Cyber Resilience Act
In EU regulation, the Cyber Resilience Act (CRA) sets security requirements for products with digital elements sold in the European market, covering their whole lifecycle. It reaches every manufacturer of connected products, which is exactly the client of an IoT assessment, and it links the world of devices to the world of compliance.
How it works
The Cyber Resilience Act places obligations on the manufacturer of a product with digital elements: hardware and software placed on the EU market that connect or process data. In broad terms it requires products to be designed and built to be secure, to ship without known exploitable vulnerabilities, to receive security updates for a defined support period, and to have a process for handling and reporting vulnerabilities once the product is in the field. It also expects transparency about the components a product contains, which connects directly to the idea of a software bill of materials. Conformity is demonstrated before a product is placed on the market, and the duties continue through the support period rather than ending at sale.
What goes wrong
The gap the regulation targets is the connected product shipped and forgotten: firmware with hard-coded credentials, no update mechanism, and no process to handle a vulnerability report when a researcher finds one. From the attacker’s side, this is the reliable target, because a device that cannot be updated stays vulnerable for its whole life, and a manufacturer with no vulnerability-handling process means a flaw stays open indefinitely. The regulation also exposes supply-chain risk: a product inherits the weaknesses of its components, so a software supply chain attack on a dependency becomes the manufacturer’s problem to detect and disclose.
Where this shows up in an audit
For a product manufacturer, an assessment against the CRA’s expectations tests the security properties the regulation demands: whether the product ships free of known exploitable flaws, whether it enforces integrity at boot through secure boot, whether updates are authenticated and possible, and whether the components are inventoried. For industrial products the relevant control framework is often IEC 62443, and the reporting duties align with NIS2. The finding is tied to both the technical weakness and the obligation it touches. This is part of how we test a product against its security obligations.