Industrial cybersecurity is no longer just an IT concern. For OEM machine builders, it has become part of the machine specification itself. It’s a deciding factor in whether you win or lose an order, and in some markets it will soon determine whether you can sell into them at all.
At the PMMI Executive Leadership Conference in Amelia Island this past April, a panel called “Cybersecurity Is Now a Customer Requirement: What CPGs Expect from Suppliers” made this shift impossible to ignore. The Vice President of Digital Manufacturing and OT at Flowers Bakeries, Garth Basson, walked through exactly how a major CPG evaluates incoming machines today. Standardized hardware lists, mandatory network segmentation, documented firmware versions, scrutiny of the OEM’s own internal IT posture, and a new question on the table: what is your AI strategy. The insurance broker on the panel walked through the contractual exposure OEMs are now signing for if their machines become an attack vector.
The message for machine builders was direct. Your HMI is one of the most visible, network-connected, and policy-relevant components in your cabinet. The cybersecurity capabilities of that HMI are now part of how your machine gets evaluated, qualified, and contracted.
This blog post explains where Weintek stands today, what we have certified, and how our flexible licensing model lets OEMs adapt to a wide range of customer policies without redesigning the machine.
Industrial Cybersecurity Regulations Every OEM Should Know
The PMMI panel was a US end user conversation, but it sits on top of a much bigger international shift. A trade compliance session at the same conference highlighted active or upcoming cybersecurity regulations across more than twenty countries, including the European Union, United Kingdom, Canada, Brazil, India, China, Japan, South Korea, Australia, and the Gulf states.
Three of these have direct, near-term consequences for OEMs shipping packaging, processing, and industrial machinery.
The EU Cyber Resilience Act (CRA) is the big one. The CRA entered into force on December 10, 2024 and applies to any manufacturer placing connected products on the EU market, regardless of whether the company is headquartered in Europe or North America. For OEMs, CE marking will now require demonstrated cybersecurity compliance, with full enforcement on December 11, 2027. Industrial machinery falls into Class II under the CRA, which means third-party conformity assessment is required. Penalties can reach 2.5 percent of global annual revenue. Earlier deadlines are already on the calendar: by September 11, 2026, OEMs are subject to vulnerability reporting obligations and must produce a Software Bill of Materials (SBOM) documenting every digital component in the machine. And the CRA is not a one-time exercise. Manufacturers must maintain security updates for a minimum of ten years after sale.
The EU Machinery Regulation arrives in parallel. Enforcement begins in January 2027 and introduces Safety-Related Security Levels (SRSL), formally tying cybersecurity into the same conformity framework OEMs already use for machine safety. For machine builders, this means cybersecurity will be evaluated alongside risk assessments, much like functional safety is today.
The EU Radio Equipment Directive (RED) Delegated Act on cybersecurity has been in effect since August 2025 for wireless connected devices. Compliance is demonstrated through the EN 18031 family of harmonised standards.
In North America, the US Cyber Trust Mark IoT labeling program is moving toward federal procurement requirements from 2027 onward, with ioXt Alliance recently named the new lead administrator. State-level laws in California and Oregon are already in effect. And as the PMMI panel made clear, sophisticated CPGs are not waiting for regulation to push these requirements onto their OEM partners. They are already publishing them as procurement standards.
One useful way to think about all of this comes from the cybersecurity community itself. Cybersecurity for OEM machine builders is roughly where functional safety was ten to fifteen years ago. Then, safety was treated as a niche specialization handled by a few specialists in the engineering team. Today, every engineer at a competent OEM has a working understanding of IEC 61508 and ISO 13849. Cybersecurity is on the same trajectory, and the OEMs that build that competency now will be the ones still selling into major markets in 2027 and beyond.
