EU CRA September 11 2026 Deadline and 4,400 Exposed PLCs: A Cybersecurity Sourcing Checklist for SEA Panel Shops
EU CRA September 11 2026 Deadline and 4,400 Exposed PLCs: A Cybersecurity Sourcing Checklist for SEA Panel Shops
A SEA panel shop quotes a small water-treatment skid in late August 2026. The RFQ asks for EtherNet/IP, six analog inputs, four digital outputs, a 7-inch HMI, and a printed wiring diagram. Firmware and security only enter the conversation after the quotation goes out.
August 2026 changed that ordering.
The market situation: August 2026 was a turning point
Two events bracketed the month and reset what every regional buyer needs to ask a PLC supplier.
On July 31 2026, the FBI confirmed that hacktivists had breached at least seven US water and wastewater utilities, with one treatment plant physically taken offline and another reporting altered chemistry setpoints. Smart Water Magazine and the Times of India both carried the FBI/EPA advisory. The advisory called out two specific vectors: default and unchanged credentials on programmable logic controllers, and unpatched firmware on remote telemetry units bridging IT and OT networks. By August 4, Smart Water Magazine reported that the FBI was reaching out to every water utility in the country with a one-page field notice that named Allen-Bradley ControlLogix and CompactLogix families specifically, plus Modicon M340 / M580 and certain Siemens S7-1500 CPUs.
On August 6 2026, The Hacker News published a Shodan snapshot showing 4,429 Rockwell Automation PLCs directly reachable from the public internet, with twenty-two of them geolocated to municipal water systems that had already been attacked. Cybersecurity News replicated the same finding with screenshots. The disclosure was not about Rockwell hardware being uniquely weak — every major PLC ships with similar defaults — but about an install base of legacy and recent CompactLogix and ControlLogix units that has not been hardened, and that is now large enough to be a strategic target.
On the regulatory side, three 2026 documents reset the compliance baseline that reaches SEA panel shops:
- June 1 2026 — Dentons published "The EU Cyber Resilience Act – What you need to know and do now," walking through the staggered applicability dates and the manufacturer obligations around vulnerability handling and conformity assessment.
- July 31 2026 — Hogan Lovells reported that the European Commission had published final CRA guidance. The guidance clarified that integrators who place a "connected product" on the EU market — including custom-configured PLC cabinets built around a commercial PLC — are themselves considered manufacturers under certain conditions and inherit the documentation and incident-reporting burden.
- August 12 2026 — Security Boulevard reported the first independent test of CRA Phase 2 self-attestation: a Claude Mythos penetration-test platform showed that self-attested firmware integrity checks failed to detect a tampered firmware image in roughly 35 percent of cases. The European Commission has signalled that Phase 2 self-attestation alone will not clear the bar for higher-risk products.
What changed for a SEA panel shop is this: the EU CRA does not directly regulate you. But every EU customer you ship to is now asking the supplier — meaning your customer, the OEM — to prove that the PLC inside the cabinet is on a supported firmware branch, has a Software Bill of Materials, and has not been re-flashed on the way through distribution. Some of that documentation requirement will flow down to you as the cabinet assembler, especially if you re-flash firmware or attach a custom boot image.
What this means for SEA panel buyers and panel shops
Three concrete shifts in buyer behaviour are visible in Q3 2026 and worth planning around.
First, every RFQ that touches an EU end-customer now asks a new line-item question. Customers want the firmware version that ships on the PLC, whether the manufacturer has signed the firmware image, and what the support window is for security patches. The Modicon M580 platform that we stock here — the BMEP581020 CPU module in particular — runs EcoStruxure Control Expert (formerly Unity Pro) and ships with a firmware revision you can pin in your quotation. Schneider Electric's published cybersecurity reference for the M580 family includes Achilles Level 2 certification and CIP Security support on the BMENOC0301 / 0311 Ethernet modules. That is the provenance you put in a quotation row, and it is the kind of documented specification the EU customer's procurement officer can file. A Modicon M340 station built around the BMXP342020 CPU uses the same firmware lineage and the same cybersecurity documentation; it is what you quote when the panel budget is tighter and the cabinet itself is less exposed.
