Skip to main content
← All posts·
Regulatory Compliance

Cyber Resilience Act for IoT Manufacturers: AI-Enabled Device Compliance Guide

CRA compliance guide for manufacturers of AI-enabled IoT devices. Covers essential cybersecurity requirements, vulnerability handling, SBOM obligations, conformity assessment for connected AI products, and the September 2026 vulnerability reporting deadline.

Luca Berton10 min read

The CRA Changes Everything for AI-Enabled IoT

The Cyber Resilience Act (Regulation 2024/2847) introduces mandatory cybersecurity requirements for all products with digital elements sold in the EU. For manufacturers of AI-enabled IoT devices — from smart home products to industrial sensors to medical wearables — this means fundamental changes to product development, supply chain management, and post-market obligations.

Key dates: Vulnerability reporting obligations begin September 2026. Full compliance required by December 2027.

Which AI-Enabled Devices Are Affected?

Default Category (Self-Assessment)

  • Smart home devices with AI (smart speakers, AI cameras, robot vacuums)
  • Consumer wearables with AI health features
  • AI-powered toys and educational devices
  • Smart appliances with ML-based energy optimisation

Important Category (Annex III — Third-Party Assessment)

  • Industrial IoT gateways and controllers with AI
  • Network equipment with AI-powered security features
  • AI-enabled building automation systems
  • Smart meters with AI analytics

Critical Category (Annex IV — EU Certification)

  • Hardware security modules with AI
  • Smart cards and secure elements in AI devices
  • Operating systems with AI components for critical infrastructure

Essential Cybersecurity Requirements for AI Devices

Annex I Requirements Applied to AI

  • Security by design — AI models must be protected against tampering, model extraction, and adversarial attacks from the design phase
  • Secure by default — AI features should ship with safe default configurations, not wide-open model access
  • Data protection — AI training data and inference data must be protected at rest and in transit
  • Minimal attack surface — Only necessary AI model endpoints should be exposed
  • Integrity protection — Ensure AI model files haven't been tampered with (signed model weights)
  • Update mechanism — Secure over-the-air updates for AI models on deployed devices
  • Logging — Device must log AI-related security events for post-incident analysis
📘 Book

Kubernetes Recipes

Practical guide for container orchestration and deployment — hands-on patterns you can use today.

View on Amazon →

SBOM Requirements for AI-Enabled Devices

The CRA requires a Software Bill of Materials (SBOM) for all products with digital elements. For AI-enabled devices, this includes:

  • ML framework versions — TensorFlow, PyTorch, ONNX Runtime version and dependencies
  • Model metadata — Model architecture, training framework version, quantisation parameters
  • Pre-trained model provenance — If using transfer learning, document the source model and its licence
  • Data processing libraries — NumPy, pandas, scikit-learn and their dependency chains
  • AI-specific vulnerabilities — Known vulnerabilities in ML libraries and their remediation status

Vulnerability Handling for AI Components

September 2026 deadline: Manufacturers must report actively exploited vulnerabilities within 24 hours to ENISA.

For AI-enabled devices, vulnerabilities include:

  • ML library CVEs (TensorFlow, PyTorch security advisories)
  • Model extraction vulnerabilities
  • Adversarial input vulnerabilities
  • Data poisoning vectors in devices that learn from user interaction

Manufacturers must provide security updates for at least 5 years (or the expected product lifetime).

🎓 Course

Federated Learning and Privacy-preserving RAGs

Implement secure AI models using federated learning techniques.

Start on Pluralsight →

CE Marking for AI-Enabled IoT

AI-enabled products will need updated CE marking that covers CRA compliance. If the AI component also falls under the EU AI Act (e.g., safety component), the conformity assessment covers both regulations through a single process where possible.

CRA
IoT
AI devices
cybersecurity
compliance
SBOM
vulnerability management
CE marking

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →