Industry

CRA for IoT Manufacturers: Securing Connected Devices

Hardware meets software. How IoT device makers must navigate the Cyber Resilience Act to legally sell in Europe.

March 2026 · 11 min read

IoT is the Primary Target of the CRA

Historically, IoT devices (webcams, smart home hubs, routers) have been plagued by hardcoded passwords and unpatchable firmware. The CRA specifically aims to end this era.

Critical Requirements for Hardware

  • No Default Passwords: Devices must prompt the user to change the password upon first initialization.
  • Update Mechanisms: Devices must be capable of receiving Over-The-Air (OTA) firmware updates.
  • Guaranteed Support Windows: Manufacturers must clearly state how long a device will receive security updates (minimum 5 years, or expected product lifetime).

Classification Risks

If your IoT device is used in critical infrastructure (e.g., smart meters, industrial control systems), it elevates to Class I or Class II, requiring an external audit by a Notified Body.

Explore our comprehensive IoT module.

Get the CRA deadline calendar

A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.

Related articles

Ready to Take Action?

Start your CRA compliance journey with our free assessment tool.

Need help with CRA? Ask the assistant.
Need help with CRA? Ask the assistant.