CRA for Software vs Hardware: Different Applications
Does the Cyber Resilience Act apply differently to software and hardware? Discover the specifics for each product type and the resulting obligations.
Does the Cyber Resilience Act apply differently to software and hardware? Discover the specifics for each product type and the resulting obligations.
The Cyber Resilience Act covers both software and hardware with digital elements, but the obligations are not identical. Understanding the differences is essential for adapting your compliance strategy.
Software is clearly in scope: web and mobile apps, SaaS platforms, operating systems, firmware, and software libraries. Focus areas include security by design, SBOM, vulnerability management, and security updates.
Hardware products with digital elements are also covered: consumer IoT, connected medical devices, industrial equipment, and hardware components with firmware. Additional requirements include physical security, secure default configuration, and OTA updates.
For software publishers: Focus on SBOM, CI/CD pipeline security, and automated vulnerability management. Expert CRA integrates with your existing tools.
For hardware manufacturers: Plan for physical constraints: OTA updates, hardware port security, no default passwords, and documented support lifecycle.
Whether you develop software or hardware, the CRA applies to you. The key is adapting your approach to your product type.