What is an OEM?
An OEM (Original Equipment Manufacturer) is a company that designs and produces machines, equipment or components that another company incorporates into an end product or sells under its own brand. In industrial automation, “OEM” usually means the machine builder: the company that supplies a complete machine or process module, including the PLC, operator interface and software. For the end user, the OEM is often the key party for maintenance, updates and remote support for many years, which makes it an important link in OT security as well.
🧠 Why is the term OEM so confusing?
The term OEM has two meanings that almost contradict each other:
- The original maker — the company that produces a part which another company resells under its own label. A drive manufacturer that supplies the same inverter under the brand of a larger automation vendor is the OEM in this sense.
- The brand owner of the end product — the company that buys components from others, assembles them and sells a complete product under its own name. In automotive and machine building this is the usual meaning: the carmaker or machine builder is called the OEM, its suppliers are not.
In industry, the second meaning dominates. Large automation vendors consistently refer to machine builders that build their PLCs and drives into machines as “OEM customers”. A related term adds to the confusion: an ODM (Original Design Manufacturer) both designs and produces a product that someone else then sells under its own brand. For legislation the label OEM does not matter at all: what counts is who places the product on the market as manufacturer, under its own name or trademark.
🔄 How does an OEM differ from a system integrator and an end user?
| Role | What does this party supply or do? | Example | Role in IEC 62443 |
|---|---|---|---|
| Component supplier | Individual products: PLC, drive, sensor, HMI software | Control hardware vendor | Product supplier |
| OEM / machine builder | Complete machine or skid with its own control system and software | Packaging machine, CNC machining centre, dosing skid | Product supplier (machine as product), often also service provider |
| System integrator | Connects machines and systems into a plant, programs SCADA and DCS | Engineering firm integrating a production line | Integration service provider |
| Maintenance provider | Support, updates and breakdown service after handover | Service contract from the OEM or a third party | Maintenance service provider |
| End user / asset owner | Owns and operates the installation | Food plant, water utility | Asset owner |
The boundaries are blurred. A skid builder, for instance, delivers a complete process module (pumps, valves, instrumentation and its own PLC on a frame) that the integrator then connects on site. Large OEMs frequently offer integration and maintenance services too, so a single company may hold several roles at once.
🧱 What legal obligations does an OEM have?
In Europe, three regulations shape the OEM’s playing field:
- Machinery Regulation (EU) 2023/1230 — applies from 20 January 2027. The machine builder is the manufacturer within the meaning of the regulation and is responsible for the risk assessment, technical file, EU declaration of conformity and CE marking. New are the essential requirements on protection against corruption of safety-related software (1.1.9) and against malicious attempts to influence control systems (1.2.1).
- Cyber Resilience Act (EU) 2024/2847 — covers products with digital elements such as PLCs, HMIs and engineering software. The obligation to report actively exploited vulnerabilities and severe incidents has applied since 11 September 2026 (early warning within 24 hours, notification within 72 hours); the remaining requirements apply from 11 December 2027. Fines can reach 15 million euros or 2.5% of worldwide annual turnover.
- Data Act (EU) 2023/2854 — applicable since 12 September 2025. Users of connected products, including industrial machinery, are entitled to the data the product generates.
Watch out for one important trap: under Article 18 of the Machinery Regulation, anyone who substantially modifies a machine becomes its manufacturer. A substantial modification is a physical or digital change not foreseen by the original manufacturer that creates a new hazard or increases an existing risk. An end user or integrator who, for example, rebuilds the safety control system or loads new software that affects safety takes on the manufacturer’s obligations. This mainly arises with retrofits in brownfield environments.
🔐 What role does the OEM play in OT security?
The OEM largely determines how secure a machine is when it arrives on site and how long it stays that way. IEC 62443 divides responsibilities between three roles: the asset owner, the service provider and the product supplier.
- As product supplier — the OEM develops the machine and its software under a secure development lifecycle (IEC 62443-4-1) and selects components that meet IEC 62443-4-2.
- As service provider — IEC 62443-2-4 (edition 2.0, December 2023) sets requirements for parties that integrate an automation solution (design, installation, configuration, testing, commissioning and handover) or maintain it after handover. Many OEMs fall into that second category through their service contracts.
- As supplier of updates — the Cyber Resilience Act requires manufacturers to set a support period of, as a rule, at least five years during which vulnerabilities are handled, and to draw up an SBOM (software bill of materials) for the product.
