Loading...
EU Cyber Resilience Act

Navigate EU CRA Compliance with Confidence

Explore expert guidance, actionable resources, and purpose-built tools to help your organization meet the requirements of the EU Cyber Resilience Act—and build a more secure product ecosystem.

EU CRA Compliance Timeline

1

Dec 11, 2027

The EU CRA becomes fully applicable

2

Sep 11, 2026

Reporting obligations for manufacturers begin

3

Dec 10, 2024

The EU CRA comes into force

4

Nov 20, 2024

The CRA is officially published in the Official Journal of the European Union

Ready to Get Started?

See how Finite State can help secure your products.

Request a DemoRequest a DemoTake a Product TourTake a Product Tour
Finite StateFinite State

Finite State is the Product Security Automation Platform that functions as an autonomous Product Security OS: design → verify → prove, grounded in what you ship.

Platform

Platform Overview
Ground Truth Inventory
Exploitability-Based Prioritization
Design-Time Architecture Security
Automated Evidence-Backed Compliance

Solutions

Device Manufacturers
Automotive
Medical Devices
Energy & Utilities
Government
Industrial

Resources

Blog
Resource Library
Webinars & Videos
Events
Documentation

Company

About Us
CareersHIRING
Press & News
Contact Sales
Media Inquiries
X

© 2026 Finite State. All rights reserved.

Privacy PolicyTerms of UseCustomer Terms and Conditions

EU CRA Core Requirements

Secure by Design Principles

Under the CRA, manufacturers must integrate security practices throughout the product lifecycle, including

  • Secure boot
  • Access controls
  • Encryption
  • Default security settings
  • Lifecycle security management

Vulnerability Handling

IoT manufacturers must proactively manage vulnerabilities and respond swiftly to security incidents with

  • Continuous monitoring
  • Formal reporting processes
  • 24hr disclosure periods
  • Secure patch distribution
  • End-of-life policy for legacy devices

SBOM & Technical Documentation

The CRA improves software supply chain transparency by imposing specific security requirements on manufacturers, such as

  • including proprietary & open-source components in SBOMs & updating them with each modifcation
  • Including hardware & software configurations, security features, update protocols, & maintenance guidelines in technical documentation

Product Lifecycle Support

The EU CRA demands product lifecycle support to keep devices secure through their operational lifespan, including

  • Defined End-of-Life policies
  • Long-term maintenance commitments
  • Provision for timely security updates
  • Incident response planning

Software Supply Chain Security

Reliance on third-party software increases attack surfaces, which is why the CRA requires

  • Comprehensive assessments of third-party suppliers
  • Continuous vulnerability scanning
  • Robust logging & auditing practices
  • Open source risk management practices

Conformity Assessments

The CRA introduces mandatory conformity assessments aligned to product risk categories

  • Self-assessments: Default & Important Class I (with exceptions)
  • 3rd-party assessments: Important Class II
  • European Common Criteria certification: Critical
Finite StateFinite State
Finite StateFinite State