CRA, RED, and CS&R Regulations to Secure the Connected World

By Francesco Vaiani* | Translated by AI 6 min Reading Time

Regulations such as the EU's Cyber Resilience Act and Radio Equipment Directive or the proposed Cyber Security and Resilience Bill in the UK tighten the requirements for connected products. Security by Design, SBOMs, secure updates, and consistent lifecycle management are more important than ever before.

Cybersecurity: The Cyber Resilience Act (CRA), the Radio Equipment Directive (RED), and other regulations make Security by Design, OTA updates, and consistent compliance mandatory for connected devices.(Image: Dall-E / AI-generated)
Cybersecurity: The Cyber Resilience Act (CRA), the Radio Equipment Directive (RED), and other regulations make Security by Design, OTA updates, and consistent compliance mandatory for connected devices.
(Image: Dall-E / AI-generated)

With the increasing number of Internet of Things (IoT) and edge devices, potential security vulnerabilities in distributed networks of electronic systems are rising dramatically. To protect their connected devices, companies require effective cybersecurity measures to ensure uninterrupted operations, secure data, and protect application users worldwide. However, as threats constantly evolve, global regulations are also advancing to enforce stricter security standards.

Pioneers of this change are the Cyber Resilience Act (CRA) and the Radio Equipment Directive (RED) of the European Union (EU). These standards establish comprehensive minimum cybersecurity requirements that shape global practices in the development of digital and wireless products.

Many companies face significant challenges as they must adapt their business strategies to comply with the new regulations. These will apply to most connected devices sold in the EU. Similar guidelines have been proposed or already enacted in other regions; an example is the "Cyber Security and Resilience (CS&R) Bill" proposed in the United Kingdom.

Increasing Attacks on Infrastructure

Cybersecurity involves protecting devices, networks, firmware, and data from external threats. The primary goal of implementing cybersecurity in IoT applications is to prevent disruptions that could jeopardize operations, safety, or regulatory compliance. However, flaws in devices, outdated firmware, or insecure communication protocols can provide attackers with easy access, allowing them to build botnets, steal data, or gain unauthorized control.

The Mirai botnet, for example, brought hundreds of thousands of unprotected IoT devices under its control and overwhelmed targets with large-scale distributed denial-of-service attacks. More recent threats, such as the Matrix botnet, followed the same pattern, compromising everything from home routers to telecommunications devices to IP cameras. Both cases demonstrate that vulnerabilities in individual devices are sufficient to compromise a company's global Internet infrastructure or expose sensitive personal and business data to third parties.

To exploit this, modern attackers increasingly rely on automation to identify and exploit vulnerabilities in large networks. The rise of AI-driven cyberattacks exacerbates this issue by creating more sophisticated and harder-to-detect threats. To counter this, companies must integrate cybersecurity into their devices from the outset and make "Security by Design" (SbD) a core element of their strategy.

Requirements of the EU Cyber Resilience Act

The Cyber Resilience Act, which originally came into force on December 10, 2024, marked a significant regulatory shift by establishing new cybersecurity requirements for almost all digital products sold in the EU.

Image 1: In general, all obligations under the CRA apply from December 11, 2027, but certain provisions come into force as early as 2025 and affect both hardware and software aspects of cybersecurity.(Image: Seco)
Image 1: In general, all obligations under the CRA apply from December 11, 2027, but certain provisions come into force as early as 2025 and affect both hardware and software aspects of cybersecurity.
(Image: Seco)

While most obligations under the CRA take effect on December 11, 2027, some aspects of the initiative will come into force significantly earlier. For example, manufacturers will be required, starting September 11, 2026, to report actively exploited vulnerabilities and severe incidents to EU authorities within 24 hours. This regulation also mandates that companies develop products according to SbD principles, manage vulnerabilities throughout the entire product lifecycle, provide timely security updates, and maintain comprehensive technical documentation, including a Software Bill of Materials (SBOM).

The CRA also intensifies cybersecurity measures by targeting the entire product supply chain, spanning manufacturers, importers, and distributors. By establishing cybersecurity as a shared regulatory responsibility among these parties, the measure effectively ensures compliance with the regulations. This, in turn, is a key requirement for obtaining the CE marking, which is necessary for a product's legal entry into the EU market.

Image 2: Comparison of the advantages of complying with the CRA versus the risks of non-compliance.(Image: Seco)
Image 2: Comparison of the advantages of complying with the CRA versus the risks of non-compliance.
(Image: Seco)

The consequences of non-compliance are severe. Depending on the violation, companies face hefty fines of up to 15 million euros or 2.5% of their global annual turnover, whichever is higher. Product bans and recalls are another aspect of this broader picture. In light of these challenges, successful implementation of the CRA principles translates to enhanced customer trust and reduced legal and reputational risks.

