EU Cyber Resilience Act: Key Obligations for IoT and Firmware Makers from 2026
The EU Cyber Resilience Act (Regulation 2024/2847), which took effect on December 10, 2024, will begin its first operational phase on September 11, 2026, when manufacturers must start reporting actively exploited vulnerabilities and serious security incidents. The regulation applies to all hardware and software sold on the European market, including IoT devices, Linux gateways, and embedded systems, with full provisions kicking in from December 11, 2027. Manufacturers are required to know exactly which products are affected, which firmware versions they run, and what software components they contain in order to meet tight reporting deadlines. The CRA also mandates that cybersecurity be built into the entire product lifecycle — covering firmware, bootloaders, software dependencies, updates, SBOMs, and post-sale vulnerability management. The regulation marks a fundamental shift for the embedded sector, demanding that security be treated as a core engineering discipline rather than an optional add-on.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in