Cyber Resilience Act for embedded systems

CRA Requirements for embedded systems

The Cyber Resilience Act (CRA) introduces cybersecurity requirements for products with digital elements placed on the EU market. For companies developing embedded products and systems, these requirements need to be considered throughout the product lifecycle – from initial development to maintenance and vulnerability management.

The first CRA reporting obligations apply from 11 September 2026. 

Cyber Resilience Act timeline from 2024 to 2027

Does the CRA apply to your embedded product?

If your product contains hardware or software with a direct or indirect data connection to another device or network and is made available on the EU market, it will generally fall within the scope of the Cyber Resilience Act.

For an embedded project, CRA requirements can be relevant not only to the final product, but also to hardware and software components placed separately on the market.

There are, however, exceptions. Certain products covered by specific EU legislation – including medical devices, automotive products, certified aviation products and marine equipment – fall outside the scope of the CRA. Products developed exclusively for national security or defence purposes are also excluded.

CRA throughout product development

CRA requirements need to be considered from the beginning of product development, rather than addressed only when the final product is ready to enter the market.

For an embedded product, this means considering cybersecurity throughout the design and development process from hardware and components to the BSP, software and final application. Cybersecurity risks related to the product and third-party components need to be assessed and taken into account during development.

Software maintenance, security updates, vulnerability management and the expected support period should also be considered during development, ensuring that cybersecurity can be managed throughout the product lifecycle.

CRA responsibilities after product delivery

Cyber security responsibilities continue after a product has been placed on the market. In an embedded product, vulnerabilities can originate at different levels of the solution – from individual hardware and software components to the embedded platform, BSP and customer application.

Every manufacturer is responsible for meeting the applicable CRA requirements for the product with digital elements it places on the market. In an embedded project, responsibilities can therefore exist at several levels of the supply chain.

Hectronic can take responsibility for agreed parts of the embedded platform, while the customer remains responsible for the final product, including the software, application and additional functionality it integrates.

Responsibilities for vulnerability monitoring, maintenance, security updates and communication should therefore be clearly defined between the parties. If a vulnerability is identified in one part of the solution, information may need to be passed through the supply chain so that the affected parties can assess the impact and take appropriate action. A Cyber Security Sub-Supplier Agreement (CSSA) can be used to clarify how these responsibilities are assigned to the involved parties.

From 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe security incidents affecting their products. Notifications are submitted through the CRA Single Reporting Platform (SRP).

Embedded product supply chain from component suppliers to product manufacturer

How Hectronic can support your embedded project

At Hectronic, we have adapted our development processes to address CRA requirements from both a technical and administrative perspective. We consider cybersecurity, documentation, vulnerability management and long-term support as part of the development process.

Our experience in embedded computing includes platforms for products with long lifecycles, demanding operating environments and industry-specific certification requirements. This provides a strong foundation for addressing security and lifecycle requirements in embedded projects.

Depending on the project, we can provide the embedded hardware platform, hardware together with a BSP, and agreed services for software maintenance and vulnerability monitoring.

Developing an embedded product?

Whether you are evaluating a new platform or developing an existing product, our team can help you find the right solution.

Sources and further reading

Request a starter kit

Fill in your details and we'll get back to you shortly.