In the age of the CRA, products are classified as “standard,” “important” (Class I and Class II), or “critical” and require strict conformity assessments. These categories include essential devices and software that are crucial for modern infrastructure, such as:

Subscribe to the newsletter now

Don't Miss out on Our Best Content

By clicking on „Subscribe to Newsletter“ I agree to the processing and use of my data according to the consent form (please expand for details) and accept the Terms of Use. For more information, please see our Privacy Policy. The consent declaration relates, among other things, to the sending of editorial newsletters by email and to data matching for marketing purposes with selected advertising partners (e.g., LinkedIn, Google, Meta)

Unfold for details of your consent
  • Routers, modems, and firewalls;
  • Industrial control systems and IoT gateways;
  • Operating systems, hypervisors, and container runtime systems;
  • Identity management systems and privileged access software; or
  • Internet-enabled toys and wearables

Additional Requirements: Radio Equipment Directive (RED) and EN 18031

Parallel to the CRA, the EU has also tightened cybersecurity regulations under its Radio Equipment Directive (Directive 2014/53/EU). This regulation applies to all products sold in the EU that are specifically designed to transmit or receive radio signals, such as Wi-Fi, LTE, or Bluetooth.

Furthermore, with Delegated Regulation (EU) 2022/30, effective August 1, 2025, the scope of mandatory cybersecurity requirements for manufacturers has been expanded, and their devices must now meet the following requirements:

  • Protect networks from unauthorized access;
  • Protect personal data and the privacy of users; and
  • Prevent fraud in digital communication

To simplify compliance with the regulations, the harmonized standard EN 18031 was developed, which establishes a presumption of conformity for the cybersecurity requirements of the RED and defines its technical specifications. These include secure boot, access control, encrypted communication, and digitally signed firmware updates. However, this conformity must be ensured at the end-product level, not merely at the module level.

Cybersecurity as a Core Competency

Given the increasing number of CRA and RED regulations coming into effect, cybersecurity for embedded systems and OEMs is no longer optional but a fundamental requirement. For engineers, this means that security design and risk analysis must take place early in the development process.

Beyond product development, lifecycle management and maintaining operational compliance are crucial. Manufacturers must continuously monitor for new vulnerabilities to promptly provide patches and inform authorities within the mandated 24-hour window about severe incidents. To achieve this, embedded systems require robust update mechanisms, encrypted communication, and hardened firmware. Since supply chains are also held accountable for violations, each component supplier must prove that their parts meet the required standards. Otherwise, end products cannot be certified for legal entry into the EU market, underscoring the importance of early implementation of cybersecurity measures for all parties involved.

Embedded Ecosystems to Support Cybersecurity

To efficiently meet these growing regulatory requirements, developers benefit from using a comprehensive ecosystem of hardware, software, and tools specifically designed for embedded applications. The Seco Clea platform, for example, follows an SbD philosophy and provides fundamental mechanisms such as secure boot, encrypted communication, and signed firmware, while also enabling comprehensive product lifecycle management.

Image 3: The Seco Clea ecosystem includes a wide range of tools, hardware, and software that enable developers to easily equip their products with the required cybersecurity measures to comply with modern regulations.(Image:  Seco)
Image 3: The Seco Clea ecosystem includes a wide range of tools, hardware, and software that enable developers to easily equip their products with the required cybersecurity measures to comply with modern regulations.
(Image: Seco)

A key element in ensuring compliance is the infrastructure for over-the-air updates (OTA), which ensures timely, reliable, and traceable delivery of software and firmware updates. By providing regular security patches and quickly addressing exploited vulnerabilities, the Clea ecosystem helps manufacturers meet their legal obligations. Additionally, it facilitates the creation and management of essential SBOMs for CE compliance and audits.

The ecosystem goes a step further by integrating monitoring, reporting, and compliance tools that enable centralized monitoring of device fleets, early detection of anomalies, and the recording and reporting of incidents. Such features optimize the workflows of OEMs, resulting in reduced regulatory risks and increased trust among customers and partners who share the responsibility for compliance.

Integration into Existing Systems

The integration of the Clea ecosystem into an existing embedded system begins with the use of SDKs, APIs, and agents for various hardware and software platforms and their incorporation into existing system stacks. This is possible without redesigning the core architecture and enables secure communication, device authentication, and lifecycle management from the early development stages.

The next step involves connecting the ecosystem to a cloud, such as Seco's cloud services, where dashboards and connectors enable access to monitoring, update, and compliance functions. These cloud platforms support standardized protocols and can be integrated into existing development and deployment workflows to ensure scalability across large, heterogeneous device fleets.

To simplify operations, Clea also offers DevOps and additional security tools for the automated creation of SBOMs, vulnerability scans, logging, and reporting. This allows teams to meet documentation and audit requirements directly within their toolchains, reducing manual effort and shortening time-to-market for compliant products.

Cybersecurity is becoming a central requirement for embedded systems and OEMs seeking access to the EU market with the introduction of CRA and RED. "Security by Design," continuous lifecycle management, complete SBOM documentation, and rapid incident response are now mandatory. Developers must therefore embed security at the architectural level. At the same time, OEMs enforce compliance across their entire supply chain.

The Seco Clea ecosystem provides a practical solution to this challenge, encompassing integrated security features, a robust OTA infrastructure, monitoring and reporting services, and automation tools for documentation and audits. This not only reduces regulatory risks but also strengthens trust in the products. In this way, OEMs can ensure continuous compliance and maintain their competitive and security advantages in this new era of cybersecurity regulations.

*Francesco Vaiani is Senior Product Manager at Seco.