Device management

Once a connected product is installed at the customer's site, the long operating phase begins. Device management makes it possible to keep track of devices, hardware versions, software, security updates and access throughout the product's lifetime. At Move we develop solutions that can be integrated into existing systems or work as a standalone cloud-based service platform.

Device management

Keeping track of products throughout their lifetime

An IoT product is rarely finished on the day it leaves production. Software has to be updated, bugs have to be fixed, security vulnerabilities have to be handled, and over time there are often several hardware and software versions in the market.

The whole fleet

Status, versions and faults in one place

Secure OTA updates

Signed, targeted and gradual

With the CRA in mind

Vulnerabilities and updates through the support period

Roles and access

Customer, distributor, region and head office

An overview of the installed fleet

That is why device management is an important part of the architecture of a connected product.

A device management system makes it possible to keep track of the installed fleet centrally. It can show, for example, where the devices are, what hardware they contain, which software version they are running, when they were last online and whether they have reported faults.

The right software for the right hardware

Once a product has been on the market for a few years, there are often several hardware versions at the same time.

A hardware revision may, for example, have a different processor, display type, sensor or communication module. That means you cannot necessarily send the same firmware to every device.

The device management platform has to know each device's configuration and make sure it is only offered software that is compatible with that particular hardware.

This can be based on product variant, serial number, hardware revision, bootloader version or installed components, among other things.

That way, older products can continue to be maintained without the risk of installing the wrong software.

Controlled software updates

Remote software and firmware updates are a big advantage when products are installed at customers' sites or distributed across many countries.

But the ability to update a product is also a security-critical function.

There has to be control over who can release an update, which devices are to receive it and when it is installed. Firmware can be digitally signed, and the product can verify that an update comes from an approved source before it is installed.

Staged rollouts are another option. A new version is first sent to internal test devices or a smaller group of products. If it runs reliably, the rollout can gradually be extended to the rest of the fleet.

Depending on the product, there may also be a need for rollback, so the device can return to an earlier version if a software update fails.

Device management and the EU's cybersecurity requirements

The ability to maintain software throughout the product's lifetime is becoming ever more important in relation to the EU's cybersecurity rules.

The Cyber Resilience Act, the CRA, sets requirements for manufacturers of many products with digital elements, including the handling of vulnerabilities and security updates throughout a defined support period. The CRA's reporting obligations for actively exploited vulnerabilities and severe security incidents already apply from 11 September 2026, while most of the requirements apply in full from 11 December 2027.

A good device management system can therefore become an important part of a company's practical set-up for handling products after launch. It can, for example, give an overview of which devices and software versions are affected by a vulnerability and make it possible to distribute a fix targeted at the relevant products.

Device management is not enough on its own to ensure CRA compliance, but it can be a central technical part of a company's vulnerability and update management. The CRA specifically requires the manufacturer to set a support period and handle relevant vulnerabilities in the product throughout that period.

Different users need different access

A service management system is often used by several organisations and different types of user.

That is why the platform can be built with roles and access levels.

An end customer may only need to see their own products. A distributor should be able to see all installations within their area, but not products sold by other distributors. A local service centre may have access to diagnostics and software updates, while the manufacturer's head office has access to the entire fleet.

That makes a structure like this possible:

Customer → distributor → region → head office

At the same time, different roles can have different rights. Some may only view data, while others can change the configuration, start diagnostics or approve a software update.

For security-critical functions, changes can also be logged, so it can be documented afterwards who did what and when.

From service tool to product insight

When all products report to the same system, device management also becomes a valuable source of data.

The head office can, for example, see how products are actually used in the field, which software versions are installed, how often particular faults occur or how different generations of the product perform.

That can make it possible to spot general problems before they turn into large numbers of support or RMA cases.

Products or installations can also be benchmarked against each other. If one installation has markedly more faults, a higher temperature or a different usage pattern from the rest of the fleet, the system can make it visible.

That way, device management is not just a service tool. It also becomes a source of feedback for development, quality and product management.

Integration or a standalone platform

Device management does not have to be a new, separate system.

If the company already uses a service, ERP, CRM or cloud tool, the functions can be integrated through APIs, so employees carry on working in their existing system.

In other projects it makes more sense to develop a standalone cloud-based service management platform that brings together devices, customers, distributors, software versions, alarms and service history.

At Move we therefore see device management as part of the product's whole lifecycle. We can work on the product's embedded software, a secure update mechanism, the cloud backend, user roles, dashboards and integration with the company's other systems.

Frequently asked questions

What is device management?

Device management is the central administration of connected products throughout their lifetime. It can include device status, software versions, configuration, diagnostics, user access and remote updates, among other things.

Can firmware be updated remotely?

Yes. Products can be designed with OTA updating, so firmware or software can be updated without physical access to the device.

How do you make sure a device gets the right firmware?

The system can know the device's hardware revision, product variant and existing software and only allow compatible software versions to be installed.

Can you control who is allowed to update products?

Yes. Role-based access can ensure that only approved users can release or install software, while other users only have read access, for example.

Can customers and distributors have different access?

Yes. The platform can be built as a multi-tenant system, where customers see their own devices, distributors see their area and the head office can see the entire installed fleet.

Can device management help with the Cyber Resilience Act?

Yes. A device management system can support the work on software updates, product versions and vulnerability handling. It is, however, only one part of the overall work on CRA compliance.

Can the system be used for statistics and product improvement?

Yes. Data across the fleet can be used to detect general faults, analyse usage patterns, compare products and give the development department valuable feedback from products in operation.

Can device management be integrated into our existing system?

Yes. The functionality can often be integrated through APIs with existing service, ERP, CRM or cloud systems. Alternatively, a standalone service management platform can be developed.

Ready when you are

Shall we turn your idea into reality?

Technical development takes more than good ideas — it takes the right skills. We have gathered hardware, software and engineering expertise under one roof, so you get from prototype to production quickly and safely.

Reach out to us →