Easing EU Cyber Resilience Act Compliance with Integrated SOMs

Full CRA compliance involves rigorous design, testing, and ongoing updates; Digi's ConnectCore platform and TrustFence framework offer pre-built security features and automation tools to help manufacturers meet EU cybersecurity regulations efficiently.

Key Highlights

  • The CRA requires manufacturers to embed security features during product design, including secure defaults, encryption, and attack surface reduction.
  • Lifecycle vulnerability management, including regular SBOM updates and automated patch deployment, is a core component of CRA compliance.

(Source: Ruslan/stock.adobe.com; generated with AI)

As connected products have become more widespread, cybersecurity can no longer depend primarily on voluntary industry practices or user configuration. Considering the serious consequences of security breaches, the European Union (EU) has introduced the Cyber Resilience Act (CRA). This regulatory framework defines the security measures required for products with digital elements that are to be sold in the European single market.[1]

Manufacturers typically release products and patch vulnerabilities as they are found. The CRA makes a purely reactive patching approach insufficient. Under this legislation, manufacturers must assess cybersecurity risks, satisfy applicable product requirements during design and development, and maintain vulnerability-handling and security-update processes throughout the defined support period. The legislation also holds manufacturers responsible for their entire hardware and software supply chain. While there are limited exceptions, such as certain products already covered by other EU regulatory frameworks (e.g., medical devices, motor vehicles, and civil aviation systems), most other connected products with digital elements are likely to fall within the scope of CRA.[2]

This blog examines the requirements of CRA legislation and the challenges manufacturers will face. It also demonstrates how an integrated hardware-software platform can offer a streamlined path to facilitating compliance. 

CRA Legislation Overview

Digi International summarizes the CRA through six implementation areas, as shown in Figure 1. This is an explanatory framework rather than the regulation’s formal legal structure.

Figure 1: Digi International’s framework summarizing six CRA implementation areas, including cybersecurity design, conformity assessments, incident notification, product classification, audits, and communication. (Source: Digi International) Click to read the entire article at Mouser

The CRA establishes requirements for the security characteristics that must be designed into products with digital elements. Additionally, the requirements include vulnerability management processes that manufacturers must follow after products are on the market.

Within this legislation, Annex I: Essential Cybersecurity Requirements mandates that products with digital elements are without known exploitable vulnerabilities at launch and sold with a secure-by-default configuration. Products must protect against unauthorized access through appropriate controls, including authentication, identity management, or access management. Separately, products must support security updates and, where applicable, automatic security updates enabled by default with a clear opt-out mechanism. Data must be protected at all stages of processing, transmission, and storage, typically through encryption, and processed only when relevant to the application. Additionally, data and settings must be securely deleted or transferred to other products upon request. The product must be able to monitor and record internal activities, providing information about access to or modification of data, services, or functions. Devices should limit the exposed entry points and interfaces, known as attack surfaces. Those surfaces should be secured and include exploitation-mitigation mechanisms to reduce the impact of breaches on the system itself and on other connected devices. These requirements may pose challenges for engineers, particularly when designing access points or Joint Test Action Group (JTAG) ports.[3]

The Vulnerability Handling Requirements in Part II of Annex I describe the manufacturer’s responsibilities regarding lifecycle risk management, security updates, vulnerability tracking, addressing and disclosure, auditing, and public transparency. A machine-readable software bill of materials (SBOM) must be produced in accordance with recognized international standards. The SBOM should detail the software’s structure and dependencies to provide a transparent view of the full supply chain. The SBOM should also be updated regularly to reflect any patches or changes.[4]

To ensure their products comply with the legislation, manufacturers must also understand the CRA implementation requirements.

CRA Implementation

Several key CRA implementation dates stand out (Figure 2). The CRA became legally binding in December 2024. In June 2026, conformity assessment bodies became operational. Manufacturers are obligated to report actively exploited vulnerabilities and severe incidents to the relevant authorities beginning September 2026. Come December 2027, compliance with the CRA will be mandatory for all devices sold in the EU that have the ability to connect to the internet.

