Skip to main content
ICP DAS

ICP DAS M-7000, ET-7000, and WISE Remote I/O Before the EU CRA September 11, 2026 Connected-Products Deadline: A 60-Hour Sourcing Audit for SEA Panel Builders

EU CRA Phase 1 24-hour vulnerability reporting starts September 11, 2026. SEA panel builders exporting machinery to EU customers should re-audit the ICP DAS M-7000, ET-7000, PET-7000, WISE, ECAT, and PROFI modules on their 2026 bills of materials.

ICP DAS M-7000, ET-7000, PET-7000, and WISE Remote I/O Before the EU CRA September 11, 2026 Deadline: A 60-Hour Sourcing Audit for SEA Panel Builders

By the Aoctrl Editorial Desk, Industrial Automation Sourcing Desk Updated September 9, 2026 — Hsinchu, Taipei

The clock runs out on September 11, 2026 at 00:00 CET. That is the moment when Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), switches on its first hard obligation for connected products placed on the EU market: a 24-hour window to notify ENISA of any actively exploited vulnerability, plus a five-day window to issue a software bill of materials (SBOM) and a public fix. For Southeast Asia (SEA) panel builders in Vietnam, Thailand, Malaysia, Indonesia, and the Philippines who build machinery that ships into the EU — Tier-1 automotive lines, F&B packaging skids, EV battery cell lines, semiconductor back-end tooling, or simple industrial OEM equipment — the question is no longer academic. Every Modbus RTU coupler, every Ethernet I/O slice, and every PoE-powered remote I/O module embedded in your control cabinet falls inside that connected-product scope the moment your machine clears customs in Hamburg or Rotterdam.

This article is a 60-hour audit checklist for SEA panel builders who already use, or plan to use, ICP DAS remote I/O modules — specifically the M-7000 (RS-485 / Modbus RTU), ET-7000 (Modbus TCP / Ethernet), PET-7000 (PoE Ethernet), WISE (IoT controllers with MQTT), ECAT (EtherCAT slaves), and PROFI (PROFINET) families — in panels that ultimately end up on EU customer sites. We map what the EU CRA actually requires of integrators (not just OEMs), what evidence you should request from your ICP DAS distributor, and where genuine surplus channels can replace clones that lack a CRA chain of custody.

What the EU CRA Phase 1 Deadline Really Activates on September 11, 2026

The Cyber Resilience Act becomes enforceable in two phases. Phase 1, the "connected products with digital elements" notification regime, applies from September 11, 2026. Phase 2, the full conformity assessment including the EN 18031 cybersecurity standard series and CE marking under CRA Annex I, follows on December 11, 2027. Phase 1 is the date every SEA panel builder should print on the inside of their control cabinet door today.

According to reporting from JD Supra (July 31, 2026) and the Crowell & Moring analysis published June 11, 2026, the obligations that switch on September 11 include:

  • A 24-hour notification to the European Union Agency for Cybersecurity (ENISA) when the manufacturer becomes aware of a vulnerability that is being actively exploited in its connected product.
  • A 5-day obligation to publish, free of charge, a corrected cybersecurity advisory and (where applicable) an SBOM covering the affected product line.
  • A first-line duty on the manufacturer to maintain a single point of contact reachable 24/7 for ENISA notifications, with named contact data registered in the EUDAMED-like CRA database.
  • A support-period commitment (Article 13.18) that the product must remain patchable for at least 5 years, with an explicit end-of-support date on the Declaration of Conformity.

The Bleeping Computer commentary published September 8, 2026 framed the Phase 1 deadline differently — as a transparency test: if your supply chain cannot tell you what shipped, in what firmware revision, with what cryptographic signing key, you do not have a CRA defence, you have a problem.

For SEA panel builders, the practical interpretation is:

  • You are an integrator, not a manufacturer — but if you place your finished machine on the EU market under your own nameplate or your customer's nameplate, the CRA's importer obligations cascade down to you. Article 19 makes this explicit.
  • Each network-connected component you embed inherits manufacturer-side CRA duties that you cannot waive. Your supplier's lack of CRA documentation is your liability, not theirs.
  • The EN 18031 series (harmonised standards under CRA Annex I) will, from December 2027 onward, become the conformance baseline. Phase 1 already expects manufacturers to be ready for that audit posture.

A common misconception in SEA panel shops is that "CE marked" equals "CRA compliant". As of September 11, 2026, it does not. CE marking under the Machinery Regulation 2023/1230 or the EMC Directive 2014/30/EU covers safety and electromagnetic compatibility. The CRA covers cybersecurity and product lifecycle support. They are different conformity tracks.

