Cyber Resilience Act and product security
A practical engineering series on the EU Cyber Resilience Act (CRA) for manufacturers of connected hardware, embedded systems, IoT, and smart-city products — what it asks for, and how hardware-backed trust such as the AmbiSEC secure module supports CRA-aligned architecture. These articles support CRA readiness; they are not legal or conformity advice.
Cyber resilience is the ability of a connected product to keep operating, and recover, under attack — and increasingly a regulatory obligation. The EU Cyber Resilience Act (CRA) makes secure-by-design, vulnerability handling, and lifecycle security mandatory for products with digital elements sold in the EU. Resilience is broader than prevention: it assumes compromise will be attempted and asks how the device detects, contains, and recovers.
This category covers CRA readiness, secure-by-design architecture, vulnerability disclosure and handling, and how a hardware root of trust underpins update integrity and attestation across a product's supported lifetime. The through-line is that resilience is designed in at the silicon and provisioning stages, not bolted on before shipping.
Articles tagged Cyber Resilience
EU Cyber Resilience Act: What It Means for Connected Hardware and IoT Manufacturers
Products with digital elements, secure-by-design, lifecycle maintenance, vulnerability handling, and the 2026–2027 deadlines.
Secure by Design Under the CRA: Why Hardware-Backed Trust Matters
The threat model behind secure-by-design — and where a hardware root of trust like AmbiSEC fits a CRA-aligned architecture.
CRA Vulnerability Handling and Product Lifecycle Security: What Manufacturers Need to Prepare
Reporting from 11 Sep 2026, support periods, disclosure, updates — and how secure elements support rotation, identity, and controlled updates.
Mapping AmbiSecure Products to CRA Readiness: AmbiSEC, ONE Pass, BioKey and Secure Identity
A product-mapping table from CRA-aligned needs to AmbiSecure building blocks — AmbiSEC, FIDO, ONE Pass, BioKey, and secure-element credentials.
Frequently asked questions
What does the Cyber Resilience Act require?
The CRA requires products with digital elements to be secure by design, ship without known exploitable vulnerabilities, provide security updates for a defined support period, and operate a coordinated vulnerability-handling process. Conformity must be demonstrated and documented.
How does a hardware root of trust support resilience?
A hardware root of trust anchors secure boot, verifies firmware signatures before execution, and protects update and attestation keys, so a device can prove its state and reject tampered updates even after a software compromise attempt.
Is vulnerability handling a one-time task?
No. It is a lifecycle obligation: monitoring for new vulnerabilities, issuing signed updates, and communicating with users for the whole supported period, not just at launch.
When do the Cyber Resilience Act obligations take effect?
Vulnerability-handling and reporting duties begin from 11 September 2026, ahead of the wider obligations. The posts in this category cover what manufacturers need in place before that date.
What is a support period and why must it be declared?
It is the length of time a manufacturer commits to providing security updates for a product. Declaring it makes the maintenance obligation explicit to buyers rather than leaving it to be discovered after deployment.