What OEMs Need to Know About the Cyber Resilience Act

What Manufacturers Need to Know About The Cyber Resilience Act

09/17/2026 | Jeremy Stacy | 3 Min Read

Cybersecurity expectations for connected IoT devices.

The European Union’s Cyber Resilience Act (CRA) introduced broad cybersecurity requirements for products with digital elements placed on the EU market. As of September 11, 2026, manufacturers are subject to the CRA's mandatory reporting requirements for actively exploited vulnerabilities and severe security incidents. The CRA's broader cybersecurity requirements become fully applicable on December 11, 2027. For device manufacturers, this represents a significant shift in how connected products are designed, maintained, documented, and supported throughout their lifecycle.

Most manufacturers understand why security matters. The challenge is implementing it efficiently while continuing to innovate and deliver products on schedule.

That is why the choice of wireless platforms and silicon providers is so critical.

Silicon Labs views the CRA, as well as the other cybersecurity regulations emerging around the world as a welcome supplement to boosting the safety of the IoT devices consumers rely on. We think that building strong security foundations simplifies CRA readiness while enabling manufacturers to build more trustworthy, connected devices from the start.

the cyber Resilience Act Places New Emphasis Diagram

CRA is Raising the Baseline for Connected IoT Device Security

Historically, product security expectations varied significantly across industries and markets.

The CRA changes that dynamic by establishing cybersecurity obligations that apply broadly across connected devices entering the EU market. Manufacturers must now manage cybersecurity throughout the product lifecycle, not just at the time of release.

These responsibilities include:

  • Managing cybersecurity risks
  • Providing secure software updates
  • Handling vulnerabilities responsibly
  • Maintaining technical documentation
  • Supporting coordinated vulnerability disclosure
  • Delivering appropriate security information to users

These requirements reinforce an important reality.

Security is no longer simply an engineering feature. It’s becoming part of product quality, operational resilience, and supply chain accountability.


Security Readiness Starts Before Full CRA Applicability

Preparing for CRA compliance touches multiple parts of an organization, including hardware architecture, firmware development, software maintenance, documentation, security governance, and incident response processes.

Addressing these requirements late in development can create unnecessary redesigns and operational burdens.

That is why Silicon Labs approaches security as a lifecycle capability rather than a standalone compliance task.

Our security practices include risk-based security assessments, secure product development, ongoing SDK maintenance and patching, product security governance, customer security guidance, and established vulnerability disclosure processes.

Silicon Labs also maintains a Product Security Incident Response Team (PSIRT) and a coordinated vulnerability disclosure program to support responsible vulnerability handling and communication.

As a CVE Numbering Authority (CNA) with MITRE since 2021, Silicon Labs can directly assign and publish CVEs, supporting transparency and timely disclosure practices aligned with evolving industry expectations.


Why Wireless Platform Selection Matters for CRA Readiness

Under the CRA, both Silicon Labs and device manufacturers are responsible for the products they place on the EU market. Silicon Labs is responsible for meeting applicable CRA requirements for its own products, while manufacturers of finished devices remain responsible for the compliance of their end products.

Choosing a secure hardware and software platform can make it easier to implement important cybersecurity capabilities, including:

  • Secure boot
  • Secure firmware updates
  • Cryptographic key management
  • Software component visibility
  • Vulnerability remediation workflows

This is where integrated security technologies provide an advantage.

Silicon Labs Secure Vault™ technology is designed to provide advanced hardware-based security protections that can help developers build stronger security architectures while reducing implementation complexity.

Silicon Labs Secure Vault Technology diagram

Transparency and Lifecycle Support Are Becoming Essential to CRA in IoT

The CRA also reinforces the importance of long-term product maintenance and transparency.

Manufacturers need visibility into software dependencies, known vulnerabilities, available updates, and security support throughout the supported life of a product.

Silicon Labs supports these needs through software maintenance practices, security documentation, vulnerablity disclosure processes, and development tools that can help customers understand and manage the software components used in their products.

Transparency and Lifecycle Support Diagram

These capabilities can help development teams strengthen internal security management processes and support broader CRA compliance efforts.


Independent Validation and Security Certifications Matter

As cybersecurity requirements become more formalized, independent security validation becomes increasingly valuable.

Silicon Labs has achieved several recognized security certifications and milestones, including:

  • The world’s first PSA Certified Level 4 for Secure Vault Series 3
  • The world’s first SESIP/PSA Level 3 achievements
  • ISO 27001:2022 certification

These certifications help demonstrate adherence to recognized security practices and provide additional confidence for customers building devices in regulated markets.


CRA Readiness Is Ultimately About Trust

The CRA reflects a broader industry transition toward more trustworthy connected IoT devices. Products that can be securely deployed, updated, maintained, and supported over time.

Manufacturers need technology partners that understand both the technical realities of embedded security and the operational demands of long-term product lifecycle management.

Silicon Labs continues to invest in secure wireless platforms, lifecycle security processes, vulnerability management practices, and customer enablement resources to help developers meet evolving security requirements.

In the next generation of connected products, robust security will increasingly define product quality and market readiness.

CATEGORIES: Security
Jeremy Stacy
Jeremy Stacy
Product Marketing Manager
Close
Loading Results
Close