EU CRA for IoT Makers: A 2027 Readiness Checklist

What the Cyber Resilience Act asks of connected-device teams.

The EU Cyber Resilience Act is not just an automotive rule. It applies to almost any product with digital elements placed on the EU market, which means most connected devices. Here is a practical readiness checklist.

If your product has software and reaches a network or another device, assume the CRA applies and confirm the detail later. It shifts responsibility for security onto the manufacturer for the product's whole supported lifetime, not just the point of sale.

The dates that matter

Two milestones drive the plan: from September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents; from December 2027, the full set of obligations applies and non-compliant products can no longer be placed on the market. Treat 2027 as the hard gate and 2026 as when your vulnerability-handling process has to be live.

The readiness checklist

Where to start

Scope which products fall in, then stand up the SBOM pipeline and vulnerability-handling process first, they take longest to make real, before working the conformity route.

A prioritised plan turns a broad regulation into manageable steps. A compliance gap assessment is the place to begin.

From Reading About Compliance to Achieving It

When you're ready to go from understanding the EU CRA to actually meeting it, start with a gap assessment mapped to your product and markets.