Fast Facts
Device lifecycle management is the unglamorous back half of every IIoT deployment, and it’s badly underfunded. Nearly 3 in 5 OEMs expect their current device management infrastructure to fail within three years — for more than 1 in 10, that failure point is under a year away. Launch dates get budget and board attention. Managing devices after they ship rarely does, and the EU’s Cyber Resilience Act is about to turn that gap into a compliance bill, not just an engineering one.
Device lifecycle management loses the internal budget fight almost every time, and the numbers explain why the loss is getting expensive. Nearly 3 in 5 OEMs expect their existing device management infrastructure to fall short within three years, and for more than 1 in 10, that failure point is less than a year away, according to Northern.tech’s 2026 State of Industrial IoT report, based on more than 500 qualified respondents.
Why Device Lifecycle Management Loses the Internal Budget Fight
90%
of OEMs manage IoT products with multiple devices rather than a single unit, and 85% expect that device count to keep growing over the next 12 months — meaning the complexity these organizations must manage is expanding faster than the infrastructure built to handle it.
Source: Northern.tech, “2026 State of Industrial IoT Device Lifecycle Management”
A product launch date earns a champion inside almost every organization — marketing wants it, sales wants it, the board tracks it. The question of how a fleet of connected devices gets patched, monitored, and eventually decommissioned five years after that launch rarely has an equivalent internal advocate, even though the infrastructure decisions made at launch determine whether that later work is manageable or a crisis. See our earlier coverage of why legacy equipment integration’s real cost isn’t the machines, where the same documentation-and-planning gap shows up on the industrial buyer’s side of this same relationship.
“OEMs are scaling faster than their infrastructure.”— Eystein Stenberg, CTO, Northern.tech
The Regulatory Deadline Turning This Into a Compliance Problem
What was previously an engineering-quality question is becoming a legal one. The EU’s Cyber Resilience Act carries reporting obligations landing later this year, and device lifecycle management is precisely the operational capability that determines whether an OEM can actually meet them — not just build a product that passes an initial security review. Northern.tech’s report found more than half of OEMs acknowledge their infrastructure won’t sustain the pace of anticipated growth, a gap that’s shifting from a future risk to a present compliance liability as the CRA deadline approaches.
“How do you manage (and fund) the ongoing operational and maintenance processes after the initial sale?”— Thomas Ryd, CEO, Northern.tech, writing in Forbes, August 6, 2026
Ryd’s framing cuts to the real financial-planning failure: most connected-product companies can answer confidently what they’re launching next, and far less confidently how they’ll fund managing it five years from now. That asymmetry between launch-day enthusiasm and post-sale funding discipline is exactly the human-behavior pattern behind the infrastructure gap Northern.tech’s data measures. See our coverage of unified namespace architecture for manufacturers for how the same underfunded, unglamorous infrastructure layer determines whether a factory’s later AI investments actually work.
⚠ Fiction — composite scenario, not a real event: A sensor manufacturer ships 50,000 industrial units with a device management platform sized for their first product generation. Three years later, the fleet has grown to 400,000 units across four product lines, and the original platform can’t handle the patch-deployment volume. A critical firmware vulnerability sits unpatched across tens of thousands of devices for months, not because engineers didn’t build a fix, but because the infrastructure to distribute it at scale was never funded past the original launch budget.
Global Implications
These infrastructure gaps compound differently depending on where a fleet operates. For manufacturers in Nigeria, West Africa, and Southeast Asia deploying IIoT devices in environments with less reliable connectivity and fewer dedicated IT resources than the OEMs surveyed in Northern.tech’s largely Western respondent base, an infrastructure failure inside three years isn’t a compliance abstraction — it’s a fleet of unpatchable, unmonitored devices sitting inside a customer’s operation with no clean remediation path. See our analysis of the audit-driven IIoT adoption crisis for how that same gap between deployment ambition and operational funding plays out once external auditors start asking questions.
The typical IoT product is no longer a single endpoint managed in isolation — it’s a system of two to ten or more heterogeneous devices that has to be managed as a coherent whole across its entire lifecycle, from design through decommissioning. That complexity multiplies the cost of getting fleet management wrong at exactly the moment regulatory deadlines are raising the cost of failure.
💡 CreedTec Analyst’s Note — Daniel Ikechukwu
Strategic Impact: Device lifecycle management is shifting from an engineering nice-to-have to a board-level compliance and liability question, and most OEM budgets haven’t caught up to that shift yet.
Stop: Funding device management infrastructure as a one-time launch cost rather than an ongoing operational line item scaled to fleet growth.
Start: Auditing current device management infrastructure against a five-year fleet-growth projection, not current device counts, before the next product launch.
Watch: Whether EU CRA enforcement actions later this year make these infrastructure gaps a visible, public compliance failure rather than an internal engineering concern.
ROI Outlook: Building scalable device lifecycle management infrastructure ahead of fleet growth costs more upfront than patching capacity in reactively, but it’s dramatically cheaper than an unpatched security incident across tens of thousands of deployed devices.
Every connected-product roadmap has a launch date circled in the calendar. Device lifecycle management is the bill that comes due years after that date passes — and right now, most OEMs are planning to pay it with infrastructure that was never sized for the fleet they’re about to have.
Subscribe to CreedTec’s newsletter — it tracks which IIoT vendors are actually funding the unglamorous back half of the device lifecycle, and which ones are still just counting launch dates.
Sources
- PR Newswire — original Northern.tech report release
- Mender (Northern.tech) — full report findings breakdown
- Forbes — Thomas Ryd commentary on funding gaps
- Embedded Computing Design — device complexity analysis
- IoT For All — report summary and EU CRA context
Further reading: Legacy Equipment Integration’s Real Cost Isn’t the Machines · Unified Namespace Explained for Manufacturers · The Audit-Driven IIoT Adoption Crisis · The Industrial IoT Trends That Decide Your 2030 ROI · What Samsara’s Insider Selling Really Signals for IIoT


