Industrie 4.0 data platform with MES, ERP and OPC UA
Integration architecture with interface catalog and data contracts
More on thisIndustries / Manufacturing
Connect MES, ERP and production while protecting industrial control systems.
Consulting. Integration. Operations.

Built around your industry.
Your priorities
We integrate MES and ERP into one continuous data chain, bring machine and quality data together on data platforms and develop models for predictive maintenance and planning.
Integration architecture with interface catalog and data contracts
More on thisAccess concept with roles, approval process and contract annex for vendors
More on thisData platform with asset model and connected sources
More on thisFrom strategy to implementation
Six fields of expertise. Explore the scope that fits your project.
Our approach
The manufacturing execution system (MES) runs production, the ERP manages orders, material and finance, and machines report their states over OPC UA. We place an integration layer to ISA-95 with versioned interfaces between these levels so that orders reach the shop floor automatically and confirmations flow back without rework. Older equipment is connected through retrofitted gateways without touching the controller. Master data, bills of materials and batches stay consistent in one system of record.
A series manufacturer replaces nightly file exports between MES and ERP with an integration layer; planning sees machine states and confirmations at the same pace as production.
Our approach
IEC 62443 divides a plant into zones with the same protection need and conduits for the controlled traffic between them, and each zone gets a target security level. We inventory equipment, controllers and data flows, assess risks to IEC 62443-3-2 and separate production networks from the office network with segmentation, firewalls and data diodes. Passive network monitoring detects new devices and unusual connections without loading the controllers. Removable media and maintenance laptops pass a checkpoint before they enter a zone.
An automotive supplier separates press shop, paint shop and assembly into zones with their own conduits; an incident in office IT has since had no effect on the lines.
Our approach
Machine vendors, integrators and your own maintenance staff need access to controllers, often at night and from outside the plant. We replace permanent VPN tunnels and shared passwords with a central access platform with personal accounts, multi-factor authentication and approval per job. Every session terminates on a jump host inside the zone, is recorded and ends automatically when the ticket closes. External companies reach only the machine named in the ticket and only for the agreed time.
A plant consolidates the remote access of several machine vendors on one access platform; every job is tied to a ticket, recorded and available for the customer audit.
Our approach
The Cyber Resilience Act requires secure updates for products with digital elements throughout the support period. We build a device PKI whose root CA and issuing CA keep their keys in an HSM certified to FIPS 140-3 Level 3. Firmware is signed from the build pipeline with separation of roles, approval and a record per release. Every device receives its own identity to IEEE 802.1AR on the production line, which it later presents to cloud, remote maintenance and the update server. Vendor-neutrally we choose between Entrust nShield 5c, Utimaco u.trust GP HSM and Thales Luna 7, depending on certification, throughput and operating model.
A manufacturer of drive controllers moves its signing key from the build server into an HSM; every release is signed after approval and every device leaves the factory with its own certificate.
Our approach
Machines deliver vibration, temperature, current and cycle times, test stations deliver measurements and scrap reasons. We merge these series with order and maintenance data and train two kinds of models on them. One detects anomalies in bearings, spindles and pumps days before a failure, the other predicts the quality of a batch from process parameters. Every prediction names the features that triggered it so that maintenance and quality assurance can check it. Models run versioned in production, with drift monitoring and controlled retraining after a tool change or a recipe change.
A manufacturer of plastic parts predicts scrap per batch from temperature, pressure and cycle time; setters correct parameters before the test station reports the problem.
Our approach
Machines stay in the field for twenty years, yet their certificates and signatures rely on RSA and elliptic curves, which capable quantum computers will break. We inventory the cryptography in controllers, device PKI, remote maintenance and firmware signing and rate each use by device lifetime and the effort of a replacement. Firmware signatures move first, because hash-based schemes such as LMS and XMSS are standardized today and run in HSMs. Device identities and TLS follow with ML-DSA and ML-KEM in hybrid certificates as soon as controllers and libraries support them.
A manufacturer of field devices signs new firmware additionally with LMS; devices of the next generation verify both signatures, older devices keep the classical check until replacement.

Typical project situations
A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.
Illustrative situations, not customer references.
01 / Manufacturing
New machine generation with network connectivity, firmware updates unsigned, signing key as a file on the build server, no SBOM.
Device PKI with HSM, signing service in the build pipeline with approval per release, device identities from the factory, SBOM and vulnerability process to the CRA.
Signed updates with records, technical documentation for the conformity assessment, reporting process for exploited vulnerabilities in place.
02 / Manufacturing
One network from office to press, remote maintenance over vendor routers at the machine, customer audit to IEC 62443 announced.
Zone and conduit model with risk assessment, firewalls and a data diode between office IT and production, central access platform with session recording.
Customer audit passed, remote access approved and logged per ticket, incidents in office IT without effect on the lines.
03 / Manufacturing
Scrap shows up only at the test station, MES and ERP exchange data in nightly runs, process data sits unused in the controllers.
Integration layer between MES and ERP, time-series platform over OPC UA, quality model per batch with explanation of influencing factors.
Confirmations at the pace of production, parameter correction before inspection, versioned models with drift monitoring in operation.
Working together
From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.
How we work
Equipment, systems, interfaces, data flows and regulatory gaps
Zone model, integration architecture, PKI and operating model
Segmentation, interfaces, signing service and models in maintenance windows
Monitoring, certificates, audits, knowledge transfer
Before our first conversation
Start with a concrete challenge. These four questions help us find the right direction together.
Book a first consultationYour current challenge and the outcome you are aiming for.
An overview of sites, applications and interfaces.
Project dates, maintenance windows and known dependencies.
The right people from IT, security and operations.
Six modules from MES and ERP integration to post-quantum readiness, planned, integrated and operated by OTOKO®. Production networks, remote maintenance and products with digital elements meet IEC 62443, NIS2 and the Cyber Resilience Act with evidence that holds up in audits. The entire solution runs in German data centers.
IT solutions for manufacturing connect machines, manufacturing execution systems and business software into one continuous data chain and protect operational technology and connected products against attacks. OTOKO® covers six modules: an Industrie 4.0 data platform with MES, ERP and OPC UA, OT security to IEC 62443, secure remote maintenance, device identities and firmware signing with an HSM-backed PKI, predictive maintenance and quality prediction with machine learning, and post-quantum readiness for long-lived machine identities.
What sets OTOKO® apart from a consultancy is the path into operations. Zone model, interfaces, models and releases come with records, version history and the documents that customer audits, NIS2 and the Cyber Resilience Act ask for. Cryptography and hardware security modules are our core competence. Signing keys and the root of your device PKI therefore live in certified hardware, not as a file on a build server.
Cryptography and hardware security modules are our core competence. Firmware signing keys and the root of your device PKI live in certified HSMs rather than as a file on a build server.
The entire solution runs in German data centers, from the data platform through the PKI to the remote maintenance platform.
We work with operators of critical infrastructure and regulated industries. We know customer audits to IEC 62443, TISAX assessments and what information security and production expect from a plant.
One team accompanies you from consulting to operations. OT security architects, integration developers and data engineers stay on, aligned with shifts and maintenance windows.
Most plants do not fail on technology but on flat networks, data silos and obligations that arrive faster than the next maintenance window.
01
Controllers, HMI panels and office PCs share one network, remote maintenance lands directly on the machine and a ransomware incident in IT reaches production unhindered.
02
Machine data sits in vendor formats, the MES reports quantities to the ERP by file export and bills of materials are maintained by hand in both systems.
03
Firmware is signed with a key that sits as a file on the build server, without separation of roles, a record or a plan for the day it is compromised.
04
NIS2 demands risk management and reporting channels, the Cyber Resilience Act signed updates and vulnerability handling, yet operational technology and product development sit outside the information security management system.
| On-Premises | German cloud | Hyperscaler | |
|---|---|---|---|
| Data location | Your plant and your data center, OT data stays in the zone | Data centers in Germany, operated under ISO 27001 | Azure, AWS or Google Cloud, region selectable |
| Operation | Your team or OTOKO® as managed service | OTOKO®, with audit rights for you and your customers | Shared, platform services by the provider |
| Tools | HSM, PKI and access platform in the plant, Kafka and time-series store at the edge | Hosted HSMs, PKI as a service, data platform and remote maintenance platform | Cloud HSM services, IoT services, managed data services |
| Suited for | Controller-level data, signing keys, plants without a stable connection | Manufacturers with customer audits and a need for sovereignty | Fleet data across sites, model training, load peaks |
| Compliance | Full control, evidence from your ISMS and zone model | Processing agreement under GDPR, location Germany, evidence for TISAX assessments | Processing agreement, standard contractual clauses, exit scenario per service |
Collaboration
Project
Clearly scoped undertaking such as a zone model to IEC 62443, an MES connection or a signing service with a defined result, milestones and acceptance.
Team reinforcement
OT security architects, integration developers or data engineers work in your teams, tools and release processes, aligned with shifts and maintenance windows.
Managed service
OTOKO® operates access platform, PKI and signing service, data platform or OT monitoring with agreed service levels, reports and the evidence that customer audits and NIS2 require.
