Development, begins together.
Banner alanı
IFM Sensor

🚀 Revolutionary Device Management Platform from PHYTEC and ML!PA: phyHUB! 🚀

Süeda Asil

Corporate
  • AQUA Automation
  • art_593_4717dfd3b524542dcc18e8c844551d97.jpg

    🔒 Compliance with the EU Cyber Resilience Act is Now Easy!​


    PHYTEC Messtechnik GmbH, in a strategic partnership with ML!PA Consulting GmbH, has introduced phyHUB, a managed device management platform designed to help manufacturers meet the requirements of the newly enacted EU Cyber Resilience Act (CRA). Backed by a seven-figure initial investment, this platform is built on ML!PA's L-IoT architecture and provides an operational layer without requiring customers to set up infrastructure.

    🚨 24-Hour Notification Requirement!​


    From September 11, 2026, the CRA mandates that manufacturers of products with digital elements report actively exploited vulnerabilities within 24 hours. phyHUB offers critical lifecycle capabilities to meet these stringent operational deadlines:

    • Signed, staged, and rollback-capable over-the-air (OTA) updates
    • Fleet health monitoring
    • Automated Software Bill of Materials (SBOM) vulnerability matching

    ☁️ Multi-Tenant and Hardware-Independent Solution​


    Unlike ML!PA's standard single-tenant deployments, phyHUB operates as a multi-tenant, hardware-independent platform fully managed by PHYTEC and hosted on Microsoft Azure in Europe. This allows companies to gain control over their device fleets, including third-party hardware and legacy installed bases, without the burden of managing core IT infrastructure.

    The service integrates directly with PHYTEC's maintenance operations in Mainz, Germany. Here, root of trust key generation, encryption, and secure boot provisioning are physically performed before modules are shipped. Reference integrations for PHYTEC modules will be available in Q4 2026, with live demos at industry events such as electronica and SPS.

    ⚖️ Importance of CRA and phyHUB's Role​


    The EU Cyber Resilience Act (CRA) transforms product cybersecurity from a voluntary best practice into a strict legal obligation. While the full CE mark requirements come into effect in December 2027, the Article 14 reporting phase is already active. This compels manufacturers to disclose serious incidents and actively exploited vulnerabilities within 24 hours via the European Union Agency for Cybersecurity's (ENISA) Single Reporting Platform.

    Failure to comply with these new reporting obligations can lead to severe administrative fines of up to 15 million Euros or 2.5% of a company's total worldwide annual turnover from the previous financial year. For embedded system manufacturers, meeting this 24-hour reporting window without a robust remote management layer is nearly impossible. When a vulnerability is found in a distributed edge device, the manufacturer needs to know exactly which software components are running (via SBOMs) and be able to deploy an immediate cryptographic, fault-tolerant OTA patch to the field. By anchoring the root of trust at the physical point of manufacture and linking this to a continuous Common Vulnerabilities and Exposures (CVE) assessment service, platforms like phyHUB prevent industrial original equipment manufacturers (OEMs) from being excluded from the European market due to their inability to securely update aging product fleets.
     
    Back
    Top