The Cyber Resilience Act for IoT Manufacturers
Prepare your connected hardware, firmware, and cloud backends for mandatory EU cybersecurity standards before the 2026 and 2027 deadlines.

For an IoT manufacturer, the Cyber Resilience Act (EU Regulation 2024/2847) mandates cybersecurity by design, continuous vulnerability monitoring, and a software bill of materials (SBOM) for all connected products sold in the EU market. Compliance requires implementing mandatory ENISA vulnerability reporting by 11 September 2026 and full technical documentation by 11 December 2027. CRAcheck provides automated self-assessment support to help hardware and embedded software teams streamline these obligations.
Understanding CRA Compliance Scope for Connected Devices
The EU Cyber Resilience Act applies directly to products with digital elements, covering both physical IoT hardware devices and their embedded firmware or connected software interfaces.
Key enforcement dates and penalties that IoT makers must prepare for include:
- 10 December 2024: CRA officially entered into force.
- 11 September 2026: Mandatory reporting of actively exploited vulnerabilities and severe incidents.
- 11 December 2027: Full compliance enforcement across all product categories and technical files.
- Non-compliance risks fines up to EUR 15M or 2.5% of total worldwide annual turnover.
Core Capabilities for IoT Engineering Teams
CRAcheck simplifies technical record-keeping and vulnerability monitoring for hardware and embedded teams.
Multi-Ecosystem SBOM Generation
Generate CycloneDX SBOMs covering npm, PyPI, Go, Rust, .NET, PHP, Ruby, and Java components used in device firmware or cloud APIs.
ENISA Incident Workflows
Structured notification workflows to support strict reporting timelines: early warning within 24h, notification within 72h, and final report within 14d.
Annex VII Technical Dossiers
Auto-populate technical documentation templates and draft your EU Declaration of Conformity based on continuous repository scans.
Automated Score & Alerts
Compute a clear 0 to 100 compliance score for your repositories and receive email alerts whenever new CVE vulnerabilities are detected.
Practical Cyber Security Management for Embedded Systems
IoT manufacturers must bridge embedded firmware development, cloud gateways, and ongoing post-market security obligations.
- Connect GitHub repositories storing firmware drivers, SDKs, and cloud backend microservices.
- Maintain standardized SECURITY.md files for coordinated vulnerability disclosure.
- Generate pre-filled Annex VII technical dossiers ready for internal review and assessment.

CRA Product Classification and IoT Risk Tiers
Under EU Regulation 2024/2847, products with digital elements are organized into risk classes that determine conformity assessment procedures:
Default Product Class (Self-Assessment)
Most standard consumer connected devices (such as smart home sensors or connected wearables) fall under the Default class. Manufacturers can perform internal production control (Module A) self-assessments using tools like CRAcheck to prepare required documentation.
Important & Critical Product Classes
IoT products performing critical functions—such as smart meters, industrial controllers, or network firewalls—are listed under Annex III (Classes I & II) or Annex IV (Critical). These tiers may require third-party notified body assessments or harmonized standards adherence.
Assess Your Repository Readiness for the CRA
Explore how automated repository checks support your engineering team in preparing for regulatory milestones.
3 Steps to Prepare IoT Codebases with CRAcheck
- 1
1. Connect Firmware & API Codebases
Link your GitHub repositories storing embedded source code, build scripts, and cloud backend APIs.
- 2
2. Generate SBOMs & Monitor Vulnerabilities
Automatically generate CycloneDX SBOMs across 9 ecosystems and receive email alerts for newly identified CVEs.
- 3
3. Export Technical Files & Workflows
Download pre-filled Annex VII technical dossiers, SECURITY.md files, and ENISA-formatted reporting checklists.
Self-Assessment Preparation Built for Tech Lead Teams
CRAcheck functions as an automated self-assessment support platform designed to reduce manual overhead for engineering leads.
Important Notice: CRAcheck provides self-assessment support and software tools to prepare technical files. It is not an official conformity assessment body, does not award regulatory certification, and does not replace official legal counsel.
Frequently Asked Questions
Does the CRA apply to non-EU IoT manufacturers?+
Yes. Any IoT manufacturer selling connected hardware or embedded software within the European Union market must meet CRA requirements, regardless of company headquarters.
Is CRAcheck an official CRA certification provider?+
No. CRAcheck is a self-assessment support tool. It helps teams scan repositories, compute compliance scores, generate SBOMs, and draft technical documentation, but does not offer official regulatory certification.
What ecosystems does CRAcheck support for SBOM generation?+
CRAcheck supports 9 ecosystems including npm, PyPI, Go, Rust, .NET, PHP, Ruby, Java, and CycloneDX exports.
What are the deadlines for CRA compliance?+
Vulnerability reporting obligations take effect on 11 September 2026. Full compliance obligations, including technical documentation and CE marking, apply on 11 December 2027.
Streamline CRA Compliance for Your Connected Products
Connect your GitHub repositories to generate CycloneDX SBOMs, track vulnerabilities, and pre-fill Annex VII documentation.
Same topic — Par rôle
New to the Cyber Resilience Act? Start with the complete guide.
The CRA guideFrom the blog
Check your CRA compliance in 1 minute
Free, no sign-up. Scan your repo and get your compliance score + pre-filled documents.