EU’s Official CRA Guidance: What Connected Product Makers Need to Know
The European Commission has officially released its guidance to support the implementation of the Cyber Resilience Act (CRA).
For connected product manufacturers, development teams, and GRC leads, this non-binding official guidance provides much-needed clarity on how the EU plans to enforce product cybersecurity across the full device lifecycle. The guidance arrives just in time to help engineering and compliance teams align their product roadmaps. The full CRA enforcement is only 5 quarters away.
Here is a breakdown of the key takeaways from the Commission’s release and what it means for your automated compliance strategy.
Key Takeaways from the Commission's Guidance
1. Clear Scope for Connected Services & Remote Data Processing
One of the most frequent questions from connected product manufacturers has been where the "product" ends and the "cloud service" begins. The guidance sets out a practical test: if remote data processing is performed at a distance, is designed/developed by or under the responsibility of the manufacturer, and its absence would prevent the product from performing one of its core functions, it falls within the scope of the CRA.
What this means for IoT: You cannot decouple your device firmware from its backend APIs or companion mobile apps when assessing CRA compliance. Your end-to-end stack must be secure.
2. Defining a "Substantial Modification"
Under the CRA, if you make a "substantial modification" to a product already on the market, it must be re-evaluated for compliance. The guidance clarifies that modifications affecting the product's overall security posture or fundamental functionality trigger reassessment.
What this means for IoT: Regular security patches or minor bug fixes shouldn't trigger a full re-certification—provided your automated testing pipeline proves that the core security architecture hasn't regressed.
3. Support Periods: 5 Years is the Floor, Not the Ceiling
The guidance reaffirms that the minimum support period during which manufacturers must handle vulnerabilities is 5 years—unless the product’s expected lifespan is shorter. If a device is expected to remain in industrial or consumer operation longer (e.g., smart meters, industrial controllers, smart home gateways), the support period must reflect that extended reality.
What this means for IoT: "Ship and forget" is officially over in the EU. Manufacturers must maintain continuous vulnerability monitoring, active Software Bill of Materials (SBOM) tracking, and over-the-air (OTA) patching capabilities throughout the product's operational lifespan.
4. Open-Source Software (FOSS) Rules Defined
The guidance details the lighter regime for Free and Open Source Software (FOSS). While purely non-commercial open-source projects outside commercial activities are largely exempt, integrating open-source components into a commercial IoT product places the compliance burden squarely on the commercial manufacturer.
What this means for IoT: If your firmware relies on Linux kernels, open-source protocol stacks, or third-party libraries, you are responsible for auditing and continuously monitoring those components for newly discovered CVEs.
5. Practical Support for SMEs (67 Real-World Examples)
Recognizing that compliance can place an overwhelming administrative burden on smaller engineering teams, the Commission included 67 practical examples, use cases, flowcharts, and graphs to simplify risk assessment and reporting duties.
How Test of Things Keeps You CRA-Compliant 24/7
Manual, consultant-heavy compliance audits are too slow and expensive to keep up with evolving CRA requirements. The EU’s guidance makes it clear that security and vulnerability management must be continuous across the entire lifecycle.
With Test of Things, you can automate your CRA, IEC 62443, EN 18031 or upcoming EN 40000 standard compliance workflows directly in your engineering pipeline:
Automated Security Testing: Run continuous automated security scans across end-to-end IoT attack surfaces, mobile apps, and cloud backends.
Real-Time SBOM Lifecycle Tracking: Automatically identify third-party components and monitor them for newly disclosed vulnerabilities.
Instant Gap Analysis: Map your current security posture against CRA mandates to generate audit-ready documentation in minutes.
Continuous Compliance Monitoring: Stay compliant 24/7—not just on launch day.
Don't wait until the September 2026 reporting deadline to structure your compliance strategy.