For IoT and hardware makers ยท Regulation (EU) 2024/2847

What the CRA means for small IoT and hardware makers

Verified against the Official Journal text on

You are almost certainly in scope. A hardware product with software that can connect, directly or indirectly, to a device or network is a product with digital elements under the CRA (Art. 3(1), Art. 2(1)). As its manufacturer you carry the full programme: essential requirements, vulnerability handling with firmware updates across a support period, technical documentation, conformity assessment, CE marking, and reporting (Art. 13, Art. 14). Several common device types (smart home devices, connected toys, wearables, routers) sit in the important categories of Annex III, which narrows your conformity route (Art. 7). If you make devices outside the EU, your EU importer will demand your paperwork (Art. 19).

Basis: Art. 2(1), Art. 3(1), Art. 13, Art. 7, Art. 19

Connected hardware is in scope Art. 2(1), Art. 3(1), Art. 3(2)

The CRA covers software and hardware products with a direct or indirect data connection to a device or network (Art. 2(1), Art. 3(1)). Indirect counts: a sensor that talks to a hub, or a device that syncs through a phone app, is connected for these purposes (Art. 3(10)). Very few modern IoT or smart devices fall outside that.

The software in your device, its firmware, is the regulated part alongside the hardware. If a cloud backend you provide is needed for the device to perform a function, that backend is in scope with it as a remote data processing solution (Art. 3(2), Recital 12).

The annex categories that commonly bite Art. 7, Annex III

Check your device's core functionality against Annex III. Several everyday consumer categories are listed as important products, which restricts your conformity route beyond plain self-assessment (Art. 7, Art. 32(2)). Merely including a listed component does not by itself put the whole device in the category (Art. 7(1)), but a device whose core function is a listed one does.

  • Smart home assistants and smart home products with security functionality. (Annex III)
  • Internet-connected toys with social interaction or location tracking features. (Annex III)
  • Wearables with a health monitoring purpose (where the medical device rules do not apply; if they do, the product is excluded from the CRA entirely), and wearables for children. (Annex III Class I (19), Art. 2(2))
  • Routers, modems intended for the connection to the internet, and switches, with no limit to home or small office equipment. (Annex III Class I (12))

Support period and firmware updates Art. 13(8), Art. 13(9), Art. 13(19)

You must handle vulnerabilities effectively across a support period, and for hardware that means shipping firmware security updates for its duration (Art. 13(8), Annex I Part II). Set the support period to reflect how long the device is expected to be in use; it must be at least five years unless the device is used for less (Art. 13(8)).

Two practical duties follow. Security updates must remain available for at least ten years after issue, or the rest of the support period if longer (Art. 13(9)). And the end date of the support period must be stated clearly at the time of purchase (Art. 13(19)), which for physical products means planning packaging and listings around it.

If you manufacture outside the EU Art. 19(1), Art. 19(2), Art. 18

A non-EU maker still carries the manufacturer obligations for products placed on the EU market. In practice, the EU-based importer who brings your device in cannot place it on the market unless it is compliant, and must verify that you carried out the conformity assessment, drew up the technical documentation, and affixed the CE marking (Art. 19(1), Art. 19(2)).

That makes your paperwork the importer's gating item. Expect to hand over the declaration of conformity, technical documentation, and support-period information, or the importer legally cannot ship your product. Appointing an authorised representative in the EU can smooth this (Art. 18).

What you must do

  • Design, develop, and produce the device to the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Ship firmware security updates and handle vulnerabilities across the support period, keeping updates available for at least ten years or the support period if longer. (Art. 13(8), Art. 13(9), Annex I Part II)
  • State the support-period end date clearly at the time of purchase, and check your category against Annex III before choosing a conformity route. (Art. 13(19), Art. 7, Annex III)
  • Draw up technical documentation, carry out conformity assessment, affix the CE marking, and report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 13(12), Art. 14, Art. 32)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Our device only connects through a phone app. Is it still in scope?

Yes. An indirect connection, such as reaching a network through another device or an app, is enough to bring a product into scope. A device that syncs or is controlled through a companion app is a connected product with digital elements. (Art. 2(1), Art. 3(10))

How long must we provide firmware updates?

Across the support period, which must be at least five years unless the device is expected to be in use for less. Separately, each security update you issue must stay available for at least ten years after issue, or the rest of the support period if that is longer. (Art. 13(8), Art. 13(9))

We manufacture outside the EU. Who deals with the CRA?

You still carry the manufacturer obligations, and your EU importer cannot place the device on the market unless it is compliant. The importer must verify your conformity assessment, technical documentation, and CE marking, so they will require that paperwork from you. (Art. 19(1), Art. 19(2))

When do the duties apply?

Reporting duties for actively exploited vulnerabilities and severe incidents start 11 September 2026. The full obligations, including conformity assessment and CE marking, apply from 11 December 2027. (Art. 71(2))

Check your device category, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes and flags whether your device looks default-category or lands in an important Annex III class.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.