Industrial Automation Atmospheric Picture

System BOM Creation for Machine and Plant Engineering

Create a system BOM for your machines and plants – in under 20 minutes. With SANCTUARY Insight, you capture detailed information such as model, product number, firmware version, and much more – for industrial PCs and PLCs, but also for devices behind them, connected for example via IO-Link or EtherCat.

Machines change with every delivery

Machines and plants increasingly consist of a heterogeneous network of interconnected devices: programmable logic controllers (PLCs), numerical controls, human-machine interfaces (HMI), industrial PCs, edge gateways, sensors, and actuators. Each sub-plant operates with software and firmware delivered by different manufacturers, updated at different intervals, and integrated late in the supply chain. This heterogeneity creates blind spots that affect vulnerability management and lifecycle control. When a machine is individually customized or reconfigured, the inventory quickly deviates from the design documentation. Operators and manufacturers therefore need a reliable mechanism to enumerate hardware and software components, including exact firmware versions and configuration context, without prior knowledge of the topology.


The EU Cyber Resilience Act is approaching

Did you know that by September 2026 you must already be able to report vulnerabilities in your machines and plants? Now is the right time to prepare your system BOM and set up the necessary internal processes!

Dec 10, 2024

CRA enters into force

The Cyber Resilience Act was published in the Official Journal of the European Union and has officially entered into force.


Impact: For all hardware and software manufacturers, the 36-month period for full implementation begins.

Mid 2026

Asset and BOM Preparation

Organizations must begin creating software and system BOMs (SBOMs) to meet compliance requirements.


Ideal time to deploy automatic asset intentory solutions like SANCTUARY Insight. Insight uses passive network analysis and active device communication to capture exact firmware and topology data and automate BOM creation before upcoming deadlines.

Sep 11, 2026

Reporting obligations

Manufacturers must report actively exploited vulnerabilities and serious incidents to ENISA.


Impact: These obligations are subject to strict deadlines, including a 24-hour early warning requirement. An automated, real-time BOM is essential for immediate triage. Without automation, these deadlines are impossible to meet.

Dec 11, 2027

Full enforcement

All core CRA product requirements and obligations apply.


Impact: Products placed on the market require conformity assessments and CE marking. Manual documentation is not sufficient; continuous automated compliance through platforms like SANCTUARY Insight is required.

System BOM and Vulnerability Management with SANCTUARY Insight

Within a machine cell or line, SANCTUARY Insight identifies OT devices and their software stacks using passive network observation and selective, protocol-based queries.


PLCs, HMIs, and controllers are captured along with manufacturer, model, and serial information, where available. Firmware and operating system versions are extracted via industrial protocols and authenticated interfaces and correlated with the underlying hardware.


The system then creates a system-wide BOM that integrates a hardware BOM and a software BOM, linking software components to the executing devices to ensure unique traceability.

SANCTUARY Insight with Device SBOM

The Foundation for Compliance – In Minutes

A scan of your machine typically takes less than 30 minutes but provides all the data you need to meet your machine's documentation obligations! This data includes a complete system BOM with


  • Model name
  • Serial number
  • Product code
  • Device type
  • Manufacturer
  • Firmware version
  • Operating system
  • Installed software
  • Network connections


Our Insight sensors enable complete and detailed OT asset visibility. SANCTUARY Insight supports all standardized OT protocols such as Modbus/TCP, OPC UA, Profinet, a variety of vendor-specific discovery protocols from Siemens, Beckhoff, Phoenix Contact, Schneider Electric, as well as peripheral devices such as cameras, barcode readers, printers, and much more. Furthermore, SANCTUARY Insight imposes no load on the network or devices by 1) reducing the protocols attempted per device based on prior device information and 2) using protocols already utilized by the manufacturer's software.



SANCTUARY Insight with found devices



And for your Windows- or Linux-based embedded PCs, we offer our Insight Agent, which automatically collects a software BOM (SBOM) for you – or you can upload existing SBOMs directly to integrate them into your system BOM.


Learn more about the technology behind SANCTUARY Insight.

Integrated Machine and Customer Management

Responsibility rarely ends with the delivery of a machine or plant. SANCTUARY Insight closes the critical gap between in-depth technical asset management and customer management. Instead of managing your machine fleet in isolated data silos, it links security integrity directly with business context.


  • Centralized fleet management: Get a complete overview of the status of all scanned machines and plants across their entire lifecycle in a single, clearly structured console.
  • Multi-tenant customer assignment: Assign individual machines or complete plant complexes with a single click to specific customers, projects, or plant areas. This ensures precise monitoring, even with hundreds of active field installations.
  • Precise risk-customer mapping: When a new vulnerability (CVE) is disclosed, every second counts. Identify the affected device, such as a specific PLC or I/O unit, deep within a machine, and immediately see exactly which customers are affected. Offer proactive security support and patch scenarios before your customer even becomes aware of the risk.

Automate the capture of your system BOM!

SANCTUARY Insight significantly reduces the cost and effort of compliance! A typical machine can be scanned by a technician in less than 10 minutes.


FunctionManual / Design documents (status quo)SANCTUARY Insight
Speed & Scalability Manual inspection and vulnerability management will not be scalable for the upcoming requirements.✔ A full machine scan typically takes less than 20 minutes.
Data qualityThe inventory quickly deviates from the original design documentation upon customization or reconfiguration.✔ Real-time detection of hardware, exact firmware versions, and serial information via protocol-based queries.
CRA complianceBlind spots hinder documentation obligations and vulnerability lifecycle management.✔ Automatic generation of the system BOM required by the EU Cyber Resilience Act.
Device traceabilityHeterogeneous devices (PLCs, HMIs, gateways) from different manufacturers result in fragmented documentation.✔ Integrated hardware and software BOMs link components to the executing devices for unique traceability.


We speak the language of your machines.

Save yourself the search through endless, unwieldy protocol lists. Simply enter the name of your PLC manufacturer in the search field – our interactive matrix filters in real time and immediately shows you how we read your devices.

We clearly distinguish between two communication paths:

  • Vendor-specific protocols: For deep, vendor-specific communication (e.g., Siemens S7 or Beckhoff ADS) to achieve maximum data granularity.
  • Standardized protocols: For universal, vendor-independent detection (e.g., PROFINET, EtherNet/IP, or OPC UA).

FAQ

Contact us for a free pilot phase!

* required