Why ICP DAS Remote I/O Lands Inside the CRA Scope

ICP DAS Co., Ltd. is a Hsinchu-based Taiwanese industrial I/O manufacturer with a deliberate product strategy built around RS-485 Modbus RTU, Modbus TCP, PROFINET, EtherCAT, EtherNet/IP, CANopen, BACnet, MQTT, and PoE-powered Ethernet I/O. The catalog we list includes the M-7000 series (M-7055 16-channel isolated digital input, M-7060 relay output, M-7017MC-16 multi-channel analog input, M-7019Z-G/S2 high-density digital I/O, M-7028 counter/frequency module), the ET-7000 series (ET-7002 dual analog input, ET-7018Z/S2 8-channel thermocouple input, ET-7024 multi-channel analog output, ET-7219Z/S2 universal digital I/O, ET-7228 high-density digital I/O, ET-7226 analog output), the PET-7000 series (PET-7219Z/S PoE digital I/O, PET-7228 PoE high-density I/O, PET-7224 PoE analog output), the WISE series (WISE-5800 IoT controller, WISE-5800-MTCP with MQTT, WISE-7517M-10 modular controller, WISE-7519ZM/S MQTT web I/O, WISE-5801 compact IoT), and protocol-specific slave lines (ECAT-2011H EtherCAT, PROFI-5018 PROFINET digital I/O, PROFI-5024 PROFINET analog, EIP-2017 EtherNet/IP, CAN-2019C CANopen, PFN-2055 PROFIBUS, BNET-5304 BACnet).

Every one of these modules has a network interface. Every one ships firmware. Every one is "a product with digital elements" under CRA Annex I. The CRA does not exempt Taiwanese-made industrial I/O. The CRA does not exempt "simple" 16-channel digital inputs. The CRA does not exempt modules placed on the EU market as components that are then integrated into a larger system — Article 3.2 explicitly captures such products.

What changes for a panel builder in Bangkok or Hanoi when their customer in Stuttgart asks, "Is this ICP DAS WISE-5800-MTCP module you integrated into our packaging line CRA-compliant?" is the entire audit posture of the project. From September 11, 2026, the honest answer must include:

  • A documented firmware revision state, signed and verifiable
  • A 5-year support period commitment on the Declaration of Conformity
  • A named contact at the manufacturer side for ENISA notifications
  • A vulnerability disclosure policy that exists in writing and is reachable
  • An EN 18031 conformance roadmap or an equivalent recognised scheme (IEC 62443-4-2 with mutual recognition under CRA Annex II)

If your panel shop cannot produce that paper trail in 60 hours, the question is whether the brand of remote I/O on the BOM has the documentation. If it does not, your panel shop carries the integration-time liability for the next five years.

The 60-Hour Audit Checklist SEA Panel Builders Should Run This Week

This is the practical checklist the Aoctrl desk recommends for SEA panel builders whose bills of materials include ICP DAS or similar Asian-manufactured remote I/O and whose projects ship to EU customers. Each step includes what evidence to request, what the question means in plain language, and what a passing answer looks like.

Step 1 — Identify Every Network-Connected Module on Your Active EU-Project BOMs

Pull every active BOM from the last 12 months where the destination country is an EU member state. For each line item that has a network interface (RS-485 Modbus RTU, Ethernet Modbus TCP, PROFINET, EtherCAT, EtherNet/IP, BACnet, MQTT), record:

  • The ICP DAS model (e.g., M-7055, ET-7219Z/S2, WISE-5800-MTCP, PET-7228, ECAT-2011H, PROFI-5018)

  • The firmware revision shipped (visible on the module's web UI or via the ICP DAS utility)

  • The serial number range (so you can identify the manufacturing lot)

  • The MOQ (minimum order quantity) agreed with the supplier for the production lot, since firmware revision control and the manufacturer-side DoC typically follow the production lot

  • The distributor or surplus channel of origin

  • The intended EU customer's site and project reference

This is the data set your compliance officer will hand to ENISA in the event of a vulnerability disclosure. Without it, your panel shop will spend 24 hours chasing paperwork instead of issuing the advisory.

Step 2 — Request the EU Declaration of Conformity (CRA-Annex) From Your Supplier

For each model, request from your distributor or authorised channel a copy of the EU Declaration of Conformity (DoC) that lists:

  • The CRA conformity assessment route (self-attestation under Article 32 vs third-party under Article 33)
  • The harmonised standards applied (EN 18031-1, EN 18031-2, EN 18031-3 when published, and the EN IEC 62443-4-2 fallback)
  • The manufacturer's notified body (where third-party assessment applies)
  • The signature date and the support-period end date
  • The manufacturer's EU responsible person under Article 18 (Article 19 applies if the manufacturer is outside the EU)

In our experience as an independent distributor dealing with ICP DAS channels across SEA, a clean DoC is not yet universally available at the time of writing (September 9, 2026). Phase 1 has been in force technically since the regulation's October 2024 publication, but the EN 18031 harmonised standard was not formally cited in the OJEU until Q2 2026, which means a number of Taiwanese and Japanese remote I/O vendors are still in the gap window between regulation and harmonised standard. That gap does not exempt them from the 24-hour notification duty. It does mean you need to ask whether the vendor has a published "interim CRA conformance statement" until the EN 18031 OJEU citation triggers a formal DoC refresh.

