The Cyber Resilience Act (CRA) is an EU regulation (2024/2847) that for the first time imposes mandatory cybersecurity requirements on almost every product with digital elements sold in the European Union — from sensors, controllers and gateways to firmware and accompanying software. For IoT device manufacturers this is a fundamental shift: security stops being a marketing option and becomes a condition for placing a product on the market and keeping the CE marking.
In short: the Cyber Resilience Act requires IoT devices to be designed on a secure-by-design basis, shipped with no known exploitable vulnerabilities and supported with security updates throughout the support period. The duty to report actively exploited vulnerabilities starts on 11 September 2026, and the full set of requirements applies from 11 December 2027.

What is the Cyber Resilience Act?
The Cyber Resilience Act is the first horizontal EU law setting uniform cybersecurity requirements for products with digital elements. The regulation entered into force on 10 December 2024 and its obligations are being phased in until December 2027. The aim is to reduce the number of flaws in hardware and software products and to give users clear information about security support.
In practice the CRA covers a product across its whole lifecycle: from design and the manufacturing process, through technical documentation, all the way to vulnerability handling and post-sale updates. That sets it apart from a one-off CE and FCC certification, which confirms conformity at the moment the product is placed on the market.
Who does the CRA cover? The scope for IoT products
The scope is broad: the CRA applies to any product with digital elements whose intended or reasonably foreseeable use involves a direct or indirect connection to a network or another device. That captures the vast majority of IoT solutions — from simple sensors to industrial gateways and control systems.
The obligations fall mainly on manufacturers, but also extend to importers and distributors placing products on the EU market. Medical, aviation and automotive products covered by separate sectoral regulations remain outside the scope. Manufacturers based outside the Union are equally subject to the CRA if they make products available to European customers.
Key deadlines: what changes in 2026 and 2027?
The CRA timeline is staged, so it pays to plan the work well in advance. The most important dates are:
- 10 December 2024 — the regulation enters into force (start of the transition period).
- 11 September 2026 — the reporting obligations begin to apply: actively exploited vulnerabilities and severe security incidents.
- 11 December 2027 — full application of the CRA: essential cybersecurity requirements, vulnerability handling and the conformity assessment underpinning the CE marking.
The reporting duties also cover products already on the market before December 2027, which is why a mature incident response process has to be ready as early as 2026.
What are the secure-by-design requirements?
Secure by design means security is engineered in from the first architecture sketch rather than bolted on at the end. Among other things, the CRA requires a product to ship with no known exploitable vulnerabilities and with a secure default configuration. The essential requirements include:
- protection against unauthorised access and authentication based on device identity, for example using X.509 certificates;
- confidentiality and integrity of data — including firmware encryption and encrypted communication;
- a trusted boot chain, that is secure boot verifying the software signature;
- a mechanism for secure OTA firmware updates delivered throughout the support period;
- minimisation of the attack surface and of collected data, plus logging of security events.
The manufacturer must also produce and maintain a software bill of materials (SBOM), which makes it easier to track vulnerabilities in dependencies.
How does the vulnerability and incident reporting duty work?
From 11 September 2026 a manufacturer must report actively exploited vulnerabilities and severe incidents to the relevant CSIRT and to ENISA through a single reporting platform. The deadlines are strict:
- 24 hours — an early warning from the moment you become aware of the event;
- 72 hours — a full notification with an assessment and the first corrective measures;
- 14 days / 1 month — the final report (14 days after a remedy for the vulnerability is made available, up to a month for severe incidents).
Meeting those windows takes fleet telemetry, an update channel and a response procedure. It is worth building it on proven IoT security best practices.
Product classes and conformity assessment (CE)
The CRA groups products by risk, and that determines the conformity assessment route. Most IoT devices fall into the default category, where the manufacturer may self-assess. Important products (class I and II) and critical products face stricter requirements, including the use of harmonised standards or the involvement of a notified body.
Regardless of class, a positive conformity assessment is the precondition for affixing the CE marking and placing the product on the EU market. Non-compliance carries fines of up to EUR 15 million or 2.5% of global annual turnover — whichever is higher.
How do you prepare IoT devices for the CRA?
Preparing for the CRA is an engineering project, not merely a legal one. The recommended order of work:
- run a risk analysis and classify the product against the CRA scope;
- implement a root of trust and secure boot so firmware is authenticated at start-up;
- provide a secure OTA update channel with signing and rollback;
- build an SBOM and a process for monitoring vulnerabilities in dependencies;
- prepare an incident reporting procedure aligned with the 24/72 h deadlines;
- document everything in the technical documentation required for conformity assessment.
This is an area where experience across hardware, firmware and cloud translates directly into the time and cost of compliance.
Frequently asked questions (FAQ)
When does the Cyber Resilience Act start to apply?
The regulation entered into force on 10 December 2024. The duties to report actively exploited vulnerabilities and severe incidents apply from 11 September 2026, while the full set of essential requirements and conformity assessment applies from 11 December 2027.
Does the CRA apply to small IoT manufacturers?
Yes. The CRA covers almost every product with digital elements that connects to a network, regardless of company size. Microenterprises get some documentation simplifications, but the essential security requirements and reporting obligations remain in force.
What is the difference between the CRA and the CE marking?
The CE marking is a declaration that a product conforms to EU requirements. The CRA adds a cybersecurity dimension to it: to affix the CE marking to an IoT device after December 2027 you must meet the essential security requirements and pass the appropriate conformity assessment.
Summary and key takeaways
The Cyber Resilience Act moves IoT device cybersecurity out of the realm of good intentions and into mandatory EU market requirements. The core pillars are secure by design, no known vulnerabilities at the point of sale, updates throughout the support period, and fast incident reporting from September 2026. Companies that start now will comfortably make the deadline before full application of the CRA in December 2027.
FSS Technology designs and delivers IoT solutions that meet these requirements — from hardware and firmware to the cloud and fleet updates. Want to prepare your devices for the CRA? Explore our connected devices offering and let us talk about your compliance roadmap.