Loading...
Finite StateFinite State
Finite StateFinite State
EU Cyber Resilience Act

Navigate EU CRA Compliance with Confidence

Explore expert guidance, actionable resources, and purpose-built tools to help your organization meet the requirements of the EU Cyber Resilience Act—and build a more secure product ecosystem.

EU CRA Core Requirements

Secure by Design Principles

Under the CRA, manufacturers must integrate security practices throughout the product lifecycle, including

  • Secure boot
  • Access controls
  • Encryption
  • Default security settings
  • Lifecycle security management

Vulnerability Handling

IoT manufacturers must proactively manage vulnerabilities and respond swiftly to security incidents with

  • Continuous monitoring
  • Formal reporting processes
  • 24hr disclosure periods
  • Secure patch distribution
  • End-of-life policy for legacy devices

SBOM & Technical Documentation

The CRA improves software supply chain transparency by imposing specific security requirements on manufacturers, such as

  • including proprietary & open-source components in SBOMs & updating them with each modifcation
  • Including hardware & software configurations, security features, update protocols, & maintenance guidelines in technical documentation

Product Lifecycle Support

The EU CRA demands product lifecycle support to keep devices secure through their operational lifespan, including

  • Defined End-of-Life policies
  • Long-term maintenance commitments
  • Provision for timely security updates
  • Incident response planning

Software Supply Chain Security

Reliance on third-party software increases attack surfaces, which is why the CRA requires

  • Comprehensive assessments of third-party suppliers
  • Continuous vulnerability scanning
  • Robust logging & auditing practices
  • Open source risk management practices

Conformity Assessments

The CRA introduces mandatory conformity assessments aligned to product risk categories

  • Self-assessments: Default & Important Class I (with exceptions)
  • 3rd-party assessments: Important Class II
  • European Common Criteria certification: Critical

EU CRA Compliance Timeline

1

Dec 11, 2027

The EU CRA becomes fully applicable

2

Sep 11, 2026

Reporting obligations for manufacturers begin

3

Dec 10, 2024

The EU CRA comes into force

4

Nov 20, 2024

The CRA is officially published in the Official Journal of the European Union

Ready to Get Started?

See how Finite State can help secure your products.

Request a DemoRequest a DemoTake a Product TourTake a Product Tour
Finite StateFinite State

Finite State is the Product Security Automation Platform that functions as an autonomous Product Security OS: design → verify → prove, grounded in what you ship.

Platform

Platform Overview
Ground Truth Inventory
Exploitability-Based Prioritization
Design-Time Architecture Security
Automated Evidence-Backed Compliance

Solutions

Device Manufacturers
Automotive
Medical Devices
Energy & Utilities
Government
Industrial

Resources

Blog
Resource Library
Webinars & Videos
Events
Documentation

Company

About Us
CareersHIRING
Press & Media
Contact Sales
X

Privacy PolicyTerms of UseCustomer Terms and Conditions