Axiomtek Moves Early on EU Cyber Resilience Act Compliance
With IEC 62443-4-1 Maturity Level 2 already certified, Axiomtek is now pushing security down to the product level ahead of CRA enforcement — a signal procurement teams should watch closely.
Industrial computing supplier Axiomtek has confirmed it is extending its cybersecurity programme to meet the requirements of the EU Cyber Resilience Act (CRA), building on an existing IEC 62443-4-1 Maturity Level 2 certification for its secure development lifecycle. The company says it is now preparing its first IEC 62443-4-2 SL2 product certification, moving cybersecurity from a process-level guarantee to a product-level one.
This distinction matters. A certified development process shows that a vendor builds products responsibly; a certified product shows that the resulting hardware actually meets defined security levels — the kind of evidence procurement teams and system integrators will increasingly need to reference when specifying equipment for regulated markets under the CRA.
Why this matters for buyers
The CRA imposes obligations across both product design and lifecycle support, including vulnerability disclosure and incident response under Articles 13 and 14. Axiomtek says it is formalising these processes and expanding firmware tracking and SBOM (software bill of materials) coverage, dependent on chipset and firmware vendor roadmaps — a reminder that CRA compliance is only as strong as the weakest link in the supply chain.
On the hardware side, the company points to TPM 2.0, Secure Boot, and BIOS/firmware protection as the practical mechanisms underpinning its SL2 ambitions. For engineers specifying embedded or edge systems destined for energy, transportation, or critical infrastructure projects, these are not abstract checkboxes — they determine whether a platform can be integrated into a CRA-compliant end product without costly rework later.
“The EU Cyber Resilience Act reinforces what Axiomtek has long believed: cybersecurity must be built into products from the beginning and supported throughout the product lifecycle,” said Tab, head of Axiomtek’s Firmware Development Department.
Nordic relevance
For Nordic operators in energy, maritime, and critical infrastructure — sectors already under pressure from NIS2 alongside the CRA — early vendor alignment reduces downstream compliance risk. Specifiers in Sweden, Norway, Finland, and Denmark evaluating rugged computing platforms for long-lifecycle deployments should treat IEC 62443-4-2 readiness as a practical shortlist criterion, not a future consideration.
As CRA enforcement timelines approach, vendors that can demonstrate both certified processes and certified products will have a clear procurement advantage over those still catching up.