Weintek Has Thirty Years of Building HMIs for OEMs
Weintek was founded in 1995 and began shipping HMIs the following year. That makes Weintek one of the pioneering manufacturers in the human-machine interface category, with thirty years of focused research, development, and manufacturing in a single product line. HMIs have been Weintek’s one and only priority since day one. The company does not make PLCs. It does not make drives. It does not make sensors. It makes HMIs, primarily for high-volume OEM machine builders, which is why you will find Weintek at PMMI events, PACK EXPO, and Automate year after year.
That thirty-year focus matters in a cybersecurity conversation because the certifications, the secure development lifecycle, and the operating system architecture that supports them are not bolted on. They are the product of long-term investment in a single category, driven by what our OEM customers tell us they need to put in front of their end users.
What Certifications OEMs can Claim with Weintek HMIs
Weintek HMIs are backed by three documented, third-party verified cybersecurity credentials.
IEC 62443-4-1 certification. Weintek holds IEC 62443-4-1 certification, the international standard for secure product development lifecycle in industrial control products. IEC 62443 is widely recognized as the framework most directly aligned with CRA requirements. When an end user procurement engineer or an EU conformity assessor asks whether the HMI vendor follows a structured secure development process, Weintek’s IEC 62443-4-1 certification is the documented answer.
EN 18031-1 certification. Weintek’s wireless-enabled product lineup has passed EN 18031-1 testing and earned certification. EN 18031-1 is the harmonised standard the European Union established to enforce the cybersecurity requirements of the revised Radio Equipment Directive. The certified lineup includes the cMT X Series with the M02 WiFi module, the cMT-SVR-200 and cMT-SVR-202, and the cMT-G02X. Beyond these specific SKUs, the same technical requirements have been applied across the broader cMT X portfolio.
EasyAccess 2.0 secure remote access. Weintek’s remote access solution uses 256 bit AES and 2048 bit RSA VPN Security and has been verified through an independent third-party security assessment. This is the component that enables encrypted, authenticated remote connectivity to Weintek HMIs in the field.
A note that any honest HMI vendor should make. Compliant components do not automatically equal a compliant machine. How an OEM architects the overall system, segments the network, manages remote access, documents the SBOM, and supports the machine over its operating life all factor into the final compliance picture. What certified components do is give the OEM a defensible starting point for those conversations. Specifying Weintek HMIs means the operator interface, one of the most exposed surfaces on the machine, is already built around current cybersecurity standards. The OEM still owns the rest of the architecture, but at least that part of the conversation is already answered.
Weintek HMI OS Has Built-In Security Features that Reduce Cyber Risk
With OS version V20251118 and later, Weintek HMIs ship with a Security by Default design principle. Each of the following is active out of the box, not optional. Each one also answers a specific question OEMs are starting to hear from their end users during qualification.
1. Mandatory strong password at first login.
Customer question: does your HMI ship with a default password?
Yes, the unit ships with an initial factory default password of 111111, but the new security requirements require the installer to change this to a secure password during setup for EN compliance. Account management is hardened across system levels. This eliminates one of the most common initial access vectors flagged in OT incident reports year after year.
2. System hardening with FTP and unnecessary services disabled by default.
Customer question: what services and ports are open on the HMI when it arrives at our plant?
By default, FTP is off. Unnecessary background services are off. Network transmission has been streamlined to reduce attack surface. If the OEM needs a service enabled for a specific deployment, that becomes a documented, deliberate decision rather than an inherited vulnerability.
3. TLS 1.2 or later encrypted communication by default.
Customer question: how is data secured in transit between the HMI and our network?
Encrypted communication uses TLS 1.2 or higher as the default protocol. Legacy protocols have been optimized to minimize exposure. This aligns with the direction the entire automation industry is moving, including the newest generation of controllers from major suppliers represented on the PMMI panel.
4. Unique secure device identity.
Customer question: how do we authenticate this device on our network?
Every Weintek HMI generates and stores a unique digital identity. This is the technical foundation for the kind of zero trust architectures that more enterprise IT teams are now pushing into OT environments, and it is the kind of capability the EU CRA’s third-party conformity assessment will be looking for.
