EU CRA Compliance for Connected Products

If your connected device sells into Europe, the EU Cyber Resilience Act applies to you. Full enforcement lands in December 2027, with reporting duties starting as early as September 2026. We help connected-device and IoT makers reach conformity with gap assessments, continuous SBOM monitoring, and the reporting the CRA expects.

A Network Connection Is Now a Legal Obligation

The EU Cyber Resilience Act sets mandatory cybersecurity rules for any product with digital elements sold in the EU, from telematics units and IoT gateways to smart devices and beyond. The bar isn't “best effort.” It's documented security by design, a real vulnerability-handling process, and proven conformity.

Full enforcement lands in December 2027, and getting it wrong can mean fines up to €15 million or 2.5% of global annual turnover, whichever is higher, plus the risk of being pulled from the EU market. The work behind compliance, from SBOMs to vulnerability processes to conformity evidence, takes months. The deadline is closer than it looks.

The nearer date is the one to plan around. Vulnerability and incident reporting duties start from 11 September 2026, well before full application on 11 December 2027. If you're scoping work now, that's the milestone that sets your timeline.

From CRA Gap to Market-Ready Conformity

EU CRA Gap Assessment

We map your product against the CRA's requirements and work out which risk class it falls into.

Explore EU CRA

SBOM/HBOM & Monitoring

Continuous component monitoring through vulnerability.core, with an alert the moment a new vulnerability appears.

Explore vulnerability.core

Vulnerability-Handling Process

We help you stand up the identify-fix-disclose process the CRA requires, and keep it running.

Explore the process

Security Testing

Penetration and fuzz testing of your device firmware, interfaces and APIs.

Explore testing

Conformity Documentation

The evidence pack for self-assessment or third-party conformity, and your CE marking.

Explore compliance

Ongoing Update Strategy

A practical plan for security updates across the support period you commit to.

Explore updates

What the EU CRA Actually Requires

Security by Design & Default

A documented risk assessment, and a product that's secure straight out of the box.

SBOM (Software Bill of Materials)

A maintained list of every component in your product, so vulnerabilities can be tracked and disclosed.

Vulnerability Handling & Disclosure

A working process that runs for the life of the product, including duties to report serious issues.

Conformity Assessment

Proof that your product conforms, self-assessed or checked by a third party depending on risk class, so you can CE-mark it.

Security Updates

Updates provided across the support period you've defined for the product.

Automotive-Grade Security, Applied to Your Devices

Both worlds, one partner

We do automotive and connected-device/EU CRA work, a combination very few security vendors can offer.

Monitoring that doesn't stop at launch

vulnerability.core keeps watching your SBOM long after the assessment is signed off, not just on day one.

Evidence that holds up

Reporting built for EU CRA conformity, not a generic scan dump you have to translate yourself.

Connected Device Compliance, Common Questions

If it has digital elements and is sold or made available in the EU, it almost certainly does, and that includes IoT gateways, smart devices and telematics units. A gap assessment confirms it quickly.
Yes, absolutely. We work with connected-device and IoT makers across many sectors, bringing the same automotive-grade rigour and vulnerability.core's SBOM monitoring to your products.
An EU CRA gap assessment. It pins down your scope, your risk class, and the exact gaps to close, and from there we set up continuous SBOM monitoring.
It depends on your product's risk class. We help you work out the right route and prepare the evidence either way, so you're not guessing.

Be EU CRA Ready, Well Before 2027

Start an EU CRA assessment, and we'll map your device against the regulation, set up continuous SBOM monitoring, and build the conformity evidence that keeps you selling in the European market.