← Back to all articles
Regulatory

Cyber Resilience Act (CRA): What OEMs and embedded teams need now

July 2026·7 min min read

The Cyber Resilience Act covers products with digital elements — from MCU/PLC and edge gateways to connected drives. Manufacturers need security by design, documented risk handling, and from 2026/2027 hard reporting and CE-linked duties.

Typical questions

  • Am I a “manufacturer” under the CRA?
  • Do I need an SBOM (Art. 13) even for legacy firmware?
  • What does the 24h / 72h / 14-day reporting chain mean in practice?
  • How does CRA connect to existing CE/EMC processes?

What we do

Solvetronix is not a notified body. We support technical and documentary readiness: gap analysis, firmware/OTA security measures, SBOM path, prep for lab/audit iterations — tied into your CE/EMC process.

Key dates (orientation): CRA in force since 10 Dec 2024; reporting from 11 Sep 2026; fuller application from 11 Dec 2027 among other milestones.

CRA Embedded service · First assessment (Contact) · Overview: Regulatory & certification

Bottom line

Regulatory and certification topics are engineering topics with deadlines. Structuring early saves lab loops and compliance downtime.

Which situation describes you?

Operator or OEM — we review your case in a free 30‑minute call.

Request a free assessment
Reply within 24 hours No commitment Confidential