Improving industrial cybersecurity

AVEVA and the EU Cyber Resilience Act (CRA)

Our Commitment to You

  • As an industrial software leader trusted by more than 20,000 customers globally, AVEVA is committed to helping you maintain a strong cybersecurity posture and align with applicable requirements, including the EU Cyber Resilience Act (CRA).
  • Our approach is proactive. We embed secure-by-design software development practices from the start, not as an afterthought. The 2024 update to our product lifecycle policy was guided in part by CRA requirements.
  • We completed a CRA-readiness assessment across our portfolio, including due-diligence evaluation of thousands of third-party components.
  • We identified the products that we expect to move forward for CRA conformity assessment and CE marking ahead of the main sales obligation that goes into effect December 11, 2027.

What this means for your current system

  

AVEVA will support your existing deployments according to our Software Lifecycle and Retirement Policy:

  • Standard‑Term Servicing (STS): maximum of 3 years Full Support + maximum of 2 years Security-only Support
  • Long‑Term Servicing (LTS): 5 years Full Support + 2 years Stability Support

The CRA does not require you to replace existing systems.  You can continue to access security supported versions and renew support in alignment with our lifecycle policy to ensure continuity through the declared support period. Upgrades can be planned on a predictable schedule.    

What this means for accessing older versions

Starting December 11, 2027, AVEVA intends to remove access to software versions that no longer receive security support. This ensures that customers can be confident that all software obtained from AVEVA continues to benefit from active security monitoring, ongoing support, and alignment with current regulatory requirements.

Considerations for a smoother transition

  

  1. Build a facility-level modernization roadmap. Combine asset inventory, lifecycle/support dates, and criticality to prioritize upgrades that improve resilience without disrupting operations.
  2. Engage vendors early.  Align upgrade and migration timelines with maintenance windows, high impact systems, complex integrations, or validation cycles.
  3. Strengthen IT/OT/ET collaboration. Align on testing, patching windows, incident handling, and supply-chain checks in ways that consider the realities of industrial environments.

Summary: Benefits of early preparation and improved cybersecurity

With a dedicated focus on industrial needs and lifecycle support, AVEVA aims to provide a clear, practical path to modernize securely at your pace. Key benefits include:

  • Predictable planning: Clear support windows help you plan orderly upgrades, reducing last-minute disruption and unplanned downtime.
  • Stronger supply‑chain visibility: Clear visibility into suppliers and third-party components reduces hidden risk across complex industrial environments
  • Improved operational continuity: Secure by design practices and CRA-aligned lifecycle practices support safer, more resilient systems.

* Note: This material is for general information only and does not constitute legal advice or a guarantee of conformity. Customers are responsible for assessing their own obligations.