Skip to main content
← All posts·
Regulatory Compliance

What Is the CRA? Cyber Resilience Act Explained for IoT & Software Vendors

The EU Cyber Resilience Act (CRA) explained. Who it applies to, product categories, essential cybersecurity requirements, SBOM obligations, vulnerability handling, CE marking, and the September 2026 reporting deadline. Guide for IoT and software manufacturers.

Luca Berton10 min read

The CRA in 60 Seconds

The Cyber Resilience Act (CRA, Regulation 2024/2847) is an EU regulation that sets mandatory cybersecurity requirements for products with digital elements — hardware and software — sold in the EU market. It requires manufacturers to design, develop, and maintain products with cybersecurity in mind throughout their lifecycle.

Think of it as the CE marking requirement, but for cybersecurity. If your product connects to a network, the CRA probably applies to you.

Who Does the CRA Apply To?

Products with Digital Elements

Any product that includes software or connects to a device or network:

  • IoT devices: Smart home devices, industrial sensors, wearables, connected appliances
  • Software: Operating systems, browsers, VPNs, password managers, firewalls, SIEM
  • Hardware: Routers, switches, smart cards, industrial controllers
  • Embedded systems: Automotive components, medical device software, industrial automation

Excluded: Medical devices (regulated under MDR), aviation (EASA), motor vehicles (type approval), national security, military, and open-source software developed non-commercially.

Open-source exception: Non-commercial open-source is excluded, BUT a new "open-source steward" role was created for organisations that systematically support open-source used in commercial products (e.g., Red Hat for Ansible, Linux Foundation projects).

Product Categories

  • Default (self-assessment): ~90% of products. Manufacturer self-assesses compliance.
  • Important Class I: Higher-risk products like identity management systems, VPNs, network management, SIEM, routers, operating systems. Third-party assessment OR harmonised standards.
  • Important Class II: Highest-risk products like hypervisors, firewalls, tamper-resistant microprocessors, industrial automation. Mandatory third-party conformity assessment.
  • Critical: Defined by delegated acts. Hardware security modules, smart meter gateways, smartcard-related products.
📘 Book

Kubernetes Recipes

Practical guide for container orchestration and deployment — hands-on patterns you can use today.

View on Amazon →

Essential Requirements

  • Security by design: Products designed and developed with security from the start
  • No known exploitable vulnerabilities: Products must be delivered without known exploitable vulnerabilities
  • Secure default configuration: Secure out of the box — no default passwords
  • Vulnerability handling: Manufacturers must have a coordinated vulnerability disclosure process
  • Security updates: Free security updates for the expected product lifetime (minimum 5 years)
  • SBOM: Software Bill of Materials documenting all components (top-level dependencies minimum)
  • Incident reporting: Actively exploited vulnerabilities reported to ENISA within 24 hours

Key Deadlines

  • 11 September 2026: Vulnerability and incident reporting obligations apply (manufacturers must report actively exploited vulnerabilities to ENISA)
  • 11 December 2027: Full CRA requirements apply — all products with digital elements must comply
  • Ongoing: Security updates must be provided for the product's expected lifetime
🎓 Course with Starweaver

Back-End Infrastructure: Servers, Secure APIs and Data

Build secure back-end infrastructure from the ground up. In collaboration with Starweaver.

Start on Coursera →

CRA and AI

AI-enabled products with digital elements are explicitly covered. The CRA works alongside the EU AI Act:

  • High-risk AI systems that are also products with digital elements must comply with both the AI Act and the CRA
  • A single conformity assessment can cover both regulations where requirements overlap
  • SBOM requirements are particularly relevant for AI: documenting ML frameworks, model dependencies, and training pipeline components
CRA
Cyber Resilience Act
IoT
software security
SBOM
CE marking
regulation
explained

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →