commissioning, components and version levels change. What matters is not what was planned, but what is actually inside the machine at delivery. With the CRA and the Machinery Regulation, that real product state becomes commercially relevant.
After handover, the real question begins: what is inside which machine at which customer?
Between engineering, cabinet assembly, and commissioning, components and versions change until acceptance.
After handover, software and firmware levels can only be reconstructed from project folders and service reports.
A vendor advisory for one firmware version starts a search across projects, customers, and machines.
Six stations in a machine's life where the same documented state keeps working.
What should be inside the machine?
Target structure, approved components, and documented target levels from engineering form the reference for the later comparison.
What is actually inside?
The secnostic registered trademark sensor passively captures the reachable controllers, HMIs, industrial PCs, switches, and drives with addresses and firmware levels, where technically available. Target and actual are compared before acceptance.
Which state leaves the factory?
The approved state is documented as the reference: the technical fingerprint of the delivered machine.
Does the machine still match delivery?
Only with the operator's approval does the sensor keep observing. Changes against the reference state then become traceable: replaced components, new firmware levels, additional devices.
Which machines does a new vulnerability hit?
A vendor advisory becomes a query against the installed base: component, version, affected machines, customers. The assessment stays with the manufacturer.
How does the base age?
Hardware, firmware, EOL/EOS, and changes stay assigned to each machine and customer, from a single asset to the whole installed base.
Four recurring situations between factory, customer, and installed base, each as a concrete flow.
The modules play different roles in the deployment: observation, inventory, platform governance, and handover to the right people.
captures the reachable digital components, their firmware levels, and communication relationships directly at the machine, at the FAT and, with the operator's approval, during operation as well.
brings the states of all delivered machines together into the installed base and keeps reference state, changes, vulnerabilities, and lifecycle traceable per machine and customer.
Key questions before a first scoping conversation.
No. Risk assessment, SBOM, conformity assessment, and CE marking remain the manufacturer's tasks. secnostic registered trademark provides the technical transparency those processes build on: to assess a vulnerability, you first need to know which components and versions are actually used in which machine.
The reachable digital components such as controllers, remote I/O, HMIs, industrial PCs, switches, drives, and other intelligent field devices with IP and MAC address, vendor, device type, and software and firmware levels where technically available, plus the communication relationships inside the machine. Components that are not IP-based or sit behind gateways need supplementary engineering or vendor data.
During an incident, the analysis no longer starts with the question of what is installed there. The reference state is documented, and the comparison with the current state shows whether components were replaced, firmware levels changed, devices added, or communication paths introduced.
That is decided by the machine builder and the operator together. The sensor can remain part of the delivered machine and, with the operator's approval, keep observing passively; the data stays assigned to the operator and the individual machine. Without a sensor in operation, the documented delivered state still remains as the reference.
EU Machinery Regulation 2023/1230 applies from 20 January 2027 and adds cyber safety to the essential requirements. The main obligations of the Cyber Resilience Act apply from 11 December 2027 to new products with digital elements that fall within its scope, including risk assessment, technical documentation, and vulnerability handling during the support period. NIS2 addresses organizations, not products; affectedness has to be assessed per organization, so for the delivered machine NIS2 is only a supporting consideration.
We start with one machine type, one FAT, or one concrete vulnerability question, show which reference state and which installed-base view become usable immediately, and discuss which operating model fits your machine base.
Discuss the installed base