Starting September 11, 2026, the EU CRA (Cyber Resilience Act) is giving manufacturers 24 hours to report an actively exploited vulnerability. In OT (Operational Technology) environments, the incidents most likely to start that clock arrive on a USB drive, and most operators still can't tell you where that drive went next.
A 24 Hour Clock Is Really a Visibility Test.
As of September 11, 2026, manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe security incidents. The timeline is strict: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report within 14 days of a corrective measure being available for actively exploited vulnerabilities, or within a month for severe incidents.
Notice what the clock is anchored to: becoming aware. Every deadline in the regulation assumes you can detect the event, reconstruct how it happened, and describe the corrective measure. That is a documentation and telemetry problem long before it becomes a legal one. And the obligation reaches backward as well as forward, since it covers products already placed in the EU market, not only those shipped after the CRA becomes fully applicable in December 2027.
For anyone running or supplying industrial and OT environments, this exposes an uncomfortable gap. The pathway most likely to produce a reportable event in OT is also the pathway with the least instrumentation: removable media. The good news is that this is a tractable engineering problem with three well-understood controls: an enforced inspection point at the perimeter, hardware-enforced one-way transfer between zones, and managed transfer that logs every movement. All three are needed, and the order matters.
Problem One: The Threat That Simply Walks Through the Gate
Honeywell's industrial cybersecurity research found that 51% of the malware it analyzed was designed to spread via USB devices, up from 9% five years earlier. Its 2025 threat report found that one in four incidents handled by its response team involved a USB plug-and-play event, typically someone connecting a drive that then spread malware into the environment. Removable media has become one of the most reliable initial access vectors into ICS (Industrial Control Systems) environments precisely because it bypasses every network control an operator has invested in.
Standards bodies flagged this years ago. NIST SP 800-82 Rev. 3, the Guide to Operational Technology (OT) Security, treats media protection as a distinct control family for exactly this reason, and IEC 62443 zone and conduit models assume media entering a zone has been inspected. Policy is rarely the gap. Most plants have a removable media policy sitting in a binder somewhere. Enforcement is where it comes apart: a policy that relies on a contractor voluntarily walking to a scanning station generates no evidence on the day they walk past it instead.
The first control, then, is a mandatory checkpoint at the physical perimeter: a scanning station that every vendor laptop, technician drive, and firmware update must pass through, where files are inspected with multiple engines, reconstructed to strip embedded threats, and logged. Two outcomes matter equally: infected media never enters, and every piece of media that did enter is on the record. The second outcome is what a 72-hour notification is built from.
Problem Two: What Happens After the Gate
Sanitizing media at the entrance answers one question: what gets in. Which way data travels afterward is a separate problem.
Once a file is clean, it still has to get from the enterprise side to the control network, and in most plants that path is a firewall rule. Firewalls are software; they are bidirectional by design and configurable, which means they are also misconfigurable. A firewall permitting inbound file transfer is, by construction, a return path an adversary can attempt to use.
The architectural answer is to remove the return path physically rather than logically. Unidirectional gateways and data diodes enforce one-way data flow in hardware: data can cross from the low-trust side to the high-trust side (or out to the enterprise for historian and analytics use cases), and no protocol, no rule change, and no compromised credential can reverse it. There is nothing to misconfigure because there is nothing to configure in the first place.
This matters for regulatory posture as much as for security. CRA Annex I requires products to protect the confidentiality and integrity of data in transit and to resist unauthorized manipulation of commands, programs, and configuration. Hardware-enforced directionality is one of the few claims a vendor can demonstrate on a bench rather than assert in a datasheet, which counts for something when you are assembling a technical file or sitting across from an auditor.
Problem Three: Making It Something People Can Actually Operate
Here is where most secure-transfer projects stall. A sanitizing checkpoint and a one-way gateway describe a boundary. They do not describe a workflow, and procurement teams ask the practical question early: “Fine, but how does an engineer in Rotterdam get a validated PLC (Programmable Logic Controller) configuration to a plant in Poland on a random day?”
If the answer involves someone walking a USB drive to a kiosk, the architecture has actually reintroduced the problem it was built to solve.
Managed file transfer side steps this issue. Standard mechanisms, SFTP, REST APIs, brokered workflows, let files move between zones without a human carrying them, and every crossing gets the same multiscanning and Deep CDR™ Technology treatment the file would receive at the kiosk. Every transfer also produces a session record: who initiated it, what was sent, what the scan returned, where it landed, and when. That audit trail is the operational answer to the CRA's reporting timeline. When something does go wrong, the difference between filing the early warning inside 24 hours and missing the window is usually whether the log already exists or has to be reconstructed from interviews.
Three Problems, One Pipeline
Vendors sell the checkpoint, the gateway, and the transfer layer as three distinct purchases. They occupy three points on a single path:
Stage | Question it answers | Control |
Entry | Is this media safe to bring in? | Mandatory scanning and file sanitization checkpoint |
Crossing | Can anything travel back out? | Hardware-enforced unidirectional transfer |
Operation | How do we use this every day, with proof? | Managed, logged, protocol-based file transfer |
Solve entry alone and you have a clean file with no safe route inward. Solve the crossing alone and you have a hardened boundary that people route around. Solve operations alone and you have excellent records of moving unverified files. The value is in the complete sequence.
One Note On Scope
It is worth being precise about what the September deadline does and does not do. The CRA is product legislation: its reporting obligations fall on manufacturers, importers, and distributors of products with digital elements, not on plant operators as such. Operators of critical infrastructure in the EU are more directly governed by NIS2, which carries its own incident notification duties.
In practice, though, the two converge on the same capability. Whether the obligation reaches you as a manufacturer under the CRA or as an essential entity under NIS2, you are being asked to detect an event quickly, explain how data moved, and show the controls that were in place. An instrumented data pipeline answers all three. A policy document, however carefully drafted, answers none.
Where to start
If September 11 is on your calendar, skip the gap assessment against the regulation text and run a walk-through instead: pick one real file, say a firmware update, a vendor patch, or an updated batch recipe, and trace its full journey from a supplier’s laptop to a controller. Note every point where a human decision substitutes for an enforced control, and every point where the trail goes cold
Most organizations find the same three gaps, in the same order.
OPSWAT works with critical infrastructure operators and OEMs on exactly this pipeline: MetaDefender Kiosk™ for removable media security at the perimeter, the MetaDefender Unidirectional Security Gateway for hardware-enforced one-way transfer between zones, and MetaDefender Managed File Transfer for managed movement with full session auditing. To walk your own data path against the CRA and NIS2 reporting, get in touch with our team.
