<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jasper Bogaerts, Author at Verhaert Masters in Innovation</title>
	<atom:link href="https://verhaert.com/author/jbogaerts/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Boosting your capacity to innovate</description>
	<lastBuildDate>Tue, 04 Nov 2025 14:33:35 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://verhaert.com/wp-content/uploads/cropped-2024-Verhaert-Favicon-32x32.jpg</url>
	<title>Jasper Bogaerts, Author at Verhaert Masters in Innovation</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CRA compliance in practice: The strategic role of OTA updates</title>
		<link>https://verhaert.com/insights/blog/di/the-strategic-role-of-ota-in-cra-compliance/</link>
		
		<dc:creator><![CDATA[Jasper Bogaerts]]></dc:creator>
		<pubDate>Fri, 26 Sep 2025 11:05:29 +0000</pubDate>
				<category><![CDATA[Digital innovation]]></category>
		<category><![CDATA[Digital transformation]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://verhaert.com/?p=41193</guid>

					<description><![CDATA[<p>Discover how OTA updates emerge as a powerful enabler, beyond an efficient way to deliver timely patches and extend CRA compliance.</p>
<p>The post <a rel="nofollow" href="https://verhaert.com/insights/blog/di/the-strategic-role-of-ota-in-cra-compliance/">CRA compliance in practice: The strategic role of OTA updates</a> appeared first on <a rel="nofollow" href="https://verhaert.com">Verhaert Masters in Innovation</a>.</p>
<p>The post <a href="https://verhaert.com/insights/blog/di/the-strategic-role-of-ota-in-cra-compliance/">CRA compliance in practice: The strategic role of OTA updates</a> appeared first on <a href="https://verhaert.com">Verhaert Masters in Innovation</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>The Cyber Resilience Act (CRA) marks a decisive shift in how the EU regulates digital products. Contrary to previous regulations, cybersecurity is no longer a voluntary best practice or industry-specific add-on. It’s a binding obligation for all manufacturers and service providers selling products with digital elements in the EU. ‘Secure by design’ instead of ‘secure if you’re lucky’.</strong></p>
<p><strong>Within this new landscape, over-the-air (OTA) updates emerge as a powerful enabler. Beyond offering an efficient way to deliver timely patches and extend compliance beyond launch, OTA capabilities within software platforms unlock strategic advantages. To explore this further, we sat down with Jasper Bogaerts, <a style="text-decoration: underline;" href="https://verhaert.digital/" target="_blank" rel="noopener">Verhaert Digital</a>’s CRA specialist. Let’s dive in!</strong></p>
<p><img fetchpriority="high" decoding="async" class="alignnone wp-image-33447" style="margin-bottom: 20px;" src="https://verhaert.com/wp-content/uploads/2025-Blog-The-strategic-role-of-OTA-updates-in-CRA-compliance-banner.png" alt="Banner OTA in CRA" width="762" height="457" /></p>
<div style="background-color: #e5e8ea; padding: 20px; margin-bottom: 20px;">If you want more information about the CRA and its implications in product development, make sure to check out our blog ‘<a style="text-decoration: underline;" href="https://verhaert.com/insights/blog/pi/how-the-cra-will-redefine-product-innovation/" target="_blank" rel="noopener">Building trust by design: How the CRA will redefine product innovation</a>’.</div>
<h2>Why are OTA updates considered an interesting measure to keep hardware with a digital component and software secure under the CRA?</h2>
<p>Through OTA updates, the manufacturer has a way to <strong>efficiently keep products secure throughout their lifecycle</strong>. Even for companies that don’t yet have a fully mature cybersecurity strategy, OTA can be an interesting option. Whenever a vulnerability is discovered after the release, you can deliver patches quickly and at scale. However, OTA should not be seen as a substitute for ‘secure by design’ — rather, it complements a broader, more mature security approach. While a manufacturer needs to put in place the necessary processes to rapidly identify the root causes for these vulnerabilities and develop patches, OTA updates have proven to be an effective approach to disseminate those security updates, minimizing disruption for the end-user.</p>
<p>In short, a typical OTA update works as follows:<br />
<img decoding="async" class="aligncenter wp-image-41276 size-large" src="https://verhaert.com/wp-content/uploads/OTA-updates-process-V3-1024x331.png" alt="" width="1024" height="331" srcset="https://verhaert.com/wp-content/uploads/OTA-updates-process-V3-1024x331.png 1024w, https://verhaert.com/wp-content/uploads/OTA-updates-process-V3-300x97.png 300w, https://verhaert.com/wp-content/uploads/OTA-updates-process-V3-768x248.png 768w, https://verhaert.com/wp-content/uploads/OTA-updates-process-V3-1536x496.png 1536w, https://verhaert.com/wp-content/uploads/OTA-updates-process-V3-2048x662.png 2048w, https://verhaert.com/wp-content/uploads/OTA-updates-process-V3-464x150.png 464w" sizes="(max-width: 1024px) 100vw, 1024px" /></p>