For the end user, OEMs therefore fall under supplier security and third-party risk management, which NIS2 (Article 21) makes explicitly mandatory for essential and important entities.
⚠️ What security risks do OEMs introduce?
Remote access
Many machines ship with their own 4G router or VPN box so that the OEM can fix faults remotely. Such connections often bypass the plant’s firewall and access policy. When several OEMs each bring their own remote access, dozens of uncontrolled entry points into the OT network appear. A central jump server with multi-factor authentication, session logging and access that is only opened on request is the usual answer.
Warranty and patching
Many OEMs only permit updates they have validated themselves; installing a Windows patch on an HMI PC on your own initiative can void the warranty or support. As a result, machines sometimes run for years with known vulnerabilities. IEC TR 62443-2-3 (2015) describes how asset owners and suppliers exchange patch information. Agree contractually on how quickly the OEM validates patches, so that patch management does not grind to a halt.
Lifecycle
A machine often stays in service for twenty years or more, while the embedded control software falls out of support much sooner. The result is legacy systems for which the OEM no longer provides updates.
🛠️ How do you set security requirements for an OEM?
- Specify requirements in the tender — ask for IEC 62443-4-1 certification, the security level of the machine and an SBOM on delivery.
- Control remote access — prohibit the OEM’s own modems and routers; the OEM works through your jump server with personal accounts and session logging.
- Agree patch timelines — for example validation of critical security patches within 30 days, and no loss of warranty when validated patches are installed.
- Fix the support period — at least five years of security updates, and notice well before end of support.
- Require disclosure — the OEM informs you about vulnerabilities and incidents that affect your machines.
- Arrange data access — define which machine data you receive and whether you may share it with third parties, in line with the Data Act.
- Test at handover — check default passwords, open ports and unnecessary services before the machine is connected to the network.
| Contract topic | Typical requirement |
|---|---|
| Development process | IEC 62443-4-1 or demonstrably equivalent |
| Remote access | Only via the end user’s jump server, MFA mandatory |
| Patches | Critical patches validated within 30 days |
| Support | At least 5 years of security updates |
| Documentation | SBOM, network overview, list of ports and services |
| Data | Access to machine data in line with the Data Act |
❓ Frequently asked questions
What does OEM mean in industry?
In industry, an OEM (Original Equipment Manufacturer) is usually a machine builder that supplies a complete machine or process module under its own name. The OEM buys in components such as PLCs and drives and adds its own mechanical design and software. The end user buys the machine from the OEM as a single product.
What is the difference between an OEM and a system integrator?
An OEM supplies a machine it has designed itself as a product, whereas a system integrator connects existing machines and systems into a working installation. The OEM is therefore the manufacturer under the Machinery Regulation, while the integrator is a service provider in IEC 62443 terms. In practice, large OEMs often fulfil both roles.
Is an OEM responsible for the cybersecurity of a machine?
Yes, as manufacturer an OEM is responsible for the cybersecurity of the machine it places on the market. The Machinery Regulation requires protection against corruption and malicious interference, and the Cyber Resilience Act obliges OEMs to handle vulnerabilities and provide security updates. The end user remains responsible for operating the machine securely within its own network.
Can I install patches myself on an OEM machine?
That depends on your contract with the OEM. Many OEMs only allow validated patches and otherwise exclude warranty or support. Agree in advance how quickly the OEM tests and releases security patches.
Why is OEM remote access a security risk?
OEM remote access is a risk because the OEM’s own modems and VPN connections often bypass the security of the plant network. Attackers can then reach the control system directly through a shared password or a vulnerable router. Let the OEM work only through a controlled jump server with MFA and logging.
What does the Data Act change for OEMs?
The Data Act gives users of connected machines the right to the data the machine generates, even if the OEM currently uses that data exclusively. Machines placed on the market after 12 September 2026 must be designed so that this data is accessible by default. An OEM can therefore no longer reserve data access solely for its own service contract.
📌 In summary
An OEM is the builder of a machine or component that someone else puts into operation or resells, and therefore the party that decides how secure that machine is at the start of its life. The Machinery Regulation, the Cyber Resilience Act and the Data Act impose hard obligations on OEMs; end users make the difference with clear contractual requirements on remote access, patching, SBOMs and support.