Second, panel shops that flash firmware before delivery now need to keep the firmware image, the signing hash, and the toolchain version on file. If you have ever needed to recover a customer station after a bad flash, you know that the original image file is the first thing you ask for. The EU CRA effectively makes that file part of your documentation pack for any cabinet that ends up in the EU market after September 11 2026. The August 12 Security Boulevard test showed that self-attestation is not enough, and integrators are already being asked for image hashes in pre-shipment reviews.
Third, the lead-time picture for the high-trust CPU families is not the same as it was eighteen months ago. The Modicon M580 BMEP581020 CPU has been on a six-to-eight week lead time in our SEA warehouse for most of 2026, against a published factory lead time closer to fourteen weeks during the Q2 spike. The M340 BMXP342020 is faster — three to five weeks — and is the fallback we suggest for panels where the customer has not formally specified M580. The point is that the procurement channel for these CPUs has tightened, and that tightening is independent of the cybersecurity story. A panel shop that needs an M580 for an EU-bound cabinet in Q4 2026 should reserve the CPU now rather than wait for a confirmed PO, because the documentation chain downstream will eat any time you save by ordering late.
What is in our catalog and how it maps to a CRA-aware quotation
The catalog carries the two Schneider Modicon CPUs that anchor this discussion, and the difference between them is worth being explicit about before you write a quotation.
Modicon M580 — BMEP581020. This is the high-end Ethernet PAC. In our catalog it sits at an aiDemandScore of 83.5 in the key tier. The BMEP581020 is a BMEP58 family processor, dual Ethernet ports, supports up to 64 MB program memory, and is paired with the BMENOC0301 / BMENOC0311 cybersecurity modules for CIP Security and Modbus/TCP with TLS. It runs EcoStruxure Control Expert (formerly Unity Pro) and accepts IEC 61131-3 languages including the structured text and ladder that most SEA panel shops already use. Schneider's cybersecurity reference manual documents Achilles Level 2 certification, signed firmware updates, role-based access control on the engineering port, and a configurable password policy. For EU customers, the BMEP581020 with a BMENOC0301 module and a current EcoStruxure Control Expert version is the strongest answer to the CRA documentation request that a panel shop can give. MOQ on this CPU is one unit; supply is from authorised SEA channel stock.
Modicon M340 — BMXP342020. This is the mid-range Ethernet PLC. In our catalog the BMXP342020 is at aiDemandScore 84.2, also in the key tier. It is a 32-bit processor with two Ethernet ports, supports up to 4096 I/O, runs Unity Pro / EcoStruxure Control Expert, and accepts the same BMX CRA / BMX NOC communication modules as the rest of the M340 family. The M340 does not carry the same Achilles Level 2 claim as the M580; its cybersecurity documentation is older and narrower. For an EU-bound water skid in a municipal environment, the M340 is the option you propose only when the budget is constrained and the customer accepts the M340 cybersecurity manual as the reference. For non-EU SEA customers — most of Indonesia, Vietnam, Thailand, the Philippines — the M340 remains a sensible default. MOQ is also one unit, and in stock at SEA warehouse.
For comparison and completeness, three other PLC families appear in the catalog and the August 2026 advisory named them as well. The Siemens S7-1200 6ES7212-1AE40-0XB0 CPU (score 92) and the S7-1500 family covered in our earlier SCALANCE article share the same firmware-signing and TIA Portal configuration story. The Allen-Bradley CompactLogix 5380 and ControlLogix 5580 families are the families that showed up most heavily in the 4,400-exposed-PLC count; they run Studio 5000 Logix Designer and the security administration in that toolchain is different from the Schneider approach. The Omron Sysmac NX102 platform, which we covered in the context of Iranian-targeting advisories earlier this year, runs Sysmac Studio and carries its own cybersecurity configuration. All three are valid engineering choices; what matters for a CRA-aware quotation is that you can point to the manufacturer's cybersecurity manual, the supported firmware version, and the signing-hash procedure for any of them. Our catalog carries MPNs from each family so selection support for the SEA panel shop is in-house rather than by email to a regional rep.
The Modicon M580 catalog entry on this site is the BMEP581020 at aiDemandScore 83.5; the M340 catalog entry is the BMXP342020 at aiDemandScore 84.2. Both are published, both are in stock at SEA warehouse, and both are sold with the firmware revision that was current at the time of stock receipt. We do not re-flash PLCs to a specific firmware before dispatch unless the customer asks, because re-flashing breaks the firmware signature chain and creates exactly the audit problem the CRA is trying to prevent. Panel shops that need a different firmware revision should request an RFQ with the firmware string explicitly written into the line item; we will quote against the published availability rather than promising a re-flash on dispatch.