<h2>How do OTA updates reduce both technical and organizational compliance burdens compared to more traditional update methods?</h2>
<p><strong>Traditional updates</strong> generally require manual or physical intervention. For example, a maintenance team would need to access each affected device one by one, which, from an organizational perspective alone, can be quite a burden, especially if they were deployed in remote or hard-to-reach locations. Alternative methods involving wired connections may be subject to technical problems, such as faulty wires, or involve technical challenges when disseminating the patches through local networks.</p>
<p>OTA strategies that account for client requirements, operational constraints and security priorities dramatically reduce these burdens. They enable <strong>centralized or selective deployments remotely</strong>, controlling which devices are updated, when and how. This flexibility is especially valuable in environments where <strong>updates can be prioritized or scheduled</strong> to minimize disruption and downtime. Using management platforms or orchestration tools, manufacturers can ensure patches are applied efficiently and securely across diverse devices.</p>
<h2>Can you give some examples of industries that already rely heavily on OTA updates?</h2>
<p>Industries that apply this are becoming increasingly widespread. For instance, in the <strong>automotive industry</strong>, some regulations require manufacturers to have a software update management system and prove safe OTA update practices. Tesla pioneered this for both features and safety recalls. Volkswagen, BMW and Ford now rely on OTA to comply with international vehicle regulations, too.</p>
<p>The automotive industry is not alone. For quick, at-scale security patches for <strong>smartphones, tablets and smartphone equipment</strong>, OTA programming is already being considered the most feasible way to apply effective security updates, and many manufacturers have mature processes in place to support this.</p>
<p>Depending on the product and scaling needs, OTA technology can vary, but <strong>three interesting models</strong> stand out:</p>
<ul style="padding-left: 40px; padding-bottom: 20px;">
<li>Lightweight OTA for consumer IoT – designed for devices with limited memory and processing power (e.g. smart speakers, wearables), where updates are automated and minimally disruptive.</li>
<li>Managed OTA for mid-scale fleets – used in sectors like healthcare or smart home hubs, where orchestration tools enable selective rollouts, device grouping, and compliance tracking.</li>
<li>Industrial-grade OTA ecosystems – applied to critical infrastructure and large-scale industrial systems, with redundancy, scheduling, and strict fail-safes to minimize downtime (e.g. manufacturing equipment, energy networks).</li>
</ul>
<h2>What are the technical prerequisites for companies to implement OTA updates?</h2>
<p>OTA updates are not always necessary or feasible: some products lack the required network components options, face strict security constraints or simply do not justify the additional cost and complexity. When OTA is worthwhile, there’s a wide range of technical challenges that a company must address in order to be able to support OTA programming.</p>
<p>First and foremost, the <strong>infrastructure</strong> must be there to support the volume and distribution of devices while meeting client-specific requirements. From a security perspective, <strong>essential measures</strong> include the capability to support secure boot (verified firmware), having a good fail-safe, applying robust encryption in transit, mutual verification of device and server identities in the update process, and being able to provide trustworthy audit trails of the complete update cycle, from server to device. Besides this, there is also the question of how the interaction with the consumer will be. Will all updates be automated? Can they be rescheduled? How are they informed? To what extent does the consumer have control over what is being updated and when? Especially when there are multiple similar devices that might be impacted in an industrial setting. All this requires technical support to ensure that an update is delivered in an effective manner. As a consequence, supporting OTA updates may involve tailored approaches depending on the context of the devices, requiring a thorough analysis to determine the optimal way to apply them seamlessly.</p>
