Digi solutions are secure by design. We offer comprehensive CRA compliance support including automated vulnerability scanning, secure remote updates, and expert consulting throughout the product lifecycle via Digi TrustFence, Digi ConnectCore Security Services, Digi ConnectCore Cloud Services, and Digi Embedded Yocto.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Readers should not act upon any information presented herein without seeking professional counsel. For advice regarding your specific situation or for interpretation of applicable laws, please consult a qualified attorney.

Digi security building blocks

Digi TrustFence

Digi TrustFence helps you build security directly into IoT devices, supporting both security-by-design and secure configuration through features such as secure boot, secure console, secure software updates, encrypted file system, and protected hardware and pins.

Digi ConnectCore Security Services

Digi ConnectCore Security Services feature a range of tools to help organizations address the CRA’s essential cybersecurity requirements, both cybersecurity requirements relating to the properties of products, and vulnerability handling requirements.

This includes consistently analyzing and monitoring a custom SBOM running on Digi ConnectCore SOMs for security vulnerabilities. To help remediate critical issues, the services provide curated vulnerability reports, a security software layer with pre-integrated patches and fixes for common vulnerabilities, and expert consulting and support services.

Digi ConnectCore Cloud Services

Digi ConnectCore Cloud Services, based on the Digi Remote Manager® platform, help you remotely configure, monitor, and maintain connected devices via automated mass firmware and software updates, bi-directional communication, real-time alerts, and detailed reports on device conditions.

Digi Embedded Yocto

An open-source Linux distribution based on the Yocto Project™, Digi Embedded Yocto is designed specifically for ConnectCore SOMs. It helps embedded developers fulfill CRA compliance obligations through a combination of Digi-owned software maintenance, robust patch policy, and full integration with Digi TrustFence and Digi ConnectCore Security and Cloud Services.

Building blocks mapped to CRA requirements

The following tables contain the twenty-two cybersecurity and vulnerability handling requirements, mapped to Digi TrustFence, Digi ConnectCore Security Services, Digi ConnectCore Cloud Services, and the Digi Embedded Yocto operating system.

Part I: Product security requirements

Part I

Description

Digi TrustFence

Digi ConnectCore Security Services

Digi ConnectCore Cloud Services

Digi Embedded Yocto

(1)

Products shall be designed, developed and produced ensuring an appropriate level of cybersecurity based on the risks

TrustFence overall

Security services overall

Cloud services overall

Digi Embedded Yocto overall

(2) (a)

Products shall be made available without known exploitable vulnerabilities

N/A

Custom SBOM scans, meta-digi-security

Digi Remote Manager Vulnerability Patch Policy

Digi-owned software maintenance

(2) (b)

Products shall be made available with a secure by default configuration

TrustFence overall

N/A

N/A

Hardened Digi Embedded Yocto

(2) (c)

Products shall ensure that vulnerabilities can be addressed through security updates

Secure software update

meta-digi-security, consulting and support

Secure remote OTA software updates

Secure software update, dual boot configuration

(2) (d)

Products shall ensure protection from unauthorized access

Secure console, secure JTAG

N/A

N/A

SSH/TLS

(2) (e)

Products shall protect the confidentiality of stored, transmitted or otherwise processed data, personal or other

Encrypted file system / files (hardware bound)

N/A

File system access, TLS, certificate-based authentication and encryption

Encryption, WPA3, FIPS 140-2/3 (additional cost)

(2) (f)

Products shall protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration

Secure boot / authenticated file system

N/A

File system access, TLS, certificate-based authentication and encryption

TLS, read-only file system

(2) (g)

Products shall process only data, personal or other, that are adequate, relevant and limited to what is necessary

N/A

N/A

Custom data streams

N/A

(2) (h)

Products shall protect the availability of essential and basic functions against denial-of-service attacks

N/A

N/A

N/A

Embedded systems security best practices

(2) (i)

Products shall minimize the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks

N/A

N/A

N/A

Embedded systems security best practices

(2) (j)

Products shall be designed, developed and produced to limit attack surfaces, including external interfaces

Secure boot, secure console, secure JTAG, tamper detection

meta-digi-security, consulting and support

N/A

N/A

(2) (k)

Products shall be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques

Tamper detection

N/A

Templates

N/A

(2) (l)

Products shall provide security related information by recording and monitoring relevant internal activity

Tamper detection

N/A

Security monitoring agent

N/A

(2) (m)

Products shall provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner

N/A

N/A

File system access, Digi RM data/settings management

N/A

Part II: Vulnerability handling requirements

Part II

Description

Digi TrustFence

Digi ConnectCore Security Services

Digi ConnectCore Cloud Services

Digi Embedded Yocto

(1)

Manufacturers shall draw up a software bill of materials in a commonly used and machine-readable format

N/A

Custom SBOM creation

N/A

Digi Embedded Yocto SBOM

(2)

Manufacturers shall address and remediate vulnerabilities without delay

N/A

meta-digi-security, consulting and support

Secure remote OTA software updates, templates

Digi Embedded Yocto regular releases

(3)

Manufacturers shall apply effective and regular tests and reviews of the security of the product

N/A

Custom SBOM scans

Digi RM Vulnerability Patch Policy

Digi Embedded Yocto Patch Policy

(4)

Manufacturers shall share and publicly disclose information about fixed vulnerabilities

N/A

Security Services overall

Digi Security Center

Digi Security Center

(5)

Manufacturers shall put in place and enforce a policy on coordinated vulnerability disclosure

N/A

N/A

Digi RM Vulnerability Patch Policy, Digi Security Center

Digi Embedded Yocto Patch Policy, Digi Embedded GitHub, Digi Security Center

(6)

Manufacturers shall facilitate the sharing of information about potential vulnerabilities including by providing a contact address for the reporting of the vulnerabilities discovered

N/A

N/A

Digi security form

Digi security form

(7)

Manufacturers shall provide for mechanisms to securely distribute updates to ensure that vulnerabilities are fixed or mitigated in a timely manner

Secure software update

N/A

Secure remote OTA software updates, templates, TLS, certificate-based authentication and encryption

N/A

(8)

Manufacturers shall ensure that, where security updates are available, they are disseminated without delay and, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken

N/A

N/A

Secure remote OTA software updates, templates

Digi Embedded Yocto Patch Policy, Digi Embedded GitHub

For a more detailed look at how Digi is committed to helping you navigate the requirements, download our comprehensive guide Complying with the Cyber Resilience Act (CRA).