www.industryemea.com
21
'26
Written on Modified on
PHYTEC and ML!PA Launch phyHUB Device Management Platform
The managed service helps manufacturers meet new EU Cyber Resilience Act reporting deadlines with secure OTA updates.
www.phytec.com

PHYTEC Messtechnik GmbH has launched phyHUB, a managed device management platform developed in strategic partnership with ML!PA Consulting GmbH, to help manufacturers comply with the newly effective EU Cyber Resilience Act (CRA). Backed by a seven-figure upfront investment, the platform builds upon ML!PA's L-IoT architecture, delivering an operations layer that requires no customer-built infrastructure. Since September 11, 2026, the CRA mandates that manufacturers of products with digital elements report actively exploited vulnerabilities within 24 hours. To meet these strict operational deadlines, phyHUB provides essential lifecycle capabilities, including signed over-the-air (OTA) updates with staging and rollback functionality, fleet health monitoring, and automated software bill of materials (SBOM) vulnerability matching.
Unlike ML!PA’s standard single-tenant installations, phyHUB operates as a multi-tenant, hardware-agnostic platform managed entirely by PHYTEC and hosted on Microsoft Azure in Europe. This allows companies to maintain control over their device fleets—including third-party hardware and legacy installed bases—without the burden of managing the underlying IT infrastructure. The service integrates directly with PHYTEC's maintenance operations in Mainz, Germany, where root-of-trust key generation, encryption, and secure boot provisioning physically take place before the modules are shipped. Reference integrations for PHYTEC modules will be available in the fourth quarter of 2026, with live demonstrations scheduled for upcoming industry events including electronica and SPS.
Additional Context
This section provides technological and market background not explicitly detailed in the original release.
The EU Cyber Resilience Act (CRA) fundamentally shifts product cybersecurity from a voluntary best practice to a strict legal obligation. While the full CE-marking requirements apply in December 2027, the Article 14 reporting phase is already active, forcing manufacturers to disclose severe incidents and actively exploited vulnerabilities within 24 hours via the European Union Agency for Cybersecurity's (ENISA) Single Reporting Platform. Failure to comply with these new reporting obligations can result in severe administrative fines of up to €15 million or 2.5% of a company's total worldwide annual turnover for the preceding financial year. For embedded systems manufacturers, complying with this 24-hour reporting window is practically impossible without a robust remote management layer. If a vulnerability is found in a deployed edge device, the manufacturer must know exactly which software components are running (via SBOMs) and be capable of deploying a cryptographic, fail-safe OTA patch to the field immediately. By anchoring the root of trust at the point of physical manufacturing and linking it to a continuous Common Vulnerabilities and Exposures (CVE) assessment service, platforms like phyHUB prevent industrial original equipment manufacturers (OEMs) from being locked out of the European market due to an inability to securely update their aging product fleets.
Edited by Lekshman Ramdas, Induportals editor – adapted by AI.
www.phytec.com

