← Back to CRA Guide Last updated: September 5, 2026

CRA for IoT Products: Hardware Security Requirements

How the Cyber Resilience Act applies to connected devices, smart home products, industrial IoT, wearables, and embedded systems. Specific requirements and challenges.

CRA and the Internet of Things

IoT devices are a primary focus of the Cyber Resilience Act. The regulation was designed in large part to address the poor security state of connected devices, from smart home gadgets to industrial sensors.

Why IoT is a Priority

IoT devices often have long deployment lifespans, limited update capabilities, and are frequently targeted by botnets. The CRA aims to raise the security baseline for all connected products sold in the EU market.

Covered IoT Product Types

🏠

Smart Home

  • Smart speakers
  • Security cameras
  • Smart locks
  • Thermostats
  • Smart appliances
🏭

Industrial IoT

  • Sensors & actuators
  • PLCs & controllers
  • Industrial gateways
  • SCADA components
  • Robotics systems

Consumer Electronics

  • Wearables
  • Smart toys
  • Connected vehicles
  • Health monitors
  • Gaming devices

IoT Product Classification

IoT products are classified based on their risk profile. Many consumer IoT devices fall into the Standard category, but specialized or infrastructure-connected devices may be classified higher:

Standard
Consumer electronics, smart home devices, wearables. Self-assessment (Module A) allowed.
Examples: Smart bulbs, fitness trackers, smart speakers
Important Class I
Network-connected devices, routers, smart home hubs. Third-party assessment required — no harmonised CRA standards as of 2026 (Article 32).
Examples: Home routers, smart locks, baby monitors
Important Class II
Only if your IoT product embeds one of Annex III Class II's 4 listed component types. Third-party Notified Body assessment required.
Examples: Hypervisors/container runtime systems, firewalls or intrusion detection/prevention systems, tamper-resistant microprocessors, tamper-resistant microcontrollers — not ICS/PLC/SCADA/robotics generally, which aren't named in Annex III
Critical
Smart meter gateways within smart metering systems, plus hardware security boxes and smartcards/secure elements. EU cybersecurity certification required where a scheme has been adopted (Article 8(1)); otherwise Notified Body assessment (Article 32(4)).
Examples: Smart meter gateways (not generic smart meters), hardware devices with security boxes, smartcards or secure elements

IoT-Specific CRA Requirements

While all Annex I requirements apply, these are particularly important for IoT devices:

🔑

No Default Passwords

Each device must have a unique password or require the user to set one during first setup. Universal default passwords (like "admin/admin") are prohibited.

📡

Secure Update Mechanism

Devices must support secure over-the-air (OTA) updates with cryptographic verification. Users should be notified of available updates.

🔒

Encrypted Communications

All network communications must be encrypted. No unencrypted data transmission for sensitive information.

🌐

Minimal Attack Surface

Disable unused ports and services. Devices should expose only necessary interfaces and minimize the attack surface.

Offline Functionality

Devices should remain functional (at least basic features) even without network connectivity. No unnecessary cloud dependencies.

🔄

Secure Factory Reset

Devices must allow users to securely reset to factory default and completely wipe all user data.

🛡️

Physical Security

Where appropriate, devices must be tamper-resistant. Debug interfaces should be disabled or secured in production.

Security Support Period

One of the most impactful CRA requirements for IoT manufacturers is the security support period:

⏰ Minimum 5-Year Support

Manufacturers must provide security updates for at least 5 years from placing the product on market. If the expected product lifetime is less than 5 years, provide updates for that shorter period instead. This must be clearly communicated to users at time of purchase.

What This Means for IoT

  • Long-term commitment: You must maintain update infrastructure for years
  • Cost planning: Factor support costs into product lifecycle planning
  • EOL planning: Clear communication when support ends
  • Component selection: Choose suppliers who provide long-term support

IoT-Specific Challenges

IoT manufacturers face unique challenges in achieving CRA compliance:

Resource Constraints

Many IoT devices have limited CPU, memory, and storage, making it harder to implement robust security features and cryptography.

Supply Chain Complexity

IoT products often include components from multiple suppliers, requiring coordination for vulnerability disclosures and updates.

Field Updates

Updating deployed devices can be challenging, especially for devices in remote locations or those with intermittent connectivity.

Long Deployment Cycles

Industrial IoT devices may be deployed for 10-20 years, requiring very long-term security support planning.

IoT Compliance Checklist

Key actions for IoT manufacturers:

1

Assess Product Classification

Determine if your device is Standard, Class I, Class II, or Critical.

Take Assessment →
2

Implement Secure Boot

Ensure firmware integrity verification during boot process.

3

Build OTA Update System

Implement secure, signed firmware updates with rollback capability.

4

Generate Firmware SBOM

Create a Software Bill of Materials for all firmware components.

SBOM Guide →
5

Disable Debug Interfaces

Ensure JTAG, UART, and other debug ports are disabled in production.

6

Plan Support Lifecycle

Define and communicate the security support period to customers.

Industrial IoT? Check This Too

If your IoT product is also classified as machinery (industrial robots, AGVs, smart manufacturing equipment), you may need to comply with the EU Machinery Regulation 2023/1230 in addition to CRA. This regulation has its own cybersecurity requirements starting January 2027.

Learn about Machinery Regulation →

Assess Your IoT Product

Take our free assessment to understand your classification and compliance requirements.