Does the Cyber Resilience Act Apply to Augmented Reality (AR) Apps?
Learn if the EU CRA applies to Augmented Reality (AR) Apps, what the core compliance requirements are, and how to start preparing your engineering teams automatically.
Core Definition
Yes. The EU Cyber Resilience Act applies directly to Augmented Reality (AR) Apps as they fall under the definition of "products with digital elements." An AR app overlaying data on a live camera feed needs the same secure-update rigor as any other connected software, even though it feels more like a feature than a product. This means your software must meet mandatory cybersecurity requirements to be distributed in the EU market.
Key Compliance Steps for Augmented Reality (AR) Apps
- Determine Classification: Check if your Augmented Reality (AR) Apps falls under the default category or Class I/Class II, which dictate stricter conformity assessment paths.
- Perform Risk Assessment: Map out the attack surface for your software and document the mitigations for the "secure by design" requirement.
- Implement Vulnerability Reporting: Provide a 24-hour reporting mechanism to ENISA for actively exploited vulnerabilities.
- Generate an SBOM: Ensure all dependencies used in your Augmented Reality (AR) Apps are documented in a machine-readable Software Bill of Materials.
- Avoid the Common Pitfall: AR SDKs from ad networks or analytics vendors get embedded without reviewing what camera or location data they exfiltrate.
How This Plays Out in Practice
An AR app overlaying data on a live camera feed needs the same secure-update rigor as any other connected software, even though it feels more like a feature than a product.
What to Watch For
AR SDKs from ad networks or analytics vendors get embedded without reviewing what camera or location data they exfiltrate.
Assess Your CRA Readiness
Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to Augmented Reality (AR) Apps.