Navigate EU CRA Compliance with Confidence
Explore expert guidance, actionable resources, and purpose-built tools to help your organization meet the requirements of the EU Cyber Resilience Act—and build a more secure product ecosystem.
EU CRA Core Requirements
Secure by Design Principles
Under the CRA, manufacturers must integrate security practices throughout the product lifecycle, including
- Secure boot
- Access controls
- Encryption
- Default security settings
- Lifecycle security management
Vulnerability Handling
IoT manufacturers must proactively manage vulnerabilities and respond swiftly to security incidents with
- Continuous monitoring
- Formal reporting processes
- 24hr disclosure periods
- Secure patch distribution
- End-of-life policy for legacy devices
SBOM & Technical Documentation
The CRA improves software supply chain transparency by imposing specific security requirements on manufacturers, such as
- including proprietary & open-source components in SBOMs & updating them with each modifcation
- Including hardware & software configurations, security features, update protocols, & maintenance guidelines in technical documentation
Product Lifecycle Support
The EU CRA demands product lifecycle support to keep devices secure through their operational lifespan, including
- Defined End-of-Life policies
- Long-term maintenance commitments
- Provision for timely security updates
- Incident response planning
Software Supply Chain Security
Reliance on third-party software increases attack surfaces, which is why the CRA requires
- Comprehensive assessments of third-party suppliers
- Continuous vulnerability scanning
- Robust logging & auditing practices
- Open source risk management practices
Conformity Assessments
The CRA introduces mandatory conformity assessments aligned to product risk categories
- Self-assessments: Default & Important Class I (with exceptions)
- 3rd-party assessments: Important Class II
- European Common Criteria certification: Critical
EU CRA Compliance Timeline
Dec 11, 2027
The EU CRA becomes fully applicable
Sep 11, 2026
Reporting obligations for manufacturers begin
Dec 10, 2024
The EU CRA comes into force
Nov 20, 2024
The CRA is officially published in the Official Journal of the European Union
Ready to Get Started?
See how Finite State can help secure your products.