Cyber Resilience Act (CRA): What OEMs and embedded teams need now
The Cyber Resilience Act covers products with digital elements — from MCU/PLC and edge gateways to connected drives. Manufacturers need security by design, documented risk handling, and from 2026/2027 hard reporting and CE-linked duties.
Typical questions
- Am I a “manufacturer” under the CRA?
- Do I need an SBOM (Art. 13) even for legacy firmware?
- What does the 24h / 72h / 14-day reporting chain mean in practice?
- How does CRA connect to existing CE/EMC processes?
What we do
Solvetronix is not a notified body. We support technical and documentary readiness: gap analysis, firmware/OTA security measures, SBOM path, prep for lab/audit iterations — tied into your CE/EMC process.
Key dates (orientation): CRA in force since 10 Dec 2024; reporting from 11 Sep 2026; fuller application from 11 Dec 2027 among other milestones.
CRA Embedded service · First assessment (Contact) · Overview: Regulatory & certification
Bottom line
Regulatory and certification topics are engineering topics with deadlines. Structuring early saves lab loops and compliance downtime.