Cybersecurity · CRA · NIS2 · IEC 62443

Cybersecurity Compliance
integrated manufacturing

Eziwan Gateway and Cloud are designed to meet growing regulatory requirements: CRA 2027, NIS2 Directive, IEC 62443 SL2, and ANSSI standards. Zero Trust OT architecture by default.

Eziwan Security Architecture
Zero Trust OT · Layers 1–6
PROTECTED
Zero Inbound Port
No open ports to the Internet.
End-to-end encryption
OpenVPN (AES-256-GCM) for the VPN.
Strong Authentication
MFA is required on the platform.
RBAC & Access Control
Granular roles: admin, operator, read-only.
OT/IT Segregation
The OT network is isolated from the corporate IT system.
Secure Firmware & OTA
Cryptographically signed firmware.
IEC 62443 SL2
Aligned · Documented

What each regulation
requires you to

And how Eziwan helps you address these issues in practical terms.

CRA
Cyber Resilience Act
Regulation (EU) 2024/2847

The CRA mandates cybersecurity by design for all products containing digital components, including IoT routers and gateways. It requires security updates, vulnerability management, and a cybersecurity CE marking.

Effective: December 2027
Manufacturers of connected products sold in the EU
Official Text
What the regulations require
Cybersecurity by design required from the outset
Lifetime Security Updates
Documented Vulnerability Management (CVE)
Reporting Security Incidents to ENISA
Mandatory CE Marking for Cybersecurity
Complete technical documentation
How Eziwan Responds to This
Gateway developed according to the "Secure by Design" principles
Cryptographically Signed OTA Firmware
CVE tracking and patches in less than 30 days
Certifiable technical documentation available
CRA 2027 Compliance Roadmap Underway

6 layers of security
Zero Trust OT

Each layer is independent. Even if one is compromised, the others maintain the insulation.

LAYER 01

Zero Inbound Port

No open ports to the Internet. The gateway always initiates the connection to Eziwan Cloud. Full Zero Trust model.

LAYER 02

End-to-end encryption

OpenVPN (AES-256-GCM) for the VPN. TLS 1.3 for the API. AES-256 encryption at rest.

LAYER 03

Strong Authentication

MFA is required on the platform. Asymmetric keys for gateways. Automatic certificate rotation.

LAYER 04

RBAC & Access Control

Granular roles: admin, operator, read-only. Access by gateway, by site, by time range. Immutable audit log.

LAYER 05

OT/IT Segregation

The OT network is isolated from the corporate IT system. Each site has its own VPN tunnel. There are no uncontrolled interconnections.

LAYER 06

Secure Firmware & OTA

Cryptographically signed firmware. Integrity check before installation. Centralized OTA deployments without on-site intervention.

Eziwan covers Key Requirements

Safety RequirementCRANIS2IEC 62443ANSSI
Strong Authentication (MFA)
Encryption in transit (TLS 1.3)
Encryption at rest (AES-256)
Zero inbound ports (Zero Trust)
Granular RBAC
Immutable audit logs
Signed Firmware (OTA)
Vulnerability Management (CVE)
OT/IT Segregation
Continuity (Dual SIM Failover)
Sovereign Hosting in France
Complete technical documentation
Cybersecurity for Industrial Infrastructure
CEFCCRoHSIP40OpenVPN

Certified. Documented.
Auditable.

The Eziwan gateway is CE, FCC, and RoHS certified. The software architecture is documented to facilitate certification by your security teams or external auditors (NIS2, ANSSI).

Technical specifications available
Architecture diagrams, data flows, security policies—for your audits and certifications.
Annual Penetration Testing
Regular penetration tests conducted by independent third parties. Reports available upon request under an NDA.
CVE tracking & patches < 30 days
Continuous vulnerability monitoring. Patches deployed via OTA within 30 days of discovery.
Bug Bounty Program
Open Responsible Disclosure Program. Rewards for Security Researchers.
FAQ

Frequently Asked Questions

CRA · NIS2 · IEC 62443 · ANSSI

Ready to Get Started on Your Compliance
Industrial cybersecurity?

Our security team will assist you in assessing your regulatory obligations and ensuring that your industrial IoT infrastructure is compliant.

Free Estimate · Technical Specifications Available Upon Request · Response Within 24 Hours