Five regulations that affect plants and product manufacturers, with what they demand and what OTOKO® delivers for them.
| Requirement | Demands | OTOKO® delivers |
|---|---|---|
| IEC 62443 | Zones and conduits, risk assessment and target security levels for plants, secure development and component requirements for manufacturers, obligations for service providers | Zone and conduit model to 62443-3-2, segmentation and monitoring to 62443-3-3, remote maintenance to 62443-2-4, development process to 62443-4-1 for your products |
| Cyber Resilience Act | Security by design, no known exploitable vulnerabilities at delivery, secure updates throughout the support period, SBOM, reporting of actively exploited vulnerabilities within 24 hours, CE conformity | Signing service with HSM, device PKI, update mechanism, SBOM per release, vulnerability and reporting process, technical documentation for the conformity assessment |
| NIS2 | Risk management with supply chain security, incident handling, cryptography and access control, reporting of significant incidents, management accountability, for machinery, electrical equipment and vehicle manufacturing as important entities | OT inside the ISMS scope, zone model and monitoring, reporting channels with deadlines, evidence for remote maintenance and suppliers, documents for the registration with the BSI |
| ISO 27001 | Information security management system with risk assessment, statement of applicability, Annex A controls, internal audits and management review | Extension of the scope to production and product development, risk register for OT, controls and evidence, operation of our services under ISO 27001 |
| TISAX | Information security assessment against the VDA ISA catalog with assessment levels, prototype protection and data protection, exchange of results over the ENX platform | Gap analysis against VDA ISA, controls for network separation, access and remote maintenance, evidence for the assessment level your customers require |
FAQ
15 answers about your industry, the project and ongoing operations.
The portfolio covers the integration of MES, ERP and machines over OPC UA, OT security to IEC 62443, secure remote maintenance, device PKI and firmware signing with HSMs, predictive maintenance and quality prediction, and post-quantum readiness for machine identities. Each module can be commissioned on its own or as a package, with operation in German data centers.
Yes, as soon as a machine contains control software or has a network connection and is placed on the EU market. The manufacturer then has to demonstrate security by design, handle and report vulnerabilities, maintain an SBOM and provide security updates throughout the support period. The reporting obligations have applied since September 2026, the remaining obligations apply from December 2027, and signing service, device PKI and update process need lead time before that.
Usually yes. Equipment without OPC UA is connected through retrofitted gateways or additional sensors that read signals without touching the controller program. We check for each machine which data is available and which route is economical, and we plan the zone and the conduit for the gateway from the start.
Instead of a router or VPN tunnel at the machine, every external technician gets a personal account with multi-factor authentication and an approval per job, tied to a ticket and a time window. The session runs over a jump host inside the zone, is recorded and ends automatically. We work with operators of critical infrastructure and regulated industries. There, this procedure is the precondition for any remote access.
A signing key that exists as a file can be copied without anyone noticing, and a stolen key lets attackers pass off their own firmware as the manufacturer's software. In an HSM certified to FIPS 140-3 Level 3 the key never leaves the device, every signature is recorded and approval follows a separation of roles. The Cyber Resilience Act asks for exactly this evidence for the update mechanism.
Now, with the inventory. Devices shipped today stay in service longer than the expected time until capable quantum computers arrive, and a change of algorithms in the field needs firmware updates, memory in the controller and lead time across several product generations. Firmware signatures with LMS or XMSS can be introduced right away, device identities follow with hybrid certificates as soon as the target hardware can process ML-DSA.
Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.
A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.
OT security architect: Zone model, remote maintenance, evidence to IEC 62443. Integration developer: MES and ERP interfaces, OPC UA, gateways. Cryptography specialist: Device PKI, HSM, signing service, PQC roadmap. Data engineer: Time-series platform, models, drift monitoring. Compliance consultant: CRA, NIS2, TISAX, audit files. Project lead: Milestones, maintenance windows, acceptance, reporting.
We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.
Equipment, systems, interfaces, data flows and regulatory gaps Asset inventory, interface catalog, crypto inventory, gap analysis for IEC 62443, NIS2 and CRA, prioritized list of measures
Project: Clearly scoped undertaking such as a zone model to IEC 62443, an MES connection or a signing service with a defined result, milestones and acceptance. Team reinforcement: OT security architects, integration developers or data engineers work in your teams, tools and release processes, aligned with shifts and maintenance windows. Managed service: OTOKO® operates access platform, PKI and signing service, data platform or OT monitoring with agreed service levels, reports and the evidence that customer audits and NIS2 require.
Monitoring, certificates, audits, knowledge transfer OT monitoring, certificate renewal, model monitoring, audit support, stepwise handover
We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.
Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.
Manufacturing
Let us work out together how to connect machines, MES and ERP while securing your operational technology.
Book a first consultation