Cyber Resilience Act (CRA)
What is CRA?
CRA, Cyber Resilience Act, is an EU cybersecurity law that entered into force in 2024. Published as Regulation (EU) 2024/2847, it is a horizontal EU regulatory framework that imposes mandatory cybersecurity requirements on hardware and software products with digital elements made available on the EU market, excluding certain products governed by sector-specific legislation.
Enforcement and Penalty
The obligation of reporting with strict deadlines on actively exploited vulnerabilities and severe security incidents having an impact on the security of products with digital elements starts on September 11, 2026. From December 11, 2027, non-compliance may result in corrective measures, restrictions, withdrawal or recall from the EU market. Non-compliance also carries administrative fines determined by the type of infringement.
Security Is Manufacturers’ Responsibility
Under the CRA, manufacturers are responsible for securing products with digital elements throughout their lifecycle. Manufacturers must:
- Design and build securely.
- Manage vulnerabilities throughout the support period.
- Provide security updates and user support.
- Report serious cybersecurity issues.
- Demonstrate continuous conformity with evidence.
- Monitor and correct products already on the market.
Aurora Networks™ Operationalize Product Trust
Aurora Networks offers several services that help manufacturers meet their responsibilities under CRA. Some of the services leverage hardware-based security foundations, including secure storage, true random number generator, and secure boot, to help establish device and software trust.
PKIWorks® Enables Device Trust
PKIWorks issues and updates device credentials, the anchor for device trust. It supports device credential provisioning for devices being made in factories and devices already deployed in the field. It also comes with a chip-specific SDK that helps manufacturers do credential provisioning by performing chip-level security functions.
SODIACS® and PRiSM™ Build Software Trust
SODIACS scans software to identify known vulnerabilities and to compile SBOM (Software Bill of Materials) and CBOM (Cryptography Bill of Materials). PRiSM signs and encrypts software. SODIACS scanning reports and PRiSM code signing and encryption help manufacturers make software trusted.