The short version
- The Cyber Vision 5.6.0 release notes of 8 September 2026 rename Secure Equipment Access (SEA) to Cyber Vision Secure Remote Access (SRA) and add Azure Blob Storage for session recordings plus multi-VRF support for the agent.
- According to the data sheet, the gateway runs as an IOx application on Cisco network equipment — IE3300, IE3400, IE3500, IE9300, Catalyst 9300, IR1100 and IR1800 — and builds an outbound connection to the cloud portal.
- Session monitoring, joining, termination and recording are available in the Advantage tier only — and SEA Advantage is included at no extra cost for the same number of endpoints with Cyber Vision Advantage ordered or renewed on or after 20 August 2025.
- The tool provides time limits, approval and recording. Supplier agreements, approval ownership, account expiry, retention and an emergency path remain the operator’s job.
Remote maintenance by machine suppliers is routine in OT networks. In older plants we typically meet three patterns: a permanently open VPN tunnel to the supplier, a vendor router in the control cabinet and unmanaged remote control software on an operator PC. None of them reliably answers who accessed which machine, and when.
That is where NIS2 and IEC 62443 come in — and where Cisco has just renamed its tool: Secure Equipment Access is now Cyber Vision Secure Remote Access.
SEA becomes Cyber Vision Secure Remote Access
The Cyber Vision 5.6.0 release notes of 8 September 2026 are unambiguous: “Renames Secure Equipment Access (SEA) to Cyber Vision Secure Remote Access (SRA)”. According to the product page, Secure Equipment Access is now part of Cisco Cyber Vision. Cisco’s blog on its Cisco Live Americas 2026 launch already described remote access embedded in industrial switches and routers — no separate appliance, no parallel VPN.
| Change per the release notes | What it means for operations |
|---|---|
| SEA renamed to Cyber Vision Secure Remote Access, including user-interface changes | Documentation and tenders need both names for now |
| Azure Blob Storage for session recordings | A second storage option for the audit trail besides AWS S3 |
| Single sign-on cross-launch from Cyber Vision Center without an email address | Less friction for OT teams working in the Center |
| Multi-VRF support in the remote-access agent for CLI-based and Catalyst SD-WAN workflows | The agent also fits networks that separate traffic into VRFs |
Architecture: gateway in the switch, broker in the cloud
The data sheet describes two parts. The cloud portal acts as a ZTNA trust broker, enforcing policy by identity and context. The gateway is the SEA agent, an IOx application on a dedicated CPU core of the network device, according to Cisco without impact on routing or switching performance. It builds an outbound connection to the broker; no dedicated hardware is needed.
Access starts from “default deny”: remote users log in to the portal and see only approved devices, over specified protocols, on permitted days and times. The cloud side is the IoT Operations Dashboard. The 5.5.x release notes add a variant without IOx: the agent runs on Cyber Vision Center, making the Center and its network resources reachable through the IoT Operations Dashboard without direct inbound access.
| Platform | Minimum software release |
|---|---|
| Catalyst IE3300 Rugged | 17.12.01 |
| Catalyst IE3400 Rugged, IE3400 Heavy Duty | 17.12.01 |
| IE3500 Rugged, IE3500 Heavy Duty | 17.17.1 |
| Catalyst IE9300 Rugged | 17.16.01 |
| Catalyst 9300 | 17.14.01 |
| Catalyst IR1100 Rugged | 17.04.01 |
| Catalyst IR1800 Rugged | 17.11.01 |
Access modes and controls
Per the data sheet, clientless access needs only a web browser and covers RDP, VNC, HTTP(S), SSH and Telnet. The agent-based variant SEA Plus establishes a secure IP channel between the user’s computer and the OT asset, so any desktop application can be used — Cisco names file transfer and PLC programming with native tools.
The data sheet adds the controls that make access auditable:
- Just-in-time access: day and time schedules per asset and per user; connecting at arbitrary times is ruled out.
- Request and approval: technicians from suppliers and contractors can be required to request access to an asset.
- Monitor and join: a list of active sessions and the option to watch a session in real time, for control or training.
- Terminate: administrators can end an active session.
- Record: inline recording for the audit trail. The data sheet requires an AWS S3 account; since April 2026 the IoT Operations Dashboard also supports AWS Assume Role with temporary credentials for S3, and 5.6.0 adds Azure Blob Storage.
- Identity: single sign-on via your identity provider with SAML 2.0, plus multi-factor authentication against stolen credentials.
Licensing: you may already have paid for it
Per the data sheet, the subscription is based on the number of OT assets or endpoints that can be accessed, with terms of one, three, five or seven years. Of the two tiers, only Advantage contains the functions an auditor asks about:
| Function | Essentials | Advantage |
|---|---|---|
| Clientless and agent-based access (SEA Plus) | yes | yes |
| Access control groups, SSO, MFA, role-based access | yes | yes |
| Active session monitoring, joining, termination | — | yes |
| Inline session recording | — | yes |
| Host posture check via Cisco Duo for SEA Plus | — | yes |
The data sheet names two routes by which the Advantage licence comes at no extra cost:
- Cyber Vision Advantage ordered or renewed on or after 20 August 2025: SEA Advantage is included for the same number of endpoints.
