Industry Guide Updated: August 2026

Does the Cyber Resilience Act Apply to Automotive Software?

Learn if the EU CRA applies to Automotive Software, what the core compliance requirements are, and how to start preparing your engineering teams automatically.

Core Definition

It Depends. Exempt if falling under UNECE vehicle regulations. Infotainment or telematics software layered on top of a UNECE-approved vehicle system can still be in CRA scope if it's sold as a separate product. If you do not fall into an explicit exemption, your Automotive Software will be subjected to the CRA's strict requirements.

Key Compliance Steps for Automotive Software

  1. Determine Classification: Check if your Automotive Software falls under the default category or Class I/Class II, which dictate stricter conformity assessment paths.
  2. Perform Risk Assessment: Map out the attack surface for your software and document the mitigations for the "secure by design" requirement.
  3. Implement Vulnerability Reporting: Provide a 24-hour reporting mechanism to ENISA for actively exploited vulnerabilities.
  4. Generate an SBOM: Ensure all dependencies used in your Automotive Software are documented in a machine-readable Software Bill of Materials.
  5. Avoid the Common Pitfall: Treating 'automotive' as a blanket exemption category instead of checking the specific UNECE regulation that applies.

How This Plays Out in Practice

Infotainment or telematics software layered on top of a UNECE-approved vehicle system can still be in CRA scope if it's sold as a separate product.

What to Watch For

Treating 'automotive' as a blanket exemption category instead of checking the specific UNECE regulation that applies.

Assess Your CRA Readiness

Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to Automotive Software.

Need help with CRA? Ask the assistant.
Need help with CRA? Ask the assistant.