Digi solutions are secure by design. We offer comprehensive CRA compliance support including automated vulnerability scanning, secure remote updates, and expert consulting throughout the product lifecycle via Digi TrustFence, Digi ConnectCore Security Services, Digi ConnectCore Cloud Services, and Digi Embedded Yocto.
| Disclaimer: This article is for informational purposes only and does not constitute legal advice. Readers should not act upon any information presented herein without seeking professional counsel. For advice regarding your specific situation or for interpretation of applicable laws, please consult a qualified attorney. |
Digi security building blocks
Digi TrustFence
Digi TrustFence helps you build security directly into IoT devices, supporting both security-by-design and secure configuration through features such as secure boot, secure console, secure software updates, encrypted file system, and protected hardware and pins.
Digi ConnectCore Security Services
Digi ConnectCore Security Services feature a range of tools to help organizations address the CRA’s essential cybersecurity requirements, both cybersecurity requirements relating to the properties of products, and vulnerability handling requirements.
This includes consistently analyzing and monitoring a custom SBOM running on Digi ConnectCore SOMs for security vulnerabilities. To help remediate critical issues, the services provide curated vulnerability reports, a security software layer with pre-integrated patches and fixes for common vulnerabilities, and expert consulting and support services.
Digi ConnectCore Cloud Services
Digi ConnectCore Cloud Services, based on the Digi Remote Manager® platform, help you remotely configure, monitor, and maintain connected devices via automated mass firmware and software updates, bi-directional communication, real-time alerts, and detailed reports on device conditions.
Digi Embedded Yocto
An open-source Linux distribution based on the Yocto Project™, Digi Embedded Yocto is designed specifically for ConnectCore SOMs. It helps embedded developers fulfill CRA compliance obligations through a combination of Digi-owned software maintenance, robust patch policy, and full integration with Digi TrustFence and Digi ConnectCore Security and Cloud Services.
Building blocks mapped to CRA requirements
The following tables contain the twenty-two cybersecurity and vulnerability handling requirements, mapped to Digi TrustFence, Digi ConnectCore Security Services, Digi ConnectCore Cloud Services, and the Digi Embedded Yocto operating system.
Part I: Product security requirements
Part I |
Description |
Digi TrustFence |
Digi ConnectCore Security Services |
Digi ConnectCore Cloud Services |
Digi Embedded Yocto |
|---|---|---|---|---|---|
(1) |
Products shall be designed, developed and produced ensuring an appropriate level of cybersecurity based on the risks |
TrustFence overall |
Security services overall |
Cloud services overall |
Digi Embedded Yocto overall |
(2) (a) |
Products shall be made available without known exploitable vulnerabilities |
N/A |
Custom SBOM scans, meta-digi-security |
||
(2) (b) |
Products shall be made available with a secure by default configuration |
TrustFence overall |
N/A |
N/A |
Hardened Digi Embedded Yocto |
(2) (c) |
Products shall ensure that vulnerabilities can be addressed through security updates |
Secure software update |
meta-digi-security, consulting and support |
Secure remote OTA software updates |
Secure software update, dual boot configuration |
(2) (d) |
Products shall ensure protection from unauthorized access |
Secure console, secure JTAG |
N/A |
N/A |
SSH/TLS |
(2) (e) |
Products shall protect the confidentiality of stored, transmitted or otherwise processed data, personal or other |
Encrypted file system / files (hardware bound) |
N/A |
File system access, TLS, certificate-based authentication and encryption |
Encryption, WPA3, FIPS 140-2/3 (additional cost) |
(2) (f) |
Products shall protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration |
Secure boot / authenticated file system |
N/A |
File system access, TLS, certificate-based authentication and encryption |
TLS, read-only file system |
(2) (g) |
Products shall process only data, personal or other, that are adequate, relevant and limited to what is necessary |
N/A |
N/A |
Custom data streams |
N/A |
(2) (h) |
Products shall protect the availability of essential and basic functions against denial-of-service attacks |
N/A |
N/A |
N/A |
Embedded systems security best practices |
(2) (i) |
Products shall minimize the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks |
N/A |
N/A |
N/A |
Embedded systems security best practices |
(2) (j) |
Products shall be designed, developed and produced to limit attack surfaces, including external interfaces |
Secure boot, secure console, secure JTAG, tamper detection |
meta-digi-security, consulting and support |
N/A |
N/A |
(2) (k) |
Products shall be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques |
Tamper detection |
N/A |
Templates |
N/A |
(2) (l) |
Products shall provide security related information by recording and monitoring relevant internal activity |
Tamper detection |
N/A |
Security monitoring agent |
N/A |
(2) (m) |
Products shall provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner |
N/A |
N/A |
File system access, Digi RM data/settings management |
N/A |
Part II: Vulnerability handling requirements
Part II |
Description |
Digi TrustFence |
Digi ConnectCore Security Services |
Digi ConnectCore Cloud Services |
Digi Embedded Yocto |
|---|---|---|---|---|---|
(1) |
Manufacturers shall draw up a software bill of materials in a commonly used and machine-readable format |
N/A |
Custom SBOM creation |
N/A |
Digi Embedded Yocto SBOM |
(2) |
Manufacturers shall address and remediate vulnerabilities without delay |
N/A |
meta-digi-security, consulting and support |
Secure remote OTA software updates, templates |
|
(3) |
Manufacturers shall apply effective and regular tests and reviews of the security of the product |
N/A |
Custom SBOM scans |
||
(4) |
Manufacturers shall share and publicly disclose information about fixed vulnerabilities |
N/A |
Security Services overall |
||
(5) |
Manufacturers shall put in place and enforce a policy on coordinated vulnerability disclosure |
N/A |
N/A |
Digi Embedded Yocto Patch Policy, Digi Embedded GitHub, Digi Security Center |
|
(6) |
Manufacturers shall facilitate the sharing of information about potential vulnerabilities including by providing a contact address for the reporting of the vulnerabilities discovered |
N/A |
N/A |
||
(7) |
Manufacturers shall provide for mechanisms to securely distribute updates to ensure that vulnerabilities are fixed or mitigated in a timely manner |
Secure software update |
N/A |
Secure remote OTA software updates, templates, TLS, certificate-based authentication and encryption |
N/A |
(8) |
Manufacturers shall ensure that, where security updates are available, they are disseminated without delay and, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken |
N/A |
N/A |
Secure remote OTA software updates, templates |
| For a more detailed look at how Digi is committed to helping you navigate the requirements, download our comprehensive guide Complying with the Cyber Resilience Act (CRA). |