5. Controlled environment protection for segmented OT networks.
Customer question: will this HMI integrate cleanly into our segmented OT network without becoming a weak link?
Modern industrial networks often rely on segmentation to separate production systems from enterprise networks and reduce the impact of potential security incidents. Weintek HMIs support deployment within these segmented architectures and can be configured to communicate across multiple network segments when appropriate. Models with dual Ethernet ports provide additional flexibility for connecting devices on separate networks while maintaining clear network boundaries.
The EasyAccess 2.0 Flexibility Advantage for OEMs
Machine builders ship the same machine to wildly different end users. Some have mature IT organizations with company-managed remote access solutions and strict policies against unmanaged VPN appliances in plant cabinets. The clear preference from these end users, as voiced repeatedly at the PMMI panel, is that OEMs use the customer-managed remote access path rather than bringing their own cellular modems or VPN hardware into the plant. Other end users have no remote access strategy in place and want the OEM to handle support connectivity entirely.
Weintek’s approach lets the same HMI specification serve both scenarios.
EasyAccess 2.0 is a built-in capability on every cMT X Series HMI, activated by a one-time license fee per unit. There is no subscription. The OEM decides whether to activate it.
For an end user with a managed remote access policy, the OEM simply does not activate the license on units shipped to that customer. No EasyAccess 2.0 connection is established. No additional remote access hardware is required in the cabinet. The customer uses their preferred VPN method to reach the HMI as needed.
For an end user without an existing remote access solution, the OEM activates EasyAccess 2.0 and the machine ships with a secure, third-party-assessed SSL VPN access path built directly into the HMI. No separate appliance, no separate cellular modem, no separate bill of materials line.
For OEMs serving multiple verticals or customer sizes, this means one HMI specification across the product line, with remote access configured per order. That is one less BOM variation to manage, and one less reason to redesign a panel when a different end user calls.
What OEMs Can Put on the Table Right Now
When an end user procurement team hands you a security questionnaire as part of an RFQ, here is what specifying Weintek HMIs lets you answer with documentation in hand.
- The HMI vendor holds IEC 62443-4-1 certification for secure product development lifecycle
- The HMI is certified to EN 18031-1, the harmonised cybersecurity standard for the EU Radio Equipment Directive
- Encryption is offered for a variety of communication protocols and services.
- Every device has a unique secure identity
- FTP and unnecessary services are disabled by default
- A mandatory strong password is required after first login with default credentials
- The architecture is designed to integrate cleanly into segmented OT networks
- Remote access is available as a licensed, optional capability, or can be left deactivated so the end user can use their own preferred VPN method
- Declaration of Conformity documentation is available for download
These answers do not make an entire machine compliant on their own. They do mean that one of the most exposed components on the machine is already built around current standards, and that the OEM walks into the cybersecurity conversation with documented credentials rather than a blank page.
What's Next for Industrial Cybersecurity Compliance
The September 11, 2026 EU CRA deadline for vulnerability reporting and SBOM obligations is less than a year out. The full CRA compliance deadline is December 11, 2027. The EU Machinery Regulation enforcement begins in January 2027. These deadlines are not optional for any OEM that wants to keep selling into the EU market. North American OEMs are not exempt simply because their headquarters are in the US or Canada.
Weintek’s product roadmap and OS release cadence are built around this reality. The defaults shipping in OS version V20251118 are the current baseline. Future releases will continue to extend these capabilities as the standards evolve and as our OEM customers tell us what their end users are asking for next.
Cybersecurity is quickly becoming a purchasing requirement rather than an optional feature. Choosing HMI software built around recognized security standards helps OEMs simplify compliance discussions today while preparing for tomorrow’s regulations.
If you are an OEM thinking about how to future-proof your machine designs for a changing cybersecurity certifications, we would love to have that conversation. Reach out to the Weintek USA team.
Key Takeaways:
- Supporting multiple protocols is essential for meeting strict application needs.
- The protocol chosen should always reflect the structure, processing speed, and feature requirements of the application.