CRA and the Internet of Things
IoT devices are a primary focus of the Cyber Resilience Act. The regulation was designed in large part to address the poor security state of connected devices, from smart home gadgets to industrial sensors.
Why IoT is a Priority
IoT devices often have long deployment lifespans, limited update capabilities, and are frequently targeted by botnets. The CRA aims to raise the security baseline for all connected products sold in the EU market.
Covered IoT Product Types
Smart Home
- Smart speakers
- Security cameras
- Smart locks
- Thermostats
- Smart appliances
Industrial IoT
- Sensors & actuators
- PLCs & controllers
- Industrial gateways
- SCADA components
- Robotics systems
Consumer Electronics
- Wearables
- Smart toys
- Connected vehicles
- Health monitors
- Gaming devices
IoT Product Classification
IoT products are classified based on their risk profile. Many consumer IoT devices fall into the Standard category, but specialized or infrastructure-connected devices may be classified higher:
IoT-Specific CRA Requirements
While all Annex I requirements apply, these are particularly important for IoT devices:
No Default Passwords
Each device must have a unique password or require the user to set one during first setup. Universal default passwords (like "admin/admin") are prohibited.
Secure Update Mechanism
Devices must support secure over-the-air (OTA) updates with cryptographic verification. Users should be notified of available updates.
Encrypted Communications
All network communications must be encrypted. No unencrypted data transmission for sensitive information.
Minimal Attack Surface
Disable unused ports and services. Devices should expose only necessary interfaces and minimize the attack surface.
Offline Functionality
Devices should remain functional (at least basic features) even without network connectivity. No unnecessary cloud dependencies.
Secure Factory Reset
Devices must allow users to securely reset to factory default and completely wipe all user data.
Physical Security
Where appropriate, devices must be tamper-resistant. Debug interfaces should be disabled or secured in production.
Security Support Period
One of the most impactful CRA requirements for IoT manufacturers is the security support period:
⏰ Minimum 5-Year Support
Manufacturers must provide security updates for at least 5 years from placing the product on market. If the expected product lifetime is less than 5 years, provide updates for that shorter period instead. This must be clearly communicated to users at time of purchase.
What This Means for IoT
- Long-term commitment: You must maintain update infrastructure for years
- Cost planning: Factor support costs into product lifecycle planning
- EOL planning: Clear communication when support ends
- Component selection: Choose suppliers who provide long-term support
IoT-Specific Challenges
IoT manufacturers face unique challenges in achieving CRA compliance:
Resource Constraints
Many IoT devices have limited CPU, memory, and storage, making it harder to implement robust security features and cryptography.
Supply Chain Complexity
IoT products often include components from multiple suppliers, requiring coordination for vulnerability disclosures and updates.
Field Updates
Updating deployed devices can be challenging, especially for devices in remote locations or those with intermittent connectivity.
Long Deployment Cycles
Industrial IoT devices may be deployed for 10-20 years, requiring very long-term security support planning.
IoT Compliance Checklist
Key actions for IoT manufacturers:
Assess Product Classification
Determine if your device is Standard, Class I, Class II, or Critical.
Take Assessment →Implement Secure Boot
Ensure firmware integrity verification during boot process.
Build OTA Update System
Implement secure, signed firmware updates with rollback capability.
Generate Firmware SBOM
Create a Software Bill of Materials for all firmware components.
SBOM Guide →Disable Debug Interfaces
Ensure JTAG, UART, and other debug ports are disabled in production.
Plan Support Lifecycle
Define and communicate the security support period to customers.
Industrial IoT? Check This Too
If your IoT product is also classified as machinery (industrial robots, AGVs, smart manufacturing equipment), you may need to comply with the EU Machinery Regulation 2023/1230 in addition to CRA. This regulation has its own cybersecurity requirements starting January 2027.
Learn about Machinery Regulation →Assess Your IoT Product
Take our free assessment to understand your classification and compliance requirements.