From FAT to lifecycle: every machine in view

secnostic registered trademark documents which digital components are installed in every delivered machine, at which firmware level, and with which communication relationships. That creates a reference state at delivery, and from it one central view of the installed machine base.

For machine and plant builders, special-purpose machinery, system integrators, and OEM service.

From FAT to lifecycle

From 20 January 2027, Machinery Regulation 2023/1230 requires that relevant interventions in hardware, software, and configuration become traceable. The Cyber Resilience Act requires vulnerability handling during the support period for products within its scope. Both kinds of evidence start from the real state of every delivered machine, which the sensor records passively.

What this covers

The EU Machinery Regulation 2023/1230 applies from 20 January 2027 and adds cyber safety to the essential requirements. The main obligations of the Cyber Resilience Act apply from 11 December 2027 to new products with digital elements within its scope, including vulnerability handling during the support period. The basis for both is the real state of every delivered machine; OT asset inventory guidance describes how to capture it without disrupting operations.

Between design, control cabinet assembly, software development, and commissioning, components and version levels change. What matters is not what was planned, but what is actually inside the machine at delivery. With the CRA and the Machinery Regulation, that real product state becomes commercially relevant.

Outcomes

  • a documented reference state of every machine at delivery
  • one central installed base across customers and machines
  • affected machines found precisely when an advisory lands
  • technical evidence for the CRA and the Machinery Regulation

What stays open without a documented machine state

After handover, the real question begins: what is inside which machine at which customer?

Target and actual drift apart

Between engineering, cabinet assembly, and commissioning, components and versions change until acceptance.

Firmware levels live in project folders

After handover, software and firmware levels can only be reconstructed from project folders and service reports.

An advisory with no link to the base

A vendor advisory for one firmware version starts a search across projects, customers, and machines.

Warranty without a reference

During a warranty incident it is unclear whether the machine still matches the state that was delivered.

From engineering to the installed base

Six stations in a machine's life where the same documented state keeps working.

  1. Engineering

    What should be inside the machine?

    Target structure, approved components, and documented target levels from engineering form the reference for the later comparison.

  2. FAT and final inspection

    What is actually inside?

    The secnostic registered trademark sensor passively captures the reachable controllers, HMIs, industrial PCs, switches, and drives with addresses and firmware levels, where technically available. Target and actual are compared before acceptance.

  3. Delivery

    Which state leaves the factory?

    The approved state is documented as the reference: the technical fingerprint of the delivered machine.

  4. Warranty and service

    Does the machine still match delivery?

    Only with the operator's approval does the sensor keep observing. Changes against the reference state then become traceable: replaced components, new firmware levels, additional devices.

  5. Vulnerability management

    Which machines does a new vulnerability hit?

    A vendor advisory becomes a query against the installed base: component, version, affected machines, customers. The assessment stays with the manufacturer.

  6. Lifecycle

    How does the base age?

    Hardware, firmware, EOL/EOS, and changes stay assigned to each machine and customer, from a single asset to the whole installed base.

Across the machine's life, four situations

Four recurring situations between factory, customer, and installed base, each as a concrete flow.

  1. CaptureAt the FAT, the sensor captures the actual state of the machine without disturbing the test run.
  2. ReconcileThe target structure and approved components from engineering are compared with the actual state.
  3. ResolveDeviations are resolved before acceptance instead of being discovered later at the customer.
  4. DocumentThe approved state is recorded as the reference of the delivered machine.

FAQ

Key questions before a first scoping conversation.

Does secnostic replace the risk assessment, the SBOM, or the CE process?

No. Risk assessment, SBOM, conformity assessment, and CE marking remain the manufacturer's tasks. secnostic registered trademark provides the technical transparency those processes build on: to assess a vulnerability, you first need to know which components and versions are actually used in which machine.

What does the secnostic sensor capture in a machine?

The reachable digital components such as controllers, remote I/O, HMIs, industrial PCs, switches, drives, and other intelligent field devices with IP and MAC address, vendor, device type, and software and firmware levels where technically available, plus the communication relationships inside the machine. Components that are not IP-based or sit behind gateways need supplementary engineering or vendor data.

How does the documented delivered state help during warranty?

During an incident, the analysis no longer starts with the question of what is installed there. The reference state is documented, and the comparison with the current state shows whether components were replaced, firmware levels changed, devices added, or communication paths introduced.

Does the sensor stay in the machine after delivery?

That is decided by the machine builder and the operator together. The sensor can remain part of the delivered machine and, with the operator's approval, keep observing passively; the data stays assigned to the operator and the individual machine. Without a sensor in operation, the documented delivered state still remains as the reference.

What role do the CRA, the Machinery Regulation, and NIS2 play?

EU Machinery Regulation 2023/1230 applies from 20 January 2027 and adds cyber safety to the essential requirements. The main obligations of the Cyber Resilience Act apply from 11 December 2027 to new products with digital elements that fall within its scope, including risk assessment, technical documentation, and vulnerability handling during the support period. NIS2 addresses organizations, not products; affectedness has to be assessed per organization, so for the delivered machine NIS2 is only a supporting consideration.

Start with one machine

We start with one machine type, one FAT, or one concrete vulnerability question, show which reference state and which installed-base view become usable immediately, and discuss which operating model fits your machine base.

Discuss the installed base