The EU Cyber Resilience Act: What IoT Vendors Need to Know
- Last Updated: September 8, 2026
Transforma Insights
- Last Updated: September 8, 2026



The EU Cyber Resilience Act (CRA) represents a significant change in how cybersecurity is treated for products with digital elements. Beyond security needing to be demonstrated before a product reaches market, it becomes a responsibility that extends throughout the product lifecycle. The regulations apply to device manufacturers, but it would be easy for an IoT service provider to accidentally become a manufacturer for the purposes of the CRA. We explore the implications of the CRA in Transforma Insights' recently published report ‘The end of “Secure Enough”: what the EU Cyber Resilience Act changes for IoT’.
Formally adopted on 23 October 2024, the CRA introduces mandatory cybersecurity requirements for a broad range of connected hardware and software products sold in the EU. The regulation becomes fully applicable on 11 December 2027, but manufacturers' vulnerability-reporting obligations begin earlier, on 11 September 2026.
Manufacturers must address security during design and development and continue to manage vulnerabilities, updates and security throughout the product's expected lifetime. Security therefore becomes a product characteristic, rather than simply a pre-launch compliance exercise.
It applies broadly to products with digital elements, including consumer devices, industrial equipment, embedded software, operating systems and standalone software.
Third-party security specialists can audit products and provide assurance, while notified bodies undertake independent conformity assessment where required. However, the manufacturer remains responsible for declaring (and ultimately defending) compliance.
The CRA takes a risk-based approach. Lower-risk products can often be self-assessed, while Important and Critical products may require independent assessment by a notified body.
The CRA requires products to support security updates and, where appropriate, automatic updates. For IoT manufacturers, we recommend assuming that devices should be automatically updated unless there is a defensible technical or operational reason not to.
Manufacturers must identify and document vulnerabilities, maintain an SBOM, conduct security testing, operate coordinated vulnerability disclosure and provide timely security updates. For actively exploited vulnerabilities, reporting starts with an early warning within 24 hours, followed by notification within 72 hours.
An importer, distributor or service provider can fall within the manufacturer's obligations if it markets a device under its own brand or substantially modifies its functionality. This could have significant implications for IoT solution providers building services around generic hardware.
The rules apply to products placed on the EU market regardless of where the manufacturer is based. UK and US manufacturers selling into Europe therefore need to address the CRA just as EU manufacturers do.
A certified modem, secure element or operating system can help, but it does not make the complete IoT device CRA-compliant. The manufacturer remains responsible for assessing the integrated product.
The CRA requires manufacturers to embed secure development, vulnerability management and lifecycle support into their processes. The challenge may therefore be less about implementing individual security technologies and more about generating and maintaining evidence that appropriate practices have been consistently followed.
With vulnerability-reporting obligations beginning on 11 September 2026 and full application on 11 December 2027, manufacturers should not wait until 2027 to prepare.
The CRA is not simply another compliance exercise. It requires manufacturers to rethink how security is designed, documented, maintained and demonstrated throughout the life of a connected product.
The Most Comprehensive IoT Newsletter for Enterprises
Showcasing the highest-quality content, resources, news, and insights from the world of the Internet of Things. Subscribe to remain informed and up-to-date.
New Podcast Episode

Related Articles