top of page
Engineering Blog for High Performance Insights


EU CRA Readiness
NOA SECURITY BRIEF: In this brief we look at key aspects that organizations need to build out to ensure that they are fully ready to conform to CRA (Cybersecurity Resiliency Act) a sustainable way. CRA compliance is looming for vendors and operators alike from now for reporting and in 15 months for product compliance. The ramification for non-compliant products is that they will lose their CE mark if they had it before. More importantly, substantial monetary penalties are
Scott Ludwick
Aug 2910 min read


Security Update - The Four Clocks for Operators
SECURITY BRIEF: In this posting we explore the operational aspects of deploying resolution of exploitable vulnerabilities by manufacturers in the field. This article is a companion to "The Four Clocks for Manufacturers" This edition addresses the asset owner and operator: the entity running the estate at the operations level, on whom NIS2’s risk-management measures and Article 23 reporting clocks bind directly (where in scope), and whose engineering obligations run through
Scott Ludwick
Aug 86 min read


Security Update - The Four Clocks for Manufacturers
CRA Article 14 compliance for manufacturers
Scott Ludwick
Aug 86 min read


CRA - Compliance by Consortium
POSITION NOTE: Through EU legislated CRA (Cybersecurity Resiliency Act) scope is product level, efforts are made to assert compliance by way of systems architecture - will this assertion hold water? We explore this question. In late 2025, EtherCAT Technology Group consortium announced that its protocol meets the requirements of the EU Cyber Resilience Act. The initial statement, from the EtherCAT Technology Group, was carefully qualified — the protocol was said to meet IEC
Scott Ludwick
Jul 312 min read


The Flow Down - How CRA Reaches Component Vendors
EXECUTIVE BRIEF: We look at the CRA impact to component vendors and what it means for OT device suppliers. The Cyber Resilience Act names one primary obligor: the manufacturer who places a product with digital elements on the EU market under its own name. Read narrowly, that puts the compliance burden on the device maker — the relay vendor, the RTU manufacturer, the drive OEM — and leaves the supply chain beneath them untouched. That narrow reading is already failing in prac
Scott Ludwick
Jul 257 min read


The Reporting Clock - The Countdown to CRA Compliance
EXECUTIVE BRIEF: We look at required reporting becoming effective September 11, 2026 and what it means for the installed base. 24 h EARLY WARNING AFTER AWARENESS 72 h FULL NOTIFICATION VIA THE SRP €15M / 2.5% MAXIMUM FINE (GLOBAL TURNOVER) On 11 September 2026, the first operative obligation of the EU Cyber Resilience Act takes effect: manufacturers of products with digital elements sold into the EU must report actively exploited vulnerabilities and severe incidents to their
Scott Ludwick
Jul 254 min read


Cryptography Challenges for Post Quantum OT Systems
EXECUTIVE BRIEF: Quantum computing will introduce cryptography challenges for Edge devices now and in the future. Here we look at this challenge relative to the OT environment. Quantum computing occupies an unusual position in the OT security conversation: it is simultaneously the reason current encryption will eventually fail and one of the technologies proposed to replace it. For OT and embedded environments, both sides of that story collide with the same structural proble
Scott Ludwick
Jul 128 min read


Navigating the EU Cybersecurity Resiliency Act: A Comprehensive Risk Assessment Guide
The European Union is advancing its approach to cybersecurity with the introduction of the Cybersecurity Resiliency Act. This legislation aims to strengthen the security of digital products and services across the EU, addressing the growing threats in an increasingly connected world. For organizations operating within or with the EU, understanding how to conduct a thorough risk assessment under this act is essential. This guide breaks down the key elements of the EU Cybersecu
Scott Ludwick
Jun 204 min read
bottom of page