Security Question

Daniel Creasey, the Panasonic Toughbook UK Marketing Manager, wrote a very interesting blog I’d like to share with you …

Your device supplier has 77 days to answer this security question. Can they?

The EU and UK are both introducing new device security regulations that go way beyond having Norton Antivirus installed. We’re talking about hardware integrity. Supply chain trust. Security that exists before your OS even loads.

Article content
Why is there a doctor on this? is it Dr Norton?

Some people, like little old me, didn’t even know this was coming in!

Two regulations. Same destination.

Article content

In the EU, the Cyber Resilience Act is already in force. The first enforcement deadline, mandatory vulnerability and incident reporting within 24 hours, lands on 11 September 2026. Full compliance covering secure by design, supply chain integrity, vulnerability management and lifecycle governance follows in December 2027.

In the UK, the Cyber Security and Resilience Bill is moving through Parliament right now and is expected to receive Royal Assent (God Save the King) in 2026. The requirements are strikingly similar, 24 hour incident reporting, strengthened supply chain security obligations, and fines of up to £17 million or 4% of worldwide turnover for serious breaches.

Different legislation. Different deadlines. Same direction of travel.

If you deploy connected devices in operational environments, and in defence, utilities, emergency services, logistics or healthcare, you almost certainly do, both of these frameworks are heading your way. The question is whether your device supplier is ahead of them or scrambling to catch up.

Going beyond software

Most of the regulatory conversation in the industry is focused on software, patch management, vulnerability disclosure, incident reporting workflows. Those matter. But both the EU CRA and the UK bill have equally demanding requirements around hardware integrity and supply chain security that are getting far less attention.

Specifically, regulators expect connected devices to demonstrate:

  • That hardware components remain unchanged from the factory approved configuration (Fiddling detection pt1)
  • That unauthorised component swaps or tampering can be detected (Fiddling detection pt2)
  • That security is maintained throughout the full device lifecycle from manufacture through end of life (Are your suppliers going to ghost you?)
  • That supply chain integrity can be evidenced, not just claimed (Show me the money!! or in this case, show me the evidence for supply chain integrity)

This is where it gets interesting. Because demonstrating hardware integrity at that level isn’t something you can bolt on with a software update. It has to be built into the device from the ground up. You can’t Patch Adams your way to a trustworthy supply chain.

The question worth asking your supplier

If you’re evaluating or deploying rugged devices (or any devices, I just love a rugged device, it’s my kink) in any environment that falls under these frameworks, and most operational environments do, there’s a simple question worth putting to your device supplier:

How does your hardware demonstrate compliance with hardware integrity requirements at the device level, not just the software layer? – this will make them sweat, and not just because the UK is melting.

It’s a straightforward question. The answers you get back will be very revealing. Some suppliers will have a clear, confident response. Others will send you a very long email that somehow says nothing.

Where Panasonic stands

I’ll be transparent here because I work at Panasonic TOUGHBOOK, so you should know where I’m coming from. Nobody likes a surprise vendor pitch dressed up as thought leadership 😉

Panasonic is aligning to the Cyber Resilience Act and already meets many of the technical requirements through TOUGHBOOK design and security features. TOUGHBOOK Guard, our embedded firmware-based hardware integrity feature, aligns strongly with the secure by design and supply chain requirements that both frameworks demand. It validates hardware configuration against an approved baseline before the OS loads, detects unauthorised component changes, and works in offline and air-gapped environments where software tools simply can’t reach.

Full CRA compliance is a formal process that will be completed ahead of the 2027 enforcement deadline.

But the broader point stands regardless of which device you use. The regulatory direction is clear. Hardware integrity is becoming a legal requirement, not just best practice. And the time to ask your supplier the hard questions is now, not when the deadline is two weeks away.

We’re on the motorway and we can’t get off

Whether it’s the EU CRA, the UK Cyber Security and Resilience Bill, or whatever comes next, regulators on both sides of the Channel are aligned on one thing: connected devices deployed in critical environments need to be secure by design, verifiable throughout their lifecycle, and supported by suppliers who can demonstrate it. It’s inevitable, like a Greggs on your long motorway trip.

 

Let me know if you would like more information …