Industrial communication modules have traditionally been evaluated on one primary metric: how quickly they can add fieldbus or Industrial Ethernet connectivity to a device. Today, however, that equation is changing. As cybersecurity becomes an integral part of industrial automation, communication modules are increasingly judged by how well they support secure operation, software updates and long-term product maintenance.
The European Union's Cyber Resilience Act (CRA) and general security requirements are driving reflects this shift from just protocol support to longevity. While the regulation is European, its impact extends well beyond Europe because many machine builders and device manufacturers sell products globally. Beginning in September 2026, manufacturers must report actively exploited vulnerabilities and serious security incidents.
The broader cybersecurity requirements take effect in December 2027, requiring products with digital elements to incorporate security throughout their lifecycle.
For automation equipment manufacturers, the message is clear: connectivity alone is no longer enough.
Security is becoming a market and product requirement
Industrial devices often remain in service for 10 to 20 years or longer. During that time, communication technology must continue supporting software updates, vulnerability remediation and evolving security standards. As a result, communication interfaces have become an important part of a product's cybersecurity strategy rather than simply its networking capability.
This represents a significant change in how embedded communication solutions are evaluated. Traditionally, engineers focused on protocol support, ease of integration and development time. Those factors remain important, but they are now accompanied by new questions:
- Can the communication interface be securely updated?
- Does it support modern authentication and encryption mechanisms?
- Can security vulnerabilities be addressed throughout the product lifecycle?
- Does the architecture simplify regulatory compliance?
These considerations increasingly influence technology selection during product development.
As Thomas Rauch, CTO of Hilscher, explained, "Cybersecurity cannot be added afterward. It has to be integrated into the architecture from the beginning — in hardware, software and management systems."
Industrial ethernet is evolving
The industry's leading Industrial Ethernet organizations are also strengthening their security strategies. PROFINET continues expanding its security framework through multiple protection classes that address device authentication, integrity verification, encrypted communication and protection against unauthorized access. EtherCAT benefits from a relatively small attack surface because of its non-ethernet based architecture, but the EtherCAT Technology Group is also developing additional cybersecurity extensions and certificate-based authentication for applications with higher security requirements. Hilscher has already implemented it.
EtherNet/IP has introduced CIP Security, extending the Common Industrial Protocol with TLS/DTLS encryption and certificate-based authentication to secure industrial communications while protecting both data confidentiality and integrity. Although each protocol approaches cybersecurity differently, they all point in the same direction: security features are becoming standard components of industrial communication rather than optional add-ons.
The growing role of embedded modules
These developments are changing how manufacturers evaluate communication architectures. At one end of the spectrum are custom SoC implementations that provide maximum flexibility but require substantial engineering resources. At the other end are external gateways or interface products that minimize development effort but may offer less integration and customization.
Embedded communication modules offer increased flexibility and customization while delivering increased value in hardware; managing physical layer changes, controlling LEDs and maintenance infrastructure. Supplying onboard Flash and RAMoccupy the middle ground. For many OEMs, this balance has become increasingly attractive because it combines relatively fast integration with pre-developed communication functionality while reducing the complexity associated with implementing multiple industrial protocols and their associated security features.
This does not make embedded modules the right solution for every application. Manufacturers pursuing maximum hardware optimization, extremely high production volumes or very simple communication requirements may still prefer alternative approaches.
However, as we see cybersecurity requirements continuing to grow, embedded modules provide an effective way to reduce time to market, simplify engineering effort and provide while supporting long-term maintainability.
From communication interface to lifecycle platform
Modern communication modules increasingly contribute to much more than network connectivity. For example, Hilscher's comX 90 embedded communication module provides multiprotocol Industrial Ethernet connectivity while allowing device manufacturers to integrate industrial communication without developing protocol implementations from the ground up. Beyond communication itself, modules like these can help simplify lifecycle management by providing a structured foundation for updates, protocol maintenance and future security enhancements.
Looking ahead, communication technology is expected to continue evolving toward greater integration of security and lifecycle management. Future generations of industrial communication processors are likely to place even greater emphasis on secure architecture, software maintenance and regulatory readiness alongside traditional networking performance.
Connectivity is only the starting point
Industrial communication is entering a new phase. Network connectivity remains essential, but manufacturers must now consider how communication technology supports cybersecurity, software maintenance and regulatory compliance throughout a product's operational life.
As regulations such as the Cyber Resilience Act accelerate this transition, communication modules are evolving from simple connectivity components into strategic building blocks within the overall product architecture.
For OEMs and device manufacturers, selecting a communication solution is no longer just a networking decision. It is increasingly a decision that influences the long-term security, maintainability and resilience of the entire product.