<p>In summary, here’s a <strong>checklist of some typical technical prerequisites</strong> for secure OTA updates:</p>
<p><img decoding="async" class="aligncenter wp-image-41278 size-large" src="https://verhaert.com/wp-content/uploads/OTA-updates-prerequisited-V2-1024x614.png" alt="" width="1024" height="614" srcset="https://verhaert.com/wp-content/uploads/OTA-updates-prerequisited-V2-1024x614.png 1024w, https://verhaert.com/wp-content/uploads/OTA-updates-prerequisited-V2-300x180.png 300w, https://verhaert.com/wp-content/uploads/OTA-updates-prerequisited-V2-768x461.png 768w, https://verhaert.com/wp-content/uploads/OTA-updates-prerequisited-V2-1536x921.png 1536w, https://verhaert.com/wp-content/uploads/OTA-updates-prerequisited-V2-2048x1229.png 2048w, https://verhaert.com/wp-content/uploads/OTA-updates-prerequisited-V2-250x150.png 250w" sizes="(max-width: 1024px) 100vw, 1024px" /></p>
<h2>How can companies ensure that OTA updates don’t introduce new vulnerabilities?</h2>
<p>The more features you integrate, the bigger the attack surface becomes, so ensuring OTA updates themselves remain secure is critical. On a technical level, this is typically implemented through <strong>digital signatures</strong> that verify the patch originates from the manufacturer. This requires a secure supporting infrastructure and strict controls to protect the signing keys.</p>
<p>Besides securing the rollout itself, developers must also <strong>rigorously test the patches</strong> to prevent introducing additional problems and vulnerabilities. Techniques such as static and dynamic application security testing and penetration testing help identify potential risks. However, these practices should be part of a holistic approach, not only to make them compliant with the CRA, but rather to make any digital solutions produced more secure by design.</p>
<h2>Beyond CRA compliance, what strategic advantages do OTA updates offer?</h2>
<p>There are several. They enable <strong>data-driven improvements</strong>, using analytics and telemetry to give insight into usage and tailor updates accordingly. <strong>Operational costs drop</strong> by reducing returns, recalls and manual maintenance efforts, while rollout across environments becomes simpler. OTA programming can also <strong>improve revenue streams</strong>, positioning the offering as premium through seamless, reliable updates and enabling value-added services such as prioritized or extended support.</p>
<h2>Do you expect the CRA to influence global cybersecurity standards? Will OTA updates become a universal best practice in this?</h2>
<p>CRA will absolutely change the way digital products are built. In many ways, it will formalize actions that we have been doing implicitly up until now, and make the security-related decisions more explicit. This benefits both companies through higher-quality solutions and customers who gain secure-by-default devices.</p>
<p>Consider home appliances, which are increasingly connected. Even though they typically come with a two-year warranty, people expect them to last 10 years or more. That’s a long time in the digital world, and a long time for potential hackers to exploit vulnerabilities.</p>
<p>Taking this into account, I can see OTA updates becoming the <strong>predominant method of disseminating both security patches as well as any other product updates</strong>. Factors like network access, cost and design constraints will continue to influence adoption, but I’m confident that moving forward, the advantages will compel manufacturers to consider the approach whenever they design a digital product.</p>
<h2>If there’s one takeaway you want readers to remember, what would it be?</h2>
<p>Both the CRA and OTA programming should be a <strong>means, not an end, toward reaching certain goals</strong>, be it better cybersecurity or better reach toward devices that require updates.</p>
<p>At Verhaert Digital, our focus is on the purpose behind the legislation:<strong> creating genuinely secure digital solutions</strong>. Compliance is important, but you should aim for a holistic, effective and lasting solution that addresses core challenges and protects devices as effectively as possible.</p>
<p>The post <a rel="nofollow" href="https://verhaert.com/insights/blog/di/the-strategic-role-of-ota-in-cra-compliance/">CRA compliance in practice: The strategic role of OTA updates</a> appeared first on <a rel="nofollow" href="https://verhaert.com">Verhaert Masters in Innovation</a>.</p>
<p>The post <a href="https://verhaert.com/insights/blog/di/the-strategic-role-of-ota-in-cra-compliance/">CRA compliance in practice: The strategic role of OTA updates</a> appeared first on <a href="https://verhaert.com">Verhaert Masters in Innovation</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
