< Back to all clusters
[TECHNOLOGY] · Germany, United Kingdom · 5 sources

started · updated

EU Cyber Resilience Act Regulation Tightens IoT Security Requirements

The European Union’s Cyber Resilience Act (CRA), together with the Radio Equipment Directive (RED) and similar proposals such as the United Kingdom’s Cyber Security and Resilience Bill, imposes mandatory security‑by‑design, secure‑over‑the‑air updates and lifecycle‑management obligations on most connected devices sold in the EU. The rules aim to reduce vulnerabilities in the expanding Internet‑of‑Things and edge‑device market.

To aid manufacturers, developers and especially small and medium‑sized enterprises, the European Commission has issued practical, non‑binding guidance outlining how to interpret the scope of the CRA, what constitutes a substantial modification, reporting duties and risk‑assessment procedures. The guidance includes flowcharts, examples and use‑case diagrams, and points to compliance deadlines: reporting obligations start on 11 September 2026, with full CRA requirements taking effect on 11 December 2027.

Entities

Cyber Resilience Act · European Commission · Internet of Things · Radio Equipment Directive · United Kingdom Government