Step 3 — Verify the Manufacturer's Vulnerability Disclosure Endpoint

Every CRA-compliant manufacturer must publish, on a publicly accessible page, a security advisory email or web form. For ICP DAS specifically, this should include an English-language disclosure channel (not only the Taiwan-domestic Chinese-language support form), a published PGP key for advisory encryption (where the disclosure policy treats vulnerabilities as confidential until a patch is available), and a named security contact who responds within the 24-hour notification window.

Where the manufacturer does not have a published disclosure endpoint, the panel builder cannot reasonably rely on the manufacturer to meet its 24-hour obligation. In that case, the integration risk stays with the panel builder for the duration of the support period.

Step 4 — Confirm the Firmware Signing Key and Update Mechanism

Modern CRA-conformant connected products ship with cryptographic firmware signing. The module verifies the signature before applying an update. The signature chain is documented, and the key rotation policy is published. For ICP DAS firmware on the WISE, ECAT, and PROFI families, the published firmware updates are hosted on the ICP DAS FTP and the ICP DAS website; what you should ask for is a written statement of the firmware signing scheme in use (RSA-2048 vs ECDSA P-256, key rotation cadence, and the procedure for revoking a compromised key).

This matters because under CRA Annex I.3(d), the manufacturer must demonstrate that updates are delivered with integrity and authenticity protection. A module that accepts unsigned firmware is non-conformant from December 11, 2027 and creates a vulnerability surface from September 11, 2026.

Step 5 — Confirm the 5-Year Support-Period Commitment in Writing

CRA Article 13.18 requires manufacturers to commit to a support period of at least 5 years from the date the product is placed on the EU market. For your 2026 BOM, the support period therefore ends no earlier than 2031. For your 2024 BOM, it ends no earlier than 2029. Ask the manufacturer or your distributor for the support-period end date as it appears on the DoC. If the support period is shorter than 5 years, the panel builder needs to plan a migration before support lapses.

Step 6 — Decide Genuine Channel vs Parallel-Import Risk

This is where the SEA panel builder's sourcing decision actually lives. The EU CRA's importer-of-record chain of custody means that a parallel-imported ICP DAS module sourced through an unauthorised SEA broker may have:

  • No documented manufacturing lot and serial traceability
  • No English-language vulnerability disclosure endpoint routed back to the manufacturer
  • No firmware signing integrity (the firmware may have been re-flashed or repackaged)
  • No manufacturer-side CRA statement at all

The panel builder's exposure under Article 19 is the same regardless of whether the module is genuine or a clone. The 24-hour notification duty, the support-period duty, and the conformity-assessment duty apply to the integrated machine, not to the individual component. A parallel-imported ICP DAS M-7055 without manufacturer-side traceability therefore puts the same risk on the panel builder as a counterfeit module would.

The MOQ conversation also enters here: a low-MOQ broker quote on a M-7055 or M-7060 may look like a 15-20% cost saving on the panel builder’s BOM, but if the manufacturer-side documentation is absent, that 15-20% saving evaporates the first time the panel shop has to issue an ENISA notification outside business hours.

This is the substantive reason SEA panel builders should, when the BOM permits, source through a documented independent distributor that can produce manufacturer-side paperwork or, where the project timeline allows, through the authorised regional channel. It is also why the genuine surplus channel matters: surplus modules from decommissioned EU plants carry the original manufacturer's CRA documentation trail, whereas parallel imports do not.

What the Audit Will Find in Most SEA Panel Shops in September 2026

Running this audit across a sample of SEA panel builders in the food-and-beverage, automotive Tier-1, semiconductor back-end, and EV battery cell line categories, we expect three common findings in Q3 2026:

Finding A — Modules purchased in 2024 or earlier may not yet have a manufacturer-side EN 18031 conformance statement. This is not a panel-builder failure. It is the vendor's EN 18031 OJEU citation timing. What the panel builder can do is request an interim statement and place it in the project file so that, in the event of a vulnerability disclosure, the panel builder can show that due diligence was performed at integration time.

Finding B — Multiple firmware revisions on the same project. It is common to find that an ET-7219Z/S2 module purchased in 2024 ships with firmware revision 1.5.2 while an ET-7219Z/S2 purchased in 2026 ships with revision 2.1.0. From a CRA standpoint, these are two different products with two different conformity baselines. The panel builder must record which revision went into which machine, because the support period and the vulnerability notification apply per firmware revision, not per SKU.

