System BOM Creation for Mechanical and Plant Engineering

Machines and plants increasingly comprise a heterogeneous set of interconnected devices: programmable logic controllers (PLCs), numerical controllers, Human-Machine Interfaces (HMIs), industrial PCs, edge gateways, sensors, and actuators. Each subsystem operates with software and firmware that is supplied by different manufacturers, updated at different intervals, and integrated late in the supply chain. This heterogeneity creates blind spots that hinder vulnerability management and lifecycle control. When a machine is individually customized or reconfigured, the inventory quickly deviates from the design documentation. Operators and manufacturers therefore need a reliable mechanism to enumerate hardware and software components, including exact firmware versions and configuration context, without requiring prior knowledge of the topology.


The EU Cyber Resilience Act Is Approaching

Did you know that by September 2026, you must already be able to report vulnerabilities in your machines and plants? Now is the time to prepare your system bill of materials and set up the necessary internal processes!

Dec 10, 2024

CRA Enters into Force

The Cyber Resilience Act was published in the Official Journal of the European Union and officially entered into force.


Impact: For all hardware and software manufacturers, the 36-month countdown for full implementation begins.

Present – Mid-2026

Asset & BOM Preparation

Organizations must begin generating Software Bill of Materials (SBOM) and System BOMs for compliance.


SANCTUARY Insight: Employs passive network monitoring to capture exact firmware and topology data and to automate BOM creation ahead of upcoming deadlines.

Sep 11, 2026

Reporting Obligations

Manufacturers must report actively exploited vulnerabilities and critical incidents to ENISA.


Impact: These obligations are subject to strict deadlines, including a 24-hour early warning requirement. An automated, real-time BOM is essential for immediate triage.

Dec 11, 2027

Full Enforcement

All core CRA product requirements and obligations apply.


Impact: Products placed on the market require conformity assessments and CE marking. Manual documentation will not be sufficient; continuous automated compliance through platforms such as SANCTUARY Insight is mandatory.

System BOM and Vulnerability Management with SANCTUARY Insight

Within a machine cell or line, SANCTUARY Insight identifies OT devices and their software stacks using passive network monitoring and selective, protocol-based queries.


PLCs, HMIs, and controllers are detected along with manufacturer, model, and serial information, where available. Firmware and operating system versions are extracted via industrial protocols and authenticated interfaces and correlated with the underlying hardware.


The system then generates a system-wide BOM that integrates a hardware BOM and a software BOM, linking software components to the executing devices to ensure unique traceability.

SANCTUARY Insight with Device SBOM

The Foundation for Compliance – In Minutes

A scan of your machine typically takes less than 30 minutes, yet provides all the data you need to fulfill your documentation obligations for your machine! This data includes a complete system bill of materials with


  • Model Name
  • Serial Number
  • Product Code
  • Device Type
  • Manufacturer
  • Firmware Version
  • Operating System
  • Installed Software
  • Network Connections


Our Insight sensors achieve complete and detailed OT asset visibility. SANCTUARY Insight supports all standardized OT protocols such as Modbus/TCP, OPC UA, Profinet, a wide range of manufacturer-specific discovery protocols from Siemens, Beckhoff, Phoenix Contact, Schneider Electric, as well as peripheral devices such as cameras, barcode readers, printers, and much more. Furthermore, SANCTUARY Insight neither burdens the network nor the devices by 1) reducing the protocols attempted per device based on prior device information and 2) using the protocols already utilized by the manufacturer's software.


And for your Windows- or Linux-based Embedded PCs, we provide our Insight Agent, which automatically collects a Software Bill of Materials (SBOM) for you – or you can upload existing SBOMs directly to integrate them into your system bill of materials.


Learn more about the technology behind SANCTUARY Insight.

Integrated Machine and Customer Management

Responsibility rarely ends with the delivery of a machine or plant. SANCTUARY Insight bridges the critical gap between in-depth technical asset management and customer administration. Instead of managing your machine fleet in isolated data silos, it links security integrity directly with the business context.


  • Centralized Fleet Management: Get a complete overview of the status of all scanned machines and plants across their entire lifecycle in a single, clearly structured console.
  • Multi-Tenant Customer Assignment: Assign individual machines or entire plant complexes to specific customers, projects, or factory areas with a single click. This ensures precise monitoring, even with hundreds of active installations in the field.
  • Precise Risk-Customer Mapping: When a new vulnerability (CVE) is disclosed, every second counts. Identify the affected device, for example a specific PLC or I/O module, deep within a machine, and immediately see exactly which customers are affected. Offer proactive security support and patch scenarios before your customer even becomes aware of the risk.

Automate the Capture of Your System Bill of Materials!

SANCTUARY Insight significantly reduces the cost and effort of compliance! A typical machine can be scanned by a technician in less than 10 minutes.


FunctionManual / Design Documents (Status Quo)SANCTUARY Insight
Speed & Scalability Manual inspection and vulnerability management will not be scalable for the upcoming requirements.✔ A complete machine scan typically takes less than 20 minutes.
Data QualityThe inventory quickly deviates from the original design documentation during customization or reconfiguration.✔ Real-time detection of hardware, exact firmware versions, and serial information via protocol-based queries.
CRA ComplianceBlind spots hinder documentation obligations and vulnerability lifecycle control.✔ Automated generation of the system bill of materials (BOM) required by the EU Cyber Resilience Act.
Device TraceabilityHeterogeneous devices (PLCs, HMIs, gateways) from various manufacturers result in fragmented documentation.✔ Integrated hardware and software BOMs link components to the executing devices for unique traceability.


FAQ

Contact us for a free pilot phase!

* required