burgerlogo

The EU Cyber Resilience Act: What IoT Vendors Need to Know

The EU Cyber Resilience Act: What IoT Vendors Need to Know

avatar
Transforma Insights

- Last Updated: September 8, 2026

avatar

Transforma Insights

- Last Updated: September 8, 2026

featured imagefeatured imagefeatured image

The EU Cyber Resilience Act (CRA) represents a significant change in how cybersecurity is treated for products with digital elements. Beyond security needing to be demonstrated before a product reaches market, it becomes a responsibility that extends throughout the product lifecycle. The regulations apply to device manufacturers, but it would be easy for an IoT service provider to accidentally become a manufacturer for the purposes of the CRA. We explore the implications of the CRA in Transforma Insights' recently published report ‘The end of “Secure Enough”: what the EU Cyber Resilience Act changes for IoT’.

Formally adopted on 23 October 2024, the CRA introduces mandatory cybersecurity requirements for a broad range of connected hardware and software products sold in the EU. The regulation becomes fully applicable on 11 December 2027, but manufacturers' vulnerability-reporting obligations begin earlier, on 11 September 2026.

Ten things that vendors of IoT solutions need to know

1. Cybersecurity becomes a lifecycle responsibility.

Manufacturers must address security during design and development and continue to manage vulnerabilities, updates and security throughout the product's expected lifetime. Security therefore becomes a product characteristic, rather than simply a pre-launch compliance exercise.

2. The CRA covers much more than consumer IoT.

It applies broadly to products with digital elements, including consumer devices, industrial equipment, embedded software, operating systems and standalone software.

3. Manufacturers remain ultimately responsible.

Third-party security specialists can audit products and provide assurance, while notified bodies undertake independent conformity assessment where required. However, the manufacturer remains responsible for declaring (and ultimately defending) compliance.

4. Higher-risk products face greater scrutiny.

The CRA takes a risk-based approach. Lower-risk products can often be self-assessed, while Important and Critical products may require independent assessment by a notified body.

5. Automatic security updates are likely to become the norm.

The CRA requires products to support security updates and, where appropriate, automatic updates. For IoT manufacturers, we recommend assuming that devices should be automatically updated unless there is a defensible technical or operational reason not to.

6. Vulnerability management becomes a core engineering process.

Manufacturers must identify and document vulnerabilities, maintain an SBOM, conduct security testing, operate coordinated vulnerability disclosure and provide timely security updates. For actively exploited vulnerabilities, reporting starts with an early warning within 24 hours, followed by notification within 72 hours.

7. IoT service providers can become manufacturers.

An importer, distributor or service provider can fall within the manufacturer's obligations if it markets a device under its own brand or substantially modifies its functionality. This could have significant implications for IoT solution providers building services around generic hardware.

8. Being outside the EU does not avoid the CRA.

The rules apply to products placed on the EU market regardless of where the manufacturer is based. UK and US manufacturers selling into Europe therefore need to address the CRA just as EU manufacturers do.

9. Secure components do not make the whole product compliant.

A certified modem, secure element or operating system can help, but it does not make the complete IoT device CRA-compliant. The manufacturer remains responsible for assessing the integrated product.

10. The biggest challenge may be proving compliance.

The CRA requires manufacturers to embed secure development, vulnerability management and lifecycle support into their processes. The challenge may therefore be less about implementing individual security technologies and more about generating and maintaining evidence that appropriate practices have been consistently followed.

The clock is ticking

With vulnerability-reporting obligations beginning on 11 September 2026 and full application on 11 December 2027, manufacturers should not wait until 2027 to prepare.

The CRA is not simply another compliance exercise. It requires manufacturers to rethink how security is designed, documented, maintained and demonstrated throughout the life of a connected product.

Need Help Identifying the Right IoT Solution?

Our team of experts will help you find the perfect solution for your needs!

Get Help