CRA, RED, and CS&RRegulations to Secure the Connected World
By
Francesco Vaiani* | Translated by AI
6 min Reading Time
Regulations such as the EU's Cyber Resilience Act and Radio Equipment Directive or the proposed Cyber Security and Resilience Bill in the UK tighten the requirements for connected products. Security by Design, SBOMs, secure updates, and consistent lifecycle management are more important than ever before.
Cybersecurity: The Cyber Resilience Act (CRA), the Radio Equipment Directive (RED), and other regulations make Security by Design, OTA updates, and consistent compliance mandatory for connected devices.
(Image: Dall-E / AI-generated)
With the increasing number of Internet of Things (IoT) and edge devices, potential security vulnerabilities in distributed networks of electronic systems are rising dramatically. To protect their connected devices, companies require effective cybersecurity measures to ensure uninterrupted operations, secure data, and protect application users worldwide. However, as threats constantly evolve, global regulations are also advancing to enforce stricter security standards.
Pioneers of this change are the Cyber Resilience Act (CRA) and the Radio Equipment Directive (RED) of the European Union (EU). These standards establish comprehensive minimum cybersecurity requirements that shape global practices in the development of digital and wireless products.
Many companies face significant challenges as they must adapt their business strategies to comply with the new regulations. These will apply to most connected devices sold in the EU. Similar guidelines have been proposed or already enacted in other regions; an example is the "Cyber Security and Resilience (CS&R) Bill" proposed in the United Kingdom.
Cybersecurity involves protecting devices, networks, firmware, and data from external threats. The primary goal of implementing cybersecurity in IoT applications is to prevent disruptions that could jeopardize operations, safety, or regulatory compliance. However, flaws in devices, outdated firmware, or insecure communication protocols can provide attackers with easy access, allowing them to build botnets, steal data, or gain unauthorized control.
The Mirai botnet, for example, brought hundreds of thousands of unprotected IoT devices under its control and overwhelmed targets with large-scale distributed denial-of-service attacks. More recent threats, such as the Matrix botnet, followed the same pattern, compromising everything from home routers to telecommunications devices to IP cameras. Both cases demonstrate that vulnerabilities in individual devices are sufficient to compromise a company's global Internet infrastructure or expose sensitive personal and business data to third parties.
To exploit this, modern attackers increasingly rely on automation to identify and exploit vulnerabilities in large networks. The rise of AI-driven cyberattacks exacerbates this issue by creating more sophisticated and harder-to-detect threats. To counter this, companies must integrate cybersecurity into their devices from the outset and make "Security by Design" (SbD) a core element of their strategy.
Image 1: In general, all obligations under the CRA apply from December 11, 2027, but certain provisions come into force as early as 2025 and affect both hardware and software aspects of cybersecurity.
(Image: Seco)
While most obligations under the CRA take effect on December 11, 2027, some aspects of the initiative will come into force significantly earlier. For example, manufacturers will be required, starting September 11, 2026, to report actively exploited vulnerabilities and severe incidents to EU authorities within 24 hours. This regulation also mandates that companies develop products according to SbD principles, manage vulnerabilities throughout the entire product lifecycle, provide timely security updates, and maintain comprehensive technical documentation, including a Software Bill of Materials (SBOM).
The CRA also intensifies cybersecurity measures by targeting the entire product supply chain, spanning manufacturers, importers, and distributors. By establishing cybersecurity as a shared regulatory responsibility among these parties, the measure effectively ensures compliance with the regulations. This, in turn, is a key requirement for obtaining the CE marking, which is necessary for a product's legal entry into the EU market.
Image 2: Comparison of the advantages of complying with the CRA versus the risks of non-compliance.
(Image: Seco)
The consequences of non-compliance are severe. Depending on the violation, companies face hefty fines of up to 15 million euros or 2.5% of their global annual turnover, whichever is higher. Product bans and recalls are another aspect of this broader picture. In light of these challenges, successful implementation of the CRA principles translates to enhanced customer trust and reduced legal and reputational risks.
In the age of the CRA, products are classified as “standard,” “important” (Class I and Class II), or “critical” and require strict conformity assessments. These categories include essential devices and software that are crucial for modern infrastructure, such as:
Date: 08.12.2025
Naturally, we always handle your personal data responsibly. Any personal data we receive from you is processed in accordance with applicable data protection legislation. For detailed information please see our privacy policy.
Consent to the use of data for promotional purposes
I hereby consent to Vogel Communications Group GmbH & Co. KG, Max-Planck-Str. 7-9, 97082 Würzburg including any affiliated companies according to §§ 15 et seq. AktG (hereafter: Vogel Communications Group) using my e-mail address to send editorial newsletters. A list of all affiliated companies can be found here
Newsletter content may include all products and services of any companies mentioned above, including for example specialist journals and books, events and fairs as well as event-related products and services, print and digital media offers and services such as additional (editorial) newsletters, raffles, lead campaigns, market research both online and offline, specialist webportals and e-learning offers. In case my personal telephone number has also been collected, it may be used for offers of aforementioned products, for services of the companies mentioned above, and market research purposes.
Additionally, my consent also includes the processing of my email address and telephone number for data matching for marketing purposes with select advertising partners such as LinkedIn, Google, and Meta. For this, Vogel Communications Group may transmit said data in hashed form to the advertising partners who then use said data to determine whether I am also a member of the mentioned advertising partner portals. Vogel Communications Group uses this feature for the purposes of re-targeting (up-selling, cross-selling, and customer loyalty), generating so-called look-alike audiences for acquisition of new customers, and as basis for exclusion for on-going advertising campaigns. Further information can be found in section “data matching for marketing purposes”.
In case I access protected data on Internet portals of Vogel Communications Group including any affiliated companies according to §§ 15 et seq. AktG, I need to provide further data in order to register for the access to such content. In return for this free access to editorial content, my data may be used in accordance with this consent for the purposes stated here. This does not apply to data matching for marketing purposes.
Right of revocation
I understand that I can revoke my consent at will. My revocation does not change the lawfulness of data processing that was conducted based on my consent leading up to my revocation. One option to declare my revocation is to use the contact form found at https://contact.vogel.de. In case I no longer wish to receive certain newsletters, I have subscribed to, I can also click on the unsubscribe link included at the end of a newsletter. Further information regarding my right of revocation and the implementation of it as well as the consequences of my revocation can be found in the data protection declaration, section editorial newsletter.
Routers, modems, and firewalls;
Industrial control systems and IoT gateways;
Operating systems, hypervisors, and container runtime systems;
Identity management systems and privileged access software; or
Internet-enabled toys and wearables
Additional Requirements: Radio Equipment Directive (RED) and EN 18031
Parallel to the CRA, the EU has also tightened cybersecurity regulations under its Radio Equipment Directive (Directive 2014/53/EU). This regulation applies to all products sold in the EU that are specifically designed to transmit or receive radio signals, such as Wi-Fi, LTE, or Bluetooth.
Furthermore, with Delegated Regulation (EU) 2022/30, effective August 1, 2025, the scope of mandatory cybersecurity requirements for manufacturers has been expanded, and their devices must now meet the following requirements:
Protect networks from unauthorized access;
Protect personal data and the privacy of users; and
Prevent fraud in digital communication
To simplify compliance with the regulations, the harmonized standard EN 18031 was developed, which establishes a presumption of conformity for the cybersecurity requirements of the RED and defines its technical specifications. These include secure boot, access control, encrypted communication, and digitally signed firmware updates. However, this conformity must be ensured at the end-product level, not merely at the module level.
Given the increasing number of CRA and RED regulations coming into effect, cybersecurity for embedded systems and OEMs is no longer optional but a fundamental requirement. For engineers, this means that security design and risk analysis must take place early in the development process.
Beyond product development, lifecycle management and maintaining operational compliance are crucial. Manufacturers must continuously monitor for new vulnerabilities to promptly provide patches and inform authorities within the mandated 24-hour window about severe incidents. To achieve this, embedded systems require robust update mechanisms, encrypted communication, and hardened firmware. Since supply chains are also held accountable for violations, each component supplier must prove that their parts meet the required standards. Otherwise, end products cannot be certified for legal entry into the EU market, underscoring the importance of early implementation of cybersecurity measures for all parties involved.
Embedded Ecosystems to Support Cybersecurity
To efficiently meet these growing regulatory requirements, developers benefit from using a comprehensive ecosystem of hardware, software, and tools specifically designed for embedded applications. The Seco Clea platform, for example, follows an SbD philosophy and provides fundamental mechanisms such as secure boot, encrypted communication, and signed firmware, while also enabling comprehensive product lifecycle management.
Image 3: The Seco Clea ecosystem includes a wide range of tools, hardware, and software that enable developers to easily equip their products with the required cybersecurity measures to comply with modern regulations.
(Image: Seco)
A key element in ensuring compliance is the infrastructure for over-the-air updates (OTA), which ensures timely, reliable, and traceable delivery of software and firmware updates. By providing regular security patches and quickly addressing exploited vulnerabilities, the Clea ecosystem helps manufacturers meet their legal obligations. Additionally, it facilitates the creation and management of essential SBOMs for CE compliance and audits.
The ecosystem goes a step further by integrating monitoring, reporting, and compliance tools that enable centralized monitoring of device fleets, early detection of anomalies, and the recording and reporting of incidents. Such features optimize the workflows of OEMs, resulting in reduced regulatory risks and increased trust among customers and partners who share the responsibility for compliance.
Integration into Existing Systems
The integration of the Clea ecosystem into an existing embedded system begins with the use of SDKs, APIs, and agents for various hardware and software platforms and their incorporation into existing system stacks. This is possible without redesigning the core architecture and enables secure communication, device authentication, and lifecycle management from the early development stages.
The next step involves connecting the ecosystem to a cloud, such as Seco's cloud services, where dashboards and connectors enable access to monitoring, update, and compliance functions. These cloud platforms support standardized protocols and can be integrated into existing development and deployment workflows to ensure scalability across large, heterogeneous device fleets.
To simplify operations, Clea also offers DevOps and additional security tools for the automated creation of SBOMs, vulnerability scans, logging, and reporting. This allows teams to meet documentation and audit requirements directly within their toolchains, reducing manual effort and shortening time-to-market for compliant products.
Cybersecurity is becoming a central requirement for embedded systems and OEMs seeking access to the EU market with the introduction of CRA and RED. "Security by Design," continuous lifecycle management, complete SBOM documentation, and rapid incident response are now mandatory. Developers must therefore embed security at the architectural level. At the same time, OEMs enforce compliance across their entire supply chain.
The Seco Clea ecosystem provides a practical solution to this challenge, encompassing integrated security features, a robust OTA infrastructure, monitoring and reporting services, and automation tools for documentation and audits. This not only reduces regulatory risks but also strengthens trust in the products. In this way, OEMs can ensure continuous compliance and maintain their competitive and security advantages in this new era of cybersecurity regulations.
*Francesco Vaiani is Senior Product Manager at Seco.