Finding C — Documentation gap on parallel-imported modules. This is the most common finding. Where the panel builder sourced through a regional broker without an authorised ICP DAS channel, the DoC, the manufacturer contact, and the vulnerability disclosure endpoint are typically missing. The panel builder's response is to either migrate to an authorised-channel source for future builds or to apply compensating controls (network segmentation, vendor-agnostic anomaly detection) and document the compensating-control decision in the project file.

Practical Sourcing Recommendations for Late Q3 and Q4 2026

For SEA panel builders operating on EU-export machinery projects in Q4 2026 and Q1 2027, the practical sourcing recommendations are as follows.

For new designs, prefer modules with an English-language manufacturer-side vulnerability disclosure endpoint. This is the single most actionable filter. If the manufacturer does not publish a security advisory channel that a panel builder in Bangkok can reach at 02:00 local time on a Saturday night, the integration risk is unpriced.

For existing designs, request an interim CRA conformance statement at the time of order. Frame the request as a standard procurement document. "Please provide your current CRA Phase 1 readiness statement, including your vulnerability disclosure endpoint, your support-period commitment on this product family, and your EN 18031 conformance timeline." Most reputable Taiwanese and Japanese manufacturers will respond within 5 business days.

For surplus channel modules, treat the documentation trail as part of the unit price. Genuine surplus ICP DAS WISE-5800-MTCP modules from a decommissioned EU plant carry an audit trail that justifies a price premium over a parallel-imported equivalent. The premium is the cost of integrating CRA-conformant components into your panel builder's documentation packet.

For long-tail modules where the manufacturer is silent on CRA, plan a 2027 migration. The M-7017MC-16 multi-channel analog input module is a high-volume workhorse in SEA panel shops. If the manufacturer has not published a CRA statement by Q4 2026, the panel builder should plan a Q3 2027 migration to a successor module (or a competing vendor with a published CRA posture) before the December 11, 2027 Phase 2 conformity assessment deadline.

For high-availability projects, isolate the remote I/O network from the corporate LAN. This is a compensating control that does not require manufacturer cooperation. The EN IEC 62443-3-3 system-level segmentation approach lets the panel builder defend an integration where the components are not individually CRA-conformant by demonstrating that the system-level security posture meets the spirit of CRA Annex I. This is the panel builder's equivalent of cybersecurity due diligence.

Data Notes

This article draws on the following dated sources, each cited inline above:

  • BleepingComputer, "The EU CRA's Real Question: What Shipped, and When Did You Know?", September 8, 2026 — Phase 1 transparency framing and the September 11, 2026 deadline.
  • Crowell & Moring LLP, "EU Cyber Resilience Act: September 11, 2026 Reporting Deadline Less Than 100 Days Away", June 11, 2026 — Phase 1 notification duties and ENISA contact requirements.
  • JD Supra, "EU Cyber Resilience Act: 24-Hour Reporting Duties Start September 11, 2026", July 31, 2026 — Article 13.18 support-period commitment and EN 18031 harmonisation timeline.
  • Industrial Cyber, "What the Cyber Resilience Act requires from manufacturers", March 20, 2024 — Importer-of-record obligations under Article 19 and the cascade effect on integrators.
  • en.vneconomy.vn, "Northern Vietnam leads manufacturing FDI inflows with $8.63 billion in H1", September 9, 2026 — Northern Vietnam manufacturing FDI context for EU-export machinery sourcing.
  • ICP DAS Co., Ltd. official product catalogue pages for M-7055, M-7060, M-7017MC-16, M-7019Z-G/S2, M-7028, ET-7002, ET-7018Z/S2, ET-7024, ET-7219Z/S2, ET-7226, ET-7228, PET-7219Z/S, PET-7224, PET-7228, WISE-5800, WISE-5800-MTCP, WISE-7517M-10, WISE-7519ZM/S, WISE-5801, ECAT-2011H, PROFI-5018, PROFI-5024, EIP-2017, CAN-2019C, PFN-2055, BNET-5304 — module specifications, firmware revision history, and protocol coverage.

Disclaimer

This is editorial sourcing intelligence from an independent industrial automation distributor serving SEA panel builders. It is not legal advice and should not be relied upon as a substitute for qualified counsel on EU regulatory matters. The EU Cyber Resilience Act (Regulation (EU) 2024/2847) and the EN 18031 series are evolving instruments; the harmonised standards and notified-body designations are subject to OJEU citation updates through 2026 and 2027. Readers are responsible for verifying the current regulatory baseline with their own compliance counsel before integrating any component into machinery placed on the EU market. Aoctrl does not provide certification, conformity assessment, or legal opinion services. All manufacturer specifications cited are drawn from publicly available product documentation at the time of writing (September 9, 2026).

Languages: English

Last updated: September 9, 2026