The Cyber Resilience Act marks a major shift in how connected products must be designed, built, and maintained. Cybersecurity is no longer an optional feature or a one-time activity at product launch. Manufacturers must be able to identify, assess, remediate, and document vulnerabilities throughout the supported lifetime of their products.
This page provides a brief introduction to the CRA and explains how Nordic's nRF Cloud chip-to-cloud platform can help manufacturers strengthen product security, operationalize vulnerability management, deliver secure firmware updates, and maintain evidence of ongoing compliance.
The EU Cyber Resilience Act (CRA) is a broad cybersecurity regulation covering products with digital elements placed on the EU market. It responds to the growing number of connected hardware and software products with inadequate cybersecurity, limited long-term support, and insufficient information for users.
The CRA introduces mandatory cybersecurity requirements for both hardware and software products. These requirements apply not only when a product enters the market, but throughout its expected lifetime. Manufacturers must therefore establish processes for secure product design, vulnerability handling, security updates, incident reporting, and supporting documentation.
To comply with the CRA, products must meet the essential cybersecurity requirements defined in the act, and manufacturers must put effective vulnerability-handling processes in place. The regulation applies to most products with digital elements unless they are already covered by specific sector regulations, such as those for medical, aviation, military, or automotive products.
The CRA entered into force in December 2024. Its main obligations apply from December 2027, while the requirements for vulnerability and incident reporting apply from 11 September 2026. Non-compliance can result in corrective actions, withdrawal or recall of products, and significant financial penalties.
The CRA applies broadly to manufacturers, importers, and distributors of hardware and software products that include digital elements and can connect, directly or indirectly, to a network or another device.
Manufacturers carry the primary responsibility for ensuring that products are secure by design, supported throughout their expected lifetime, and capable of receiving timely security updates. Importers and distributors must also verify that products meet the applicable CRA requirements and are accompanied by the required technical documentation before they are made available in the EU.
The regulation affects the entire IoT ecosystem. Nordic, as a provider of hardware, software, and services to manufacturers, is directly affected by the CRA in the sense of making sure our hardware and software components meet the requirements for CE-marking, and it's affecting device manufacturers that use our solutions in that they will need to have integrated, straightforward solutions for CRA compliance.
Manufacturers are responsible for ensuring that products with digital elements meet the essential cybersecurity requirements listed in Annex I of the CRA. These requirements cover both the security properties of the product and the processes used to handle vulnerabilities throughout the product lifecycle.
Products must be designed, developed, and maintained in accordance with key cybersecurity principles, including:
Manufacturers must establish a repeatable and documented vulnerability management process, including:
For a complete understanding of the applicable obligations, manufacturers should refer directly to the Cyber Resilience Act and seek appropriate legal and compliance guidance.
One of the biggest changes introduced by the CRA is the requirement to keep products secure after they have been deployed. Manufacturers must be able to identify security issues, understand which products and devices are affected, deliver remediation, and document the actions taken throughout the supported lifetime of the product.
nRF Cloud supports this continuous firmware security lifecycle. It provides capabilities for SBOM-based vulnerability identification, fleet exposure analysis, secure OTA remediation, deployment verification, and compliance evidence. Together, these capabilities help manufacturers operationalize several of the CRA requirements related to vulnerability handling and lifetime security updates.
The CRA requires manufacturers to identify and address vulnerabilities throughout the product lifecycle. nRF Cloud Firmware Vulnerability Management uses firmware SBOMs to identify known vulnerabilities affecting software components and continuously monitors for newly disclosed CVEs. This helps manufacturers move from periodic, manual checks to an ongoing and repeatable vulnerability management process.
Knowing that a vulnerability exists is only the first step. Manufacturers also need to understand where it is present and how broadly it affects deployed products. nRF Cloud connects vulnerability information with firmware versions and device inventory, helping teams identify affected devices, assess fleet exposure, track vulnerability trends, and prioritize remediation based on severity and operational impact.
The CRA requires manufacturers to provide timely security updates and remediate vulnerabilities throughout the expected lifetime of the product. nRF Cloud provides secure and reliable firmware-over-the-air update capabilities across connected device fleets. Manufacturers can plan and monitor deployments, track firmware adoption, identify rollout issues, and deliver security fixes without requiring physical access to devices.
A vulnerability is not resolved simply because a firmware update has been released. Manufacturers need to know whether the fix has reached the affected fleet. nRF Cloud helps teams track update progress, monitor firmware version adoption, verify successful deployment, and identify devices that remain exposed or require additional action.
The CRA requires manufacturers to maintain documentation and provide clear information about vulnerabilities and security updates. nRF Cloud combines SBOM association, vulnerability records, device inventory, firmware version tracking, rollout status, and update history to create an auditable view of firmware security activities. This can support internal governance, compliance documentation, and evidence of ongoing vulnerability handling.
By bringing vulnerability identification, fleet analysis, secure OTA remediation, verification, and documentation together, nRF Cloud helps manufacturers manage firmware security as a continuous lifecycle:
Whether you are preparing for CRA requirements, strengthening an existing vulnerability management process, launching a new connected product, or adding long-term support to deployed devices, nRF Cloud helps you build and maintain secure connected products throughout their supported lifetime.
Explore nRF Cloud to learn how Firmware Vulnerability Management, secure OTA updates, fleet visibility, and lifecycle documentation can support your product security and CRA readiness.