EU Cyber Resilience Act

New Requirements for Manufacturers of Connected Devices

EU Cyber Resilience Act: What Manufacturers of Connected Devices Should Do

The EU Cyber Resilience Act significantly changes the requirements for manufacturers of connected devices. Anyone developing products with digital components must consider security earlier in the process and incorporate it throughout the entire product lifecycle.

For companies, this means that risks must be assessed, vulnerabilities must be properly addressed, and security measures must be documented in a traceable manner. This is precisely why manufacturers should not wait until shortly before implementation to review the Cyber Resilience Act, but rather incorporate it early on in development, operation, and maintenance.

How the EU Cyber Resilience Act Affects Manufacturers

The EU Cyber Resilience Act applies to products with digital elements. These include many connected devices, systems with software or firmware, and products with external interfaces.

The most significant change is that manufacturers must now demonstrate security in a structured manner. It is no longer sufficient to address security issues only at the end of a project. Manufacturers must be able to demonstrate

What risks exist

How they assess these risks

What measures they implement

How they address vulnerabilities

How updates are ensured throughout the product’s lifecycle

Why the Cyber Resilience Act Is Relevant for Businesses

For manufacturers of connected devices, it’s not just about regulation. The EU Cyber Resilience Act has a direct impact on day-to-day operations in development, support, and product maintenance.

Those who address these requirements early on reap multiple benefits:

  • Risks become apparent sooner

  • Security vulnerabilities can be assessed in a more structured manner

  • Updates and maintenance become easier to plan

  • Decisions are documented in a traceable manner because risks, measures, and responsibilities are recorded early on.

The practical benefit is clear: Companies can ensure greater certainty in their procedures and reduce unnecessary effort down the line.

What Companies Should Specifically Do Now

A sensible first step is to conduct an assessment. Manufacturers should examine:

Practical Examples of EU CRA Implementation

Service Desk for Vulnerability Reports

A service desk establishes a clear process for reporting, assessing, and documenting vulnerabilities.

SBOM for Transparency and Monitoring

An SBOM (Software Bill of Materials) shows which components and versions are included in a release. It is created prior to delivery and serves as the basis for ongoing monitoring. If a vulnerability is later discovered in a version currently in use, it can be specifically identified, assigned to the affected release, and reported promptly.

Conduct Targeted Security Risk Assessments of Interfaces

Every interface (e.g., Wi-Fi) potentially increases the attack surface. Therefore, manufacturers should determine early on which connections are necessary and how they can be secured.

How We Support Companies

We help companies translate the requirements of the EU Cyber Resilience Act into concrete processes.

This includes, for example:

  • Setting up a service desk for vulnerability reports

  • Targeted testing of interfaces for security risks

  • Structured assessment of dependencies and libraries

  • Using an SBOM to create greater transparency regarding the components in use and to specifically monitor changes to them as well as known vulnerabilities.

  • Using an SBOM to create greater transparency regarding the components in use

This transforms a regulatory requirement into a practical working framework.

Cyber act b

FAQ's

What is the EU Cyber Resilience Act?

The EU Cyber Resilience Act is an EU regulation for products with digital elements. Its goal is to improve the cybersecurity of connected devices and software throughout the entire product lifecycle. Manufacturers must assess risks, implement security requirements, address vulnerabilities, and ensure updates.

The EU Cyber Resilience Act applies to products with digital elements that are directly or indirectly connected to a network or other devices. This includes many connected devices, systems with software or firmware, and digital components in physical products. It is therefore important for manufacturers to assess early on which products and functions are affected.

The Cyber Resilience Act requires manufacturers of connected devices to assess security not just at the end of a project. Companies must systematically assess risks, document vulnerabilities, implement security measures, and clearly define procedures for updates and maintenance. Transparency regarding the components used, traceable documentation, and clear lines of responsibility are also important.

Companies should start by conducting an assessment: Which products are affected, which libraries and dependencies are in use, and what interfaces exist? The next step is to establish processes for vulnerability management, documentation, and updates. In practice, a service desk for reporting vulnerabilities, an SBOM to ensure transparency regarding components, and a targeted review of security-relevant interfaces can help with this.

The EU Cyber Resilience Act Calls for Clarity Rather Than Ad Hoc Responses

The EU Cyber Resilience Act makes security a mandatory responsibility for manufacturers of connected devices. Companies must systematically monitor products, components, interfaces, vulnerabilities, and updates.

Those who start now to

  • Thoroughly assess risks,

  • Establish processes for reporting and documentation,

  • Make dependencies transparent,

  • And systematically test interfaces

will create a better foundation for secure, maintainable, and sustainable products in the long term.

Our Expert

CTO

Manuel Eugster

MAS FHO Software Engineering

tranSvias Team
Yeesss - wir haben es geschafft!!!

tranSvias LSVA ist offiziell NETS-zertifiziert!

Herzlichen Dank unseren Pilotkunden für ihre Geduld, das ehrliche Feedback und Vertrauen!