Buying advice: the procurement checklist for Q3 and Q4 2026
The single concrete thing you can take from this article is a checklist to put on the quotation template. Every line corresponds to a question the August 2026 advisories and the EU CRA documentation have made fair to ask.
-
Pin the firmware version. Quote the exact firmware revision of the CPU and the cybersecurity module (for M580, that is the BMEP581020 firmware and the BMENOC0301/0311 firmware separately). Do not write "current firmware" or "latest available" — that is unauditable. The firmware revision string goes on the quotation row and on the test certificate.
-
Capture the signing hash. The Schneider M580 / M340 firmware image is signed; the SHA-256 hash of the image is in the EcoStruxure Control Expert update package. Record it on the FAT (Factory Acceptance Test) sheet so the customer can verify what was loaded.
-
Record the engineering password policy. The M580 and M340 both support role-based access. Configure the role policy before the FAT, document the roles and the password complexity, and burn the policy file with the project archive. This is what the August 12 Security Boulevard test demonstrated a self-attested integrator would skip.
-
Disable unused services. The M580 BMENOC module ships with FTP, TFTP, SNMPv1, and a diagnostic web page enabled by default. Turn off what is not used. The same goes for the Ethernet ports on the BMEP581020 itself if the cabinet will only use one of them. Every default service left on is a question you do not want during a customer audit.
-
Document the supply chain. The Modicon M580 and M340 CPUs we supply come with a documented distribution path. For an EU-bound cabinet, the customer will eventually ask whether the CPU went through any party that re-flashed it. The answer is yes if it did, no if it did not — but you have to be able to answer. Our stock is dispatched as-received from authorised channels; we do not re-flash, and the firmware revision on the device label matches what the catalog says.
-
Reserve the CPU early. A six-to-eight week lead time on the BMEP581020 and three-to-five weeks on the BMXP342020 is the Q3 2026 baseline from this warehouse. If your customer's PO does not arrive until late October, do not assume you can buy an M580 CPU in time for a December shipment. Order against the quotation, not the PO, and confirm the firmware revision at the moment of order placement.
-
Plan the M340 fallback in advance. For non-EU panels, the M340 BMXP342020 is the safe default at three-to-five week lead time. If the customer is willing to accept M340 instead of M580, document the substitution as a separate line so it is auditable later. Do not let the substitution happen during commissioning when the documentation cannot catch up.
-
Treat the RFQ cybersecurity line as binding. If your customer's RFQ now asks for firmware provenance, signing hash, and cybersecurity manual reference, answer it. Treat the absence of those questions on an EU-bound RFQ as a yellow flag that the customer is not yet aware of CRA — not as a green flag that you can skip the work. The October 2026 wave of EU customer PO templates will catch up.
-
Capture MOQ and bulk pricing in writing. The MOQ on both the BMEP581020 and the BMXP342020 is one unit, but the price ladder for 10+ units or for cabinets that include the BMENOC0301 module together can change by a meaningful margin. Put the price on the quotation row alongside the firmware revision so the customer sees both at the same time.
-
Capture selection documentation. Where the customer is asking the panel shop to make the PLC selection, capture the selection rationale in writing. The cybersecurity manual reference, the firmware version, and the Achilles certification (where applicable) all belong in the panel shop's design document, not just the quotation.
The takeaway
The September 11 2026 EU CRA reporting deadline is not a hypothetical event for a SEA panel shop; it is the date that EU customers start asking for documentation you may not yet have on file. The 4,400 exposed Rockwell PLCs disclosed on August 6 2026 are the proof, if any was needed, that the threat is real and that the install base is large. The catalog at this site carries the two Modicon CPUs — BMEP581020 at aiDemandScore 83.5 and BMXP342020 at aiDemandScore 84.2 — that map cleanly to a CRA-aware quotation. The single action to take this week is to add firmware-revision and signing-hash lines to your standard quotation template and to order the BMEP581020 CPU against any quotation that will be delivered in Q4 2026. If the cabinet is going to the EU and the customer has not yet sent you the CRA line, send the selection checklist to them first; it saves a round-trip in October.