Figure 2: An overview of the CRA Implementation timeline. (Source: Digi International) Click to read the entire article at Mouser

Once the CRA is fully enforced, all applicable products will need a CE mark to be sold in the region. Companies that fail to comply face fines of up to €15 million or 2.5 percent of their global annual turnover, whichever is higher.[5]

The CRA legislation is designed to ensure that connected devices sold in the European single market are as protected as possible against cyber threats, and that devices can be monitored for vulnerabilities and updated to mitigate security risks after deployment in the field. The legislation also outlines reporting processes intended to mitigate and contain damage when it does occur.[6] Other jurisdictions are introducing their own connected-product cybersecurity requirements. Designing products around secure-by-design, vulnerability management, and lifecycle support principles may help manufacturers prepare for overlapping requirements, but compliance with the CRA does not automatically establish compliance elsewhere.

To remain fully compliant, manufacturers should consider trustworthy hardware and software solutions that provide the ability to proactively manage field-deployed devices.

CRA Compliance

The detailed requirements of CRA legislation can make the typical design cycle much more complex, lengthy, and expensive. While many microcontrollers include extensive security features, implementing them and meeting the CRA’s mandates requires significant engineering effort, as well as ongoing monitoring, patching, and SBOM updates. If software is sourced from a different supplier, the manufacturer is responsible for ensuring the product’s cybersecurity is not compromised.

Due to the rigorous steps required to comply with the CRA, manufacturers may consider alternative solutions to simplify the design process and accelerate product launches. For example, Digi’s CRA solutions can handle most CRA compliance, leaving the manufacturer free to focus on design and conformance. Even then, Digi offers guidance to support in-house design and testing.

Part of this support includes the Digi ConnectCore ecosystem, developed to provide an easy route to CRA compliance. This family of products adheres to the CRA’s Annex I requirements and provides built-in tools for development and post-deployment.[7] Its hardware includes ConnectCore system-on-modules (SOMs).[8] Additionally, the Digi TrustFence framework enables products to be delivered with a secure default configuration, secure boot, an encrypted file system, and authenticated access (Figure 3).

Figure 3: Digi’s TrustFence solution is a multi-pronged approach designed to protect devices from common attacks. (Source: Digi International) Click to read the entire article at Mouser

To facilitate compliance with CRA Annex I, Part II, Digi ConnectCore Security Services track vulnerabilities and exposures while managing the SBOM. These services are also capable of performing automated patch deployments, sending over-the-air updates, and reporting common vulnerabilities and exposures (CVEs).[9] For applications that require cloud access, Digi ConnectCore Cloud Services are designed to provide extensive process automation, monitoring, and remote device management capabilities, as well as automated mass firmware and software updates, bi-directional communication, and real-time alerts.[10]

Conclusion

The EU’s CRA legislation will be fully enforced starting on December 11, 2027. The comprehensive framework is intended to protect devices marketed to the EU from cyber threats. Therefore, any manufacturer intending to sell connected products in the EU single market must be fully compliant. An easy way to ensure compliance is to adopt an integrated hardware-software ecosystem, such as Digi’s ConnectCore ecosystem, which has been developed specifically to map all essential CRA requirements.

Click to read the entire article at Mouser

Author

Since graduating with a BSc in Electronic Systems from the University of the West of Scotland in 1997, Alistair Winning has worked in electronics media across marketing, PR, and journalism roles. During that time, he worked as the editor of Electronics Engineering, Embedded Systems Europe, EENews Embedded, Technology First, Electronic Product Design and Test, and Panel Building and Systems Integration magazines. Currently, Allistair is the European Editor of Power Systems Design and a freelance writer, specializing in electronics and engineering.

[1] https://www.cyberresilienceact.eu/explained.html
[2] https://www.digi.com/blog/post/cyber-resilience-act
[3] https://www.cyberresilienceact.eu/annexes.html
[4] https://www.cyberresilienceact.eu/annexes.html
[5] https://www.digi.com/blog/post/cyber-resilience-act
[6] https://www.cyberresilienceact.eu/reporting.html
[7]  https://www.mouser.com/en/new/digi-international/digi-cyber-resilience-act-solutions
[8] https://www.mouser.com/pdfDocs/complying-with-the-cyber-resilience-act-cra-wp.pdf
[9] https://www.mouser.com/en/new/digi-international/digi-cyber-resilience-act-solutions
[10] https://www.mouser.com/pdfDocs/complying-with-the-cyber-resilience-act-cra-wp.pdf

DIGI is a leading global provider of mission-critical machine-to-machine (M2M) and Internet of Things (IoT) connectivity products and services. DIGI helps customers create next-generation connected products and deploy and manage critical communications infrastructures.

 

Sign up for our eNewsletters
Get the latest news and updates