- IE3500 and Catalyst IE9300 Rugged ordered with Network Advantage on or after 23 August 2025, and IE3500 Heavy Duty ordered with Network Advantage on or after 1 October 2025: a three-year limited-term Advantage licence for Cyber Vision and Secure Equipment Access covering 24 endpoints.
How Cisco maps the service — and what stays with the operator
Cisco’s IEC 62443-3-3 white paper (updated 16 August 2024) places the service under two foundational requirements. Under FR1, at SR 1.13 on access via untrusted networks, as a purpose-built remote access application on Cisco industrial network equipment that provides secure remote connectivity to individual IACS devices. Under FR2, use control: access only to a specified endpoint for a specified time (SR 2.5), and sessions limited to a time window that can be killed at any time (SR 2.6).
Cisco’s NIS2 post of 19 June 2025 lists the service under minimising risk from OT suppliers and service providers: identify unmanaged remote access gateways with Cyber Vision and plan their replacement with zero-trust remote access such as SEA. In German law these duties sit in § 30 BSIG, whose paragraph 2 names, among others, supply chain security including relationships with direct suppliers or service providers (no. 4), security measures in the acquisition, development and maintenance of IT systems (no. 5), access control concepts (no. 9) and multi-factor authentication solutions (no. 10).
A tool produces evidence, not rules. In our view, five things need settling before the first supplier moves over:
- Named approvers: who approves requests for which machine, how fast, and who deputises? An approval nobody processes leads back to the permanent tunnel.
- Supplier agreement: personal accounts instead of shared logins, notice of staff changes, no vendor-owned remote routers, the approved path only.
- Account expiry: according to the IoT Operations Dashboard change log of 20 January 2026, access to SEA does not expire for any user role by default; 180, 90 or 60 days can also be set. We set an expiry for external accounts.
- Retention: how long recordings and logs are kept, who may review them and how data protection and employee representatives are involved is the operator’s decision.
- Emergency access: a documented, restricted and regularly tested path for when the cloud portal or the uplink fails.
Why remote maintenance deserves a zone of its own is covered in IEC 62443 and the CRA; what segmentation has to prove under § 30 BSIG is in NIS2 network segmentation. Assessment and segmentation as groundwork are on the OT security service page.
Open points and rollout order
The public documentation leaves some questions open; settle them before the product decision:
- Hosting: in which region is the cloud portal operated, where do session and user data reside, and which data processing agreement applies?
- Recording per access mode: which sessions can actually be recorded — SEA Plus sessions too?
- Supplier identities: federation via your identity provider or local accounts — and how is MFA enforced for externals?
- Supplier devices: what does a maintenance laptop need for SEA Plus, and who checks its state?
- Legacy access: which routers, tunnels and tools run in parallel, and until when?
For the rollout we recommend this order:
Survey existing access
Record tunnels, vendor routers and remote maintenance software per machine. Cisco recommends finding unmanaged remote access gateways with Cyber Vision; the Cyber Vision API shows how to use that data.
Settle licences and software releases
Match Advantage licences and the minimum releases of the target devices; schedule upgrades into maintenance windows.
Define maintenance cases
Per supplier: target devices, protocols, time windows, approvers and emergency path.
Pilot with one supplier
One cell, clientless access, recording on. The test is a real maintenance job, not just a successful connection.
Migrate and close legacy paths
Move further suppliers after acceptance, retire old tunnels and routers deliberately, review accounts and approvals regularly.
Product selection follows the process, not the other way round. How we structure maintenance cases, approvals and technical paths with operations and suppliers is described on the secure OT remote access service page. For a first review of your installed base, licence position and open points, you can discuss OT remote maintenance with us.
Sources
Every evidenced claim in this article can be traced here. The retrieval date shows how fresh the check is.
- Release Notes for Cisco Cyber Vision, Release 5.6.xopens in a new tab
Cisco · 2026-09-08 · retrieved 25 September 2026
- Cisco Secure Equipment Access Data Sheetopens in a new tab
Cisco · 2026-04-14 · retrieved 25 September 2026
- Cisco Secure Equipment Accessopens in a new tab
Cisco · retrieved 25 September 2026
- Release Notes for Cisco Cyber Vision Center, Release 5.5.xopens in a new tab
Cisco · 2026-06-09 · retrieved 25 September 2026
- 2026 - Cisco IoT Operations Dashboardopens in a new tab
Cisco DevNet · retrieved 25 September 2026
- ISA/IEC-62443-3-3: What is it and how to comply?opens in a new tab
Cisco · 2024-08-16 · retrieved 25 September 2026
- NIS2 Compliance: It’s never too late to get startedopens in a new tab
Cisco Blogs · 2025-06-19 · retrieved 25 September 2026
- Layered Defense for the Plant Floor: Simplifying OT Securityopens in a new tab
Cisco Blogs · 2026-06-03 · retrieved 25 September 2026
- § 30 BSIG — Risikomanagementmaßnahmen besonders wichtiger Einrichtungen und wichtiger Einrichtungenopens in a new tab
Bundesministerium der Justiz (gesetze-im-internet.de) · retrieved 25 September 2026

