Industries · IIoT & Energy

In the end, the plant runs longer and needs less

Less energy, fewer service calls, less electronic waste. That is what we develop electronics, firmware and gateways for in industry and energy technology, and we operate the devices as a fleet in qdCloud. The obligations under the Cyber Resilience Act we carry with you for as long as the device is on the market.

Triggers

Typical entry points

  • The successor device

    The predecessor has run for years, components are discontinued, and the firmware was never designed for connectivity. The successor needs new electronics and a secured update path.

  • The safety function moves into the device

    Safe torque off, safe stop, safe brake: what a contactor once handled, machine builders now expect from the device itself.

  • The device is in the field, the CRA arrives anyway

    From December 2027 every product with digital elements must be able to fix vulnerabilities. We review the software, create the SBOM and assess the update path for your existing device.

Regulation

Regulatory framework for connected devices

  • Cyber Resilience Act

    Regulation (EU) 2024/2847. Reporting obligations apply since 11 September 2026, the product requirements from 11 December 2027, and the support period is at least five years. Monitoring vulnerabilities, assessing them and providing updates is what we take on for as long as the device is on the market.

  • IEC 62443

    Security for automation systems. Threat analysis first, then security requirements, then the architecture: secure boot, encrypted storage, protected connection, roles in the application.

  • EN 18031

    Radio equipment with internet access has had to meet the cybersecurity requirements of the Radio Equipment Directive since August 2025. For devices with Wi-Fi, Bluetooth or cellular we plan the measures in from the start.

  • IEC 61508 and ISO 13849

    Functional safety up to SIL 3 to IEC 61508 and up to PL e to ISO 13849. For our unit test framework the tool qualification IEC 61508 requires is in place.

  • Machinery Regulation

    From January 2027 cybersecurity is part of the CE marking of machinery. The standard for it, prEN 50742, exists as a draft; we already align controllers to it.

  • ISO 9001 and ISO 27001

    Sales, development and manufacturing are certified to ISO 9001. The information security management system behind it is built to ISO/IEC 27001 and is going through certification.

  • Cyber Resilience Act
  • IEC 62443
  • EN 18031
  • IEC 61508
  • ISO 13849
  • Machinery Regulation
  • ISO 27001

We work to these standards and regulations.

A device is sold in a day. It is operated for years.

Manufacturers in IIoT and energy technology who have developed with us

  • Janitza
  • BRUGG eConnect
  • halstrup-walcher
  • LIMOSS
  • HS-Technik
  • pro-beam
  • Luftmeister

Series

We support the series

  • Getting updates into the field

    A patch is worth nothing until it reaches the device. Through qdCloud we roll out firmware and configuration to fleets of any size, following your rollout strategy and with regard to system load.

  • Vulnerabilities across the field life

    Libraries, kernel and images of your device stay under watch. New vulnerabilities we assess against your device and prepare the report in substance; the 24-hour deadline stays achievable.

  • Remote access and support

    Secure access to every device in the infrastructure, with live support and screen sharing. We take in faults, follow them up and bring the correction back into the field.

  • Discontinued components

    We monitor your bills of materials and report discontinuations before they become a supply stop. If a replacement does not fit one to one, we change the design and verify the change.

Matching building blocks

Products that save time in IIoT projects

  • Logo qdHardwarePlattform
    Hardware

    qdHardwarePlatform

    qdGate as IoT gateway, qdSBC as single-board computer, plus the qdSOM module. Free pins and interfaces for your sensors, retrofit without swapping the controller.

    View
    View
  • Logo qdCoreX
    Operating system

    qdCoreX

    Buildroot-based Linux with a mainline LTS kernel. Brings the device side for updates, logging and certificates with it.

    View
    View
  • Logo qdCloud
    IoT platform

    qdCloud

    Fleet overview, updates and remote access for connected devices. Hosted in Europe or on your own infrastructure.

    View
    View
  • Logo qdTest
    Production test

    qdTest

    Programming and testing every assembly at the end of the line. Stays valid even when a component changes.

    View
    View

Services

The services behind it

  • Systems Engineering

    Requirements, architecture and system boundaries before the first board exists.

  • Hardware Engineering

    Power supply, battery management, radio and high-speed, laid out for ten years of component availability.

  • Embedded Software Engineering

    Firmware, embedded Linux and the application on top, for devices with a long field life.

  • IoT-Cloud Engineering

    Web interfaces on the device, services behind them and the connection to the system you already run.

  • AI Engineering

    Recognising conditions and anomalies on the device, with the model in the signed update.

  • Verification

    Unit tests through EMC measurement, with reports you can present in an audit.

  • Cyber Security

    Secure boot, signed updates and vulnerability management across the field life.

Frequent questions

What manufacturers ask us before the start

Do I have to use qdCloud?

No. We also connect your device to your own cloud or your ERP. The service is the development; qdCloud is an option.

Our plant has an old controller. Does it have to go?

No. A gateway collects states and energy data at the controller and brings them online; the controller stays. If it needs updates itself, replacing it is the alternative. We assess both routes with you.

Where is our data held?

In Europe or on your own infrastructure. The setup is the same. Where it runs is your decision.

Who reports a vulnerability to the authority?

The obligation lies with the manufacturer, that is with you. We deliver the basis: we detect the vulnerability, assess it against your device and prepare the report in substance.

Next step

Tell us about your plant and your devices.

Describe the device, the quantities and your schedule. We will tell you how we would approach the project and where we see risks for operation and approval. The evaluation up to a budgetary price is free of charge.

Florian Seibold

Managing Director

info@querdenkerengineering.de

+49 7807 890 80 10