Cybersecurity compliance for connected devices
RED cybersecurity to EN 18031, the Cyber Resilience Act, SBOM and vulnerability handling – we get your connected product into the EU market in compliance, and keep it there.
Since 1 August 2025 cybersecurity requirements have been mandatory for radio equipment, and from 11 September 2026 the first obligations under the Cyber Resilience Act apply. For manufacturers of connected products this means security is no longer optional: it is a precondition for CE marking – and therefore for market access.
We develop embedded systems that meet these requirements from the outset rather than retrofitting them at the end. Retrofitting security is expensive: a device without secure boot or without an update mechanism cannot be fixed by software alone.
RED: cybersecurity for radio equipment (mandatory since 08/2025)
Delegated Regulation (EU) 2022/30 activates Article 3(3)(d), (e) and (f) of the Radio Equipment Directive (RED, 2014/53/EU). In practice this affects any device with Wi-Fi, Bluetooth, cellular or other radio that connects to the internet – from IoT gateways and sensor nodes to wearables.
The three protection goals:
- Network protection (3.3 d) – the device must not harm the network or allow misuse of network resources
- Protection of personal data (3.3 e) – for devices processing personal, traffic or location data
- Protection against fraud (3.3 f) – for devices transferring money or monetary value
Conformity is demonstrated using the harmonised standards EN 18031-1/-2/-3, listed in the Official Journal since January 2025 (Implementing Decision (EU) 2025/138). Note the restrictions: the presumption of conformity does not apply in all cases – for instance where a device can be operated without a password. The route then leads through a notified body and an EU type-examination. These are exactly the traps we clear up before the design, not after.
Cyber Resilience Act: the timeline
Regulation (EU) 2024/2847 applies to all „products with digital elements“ – hardware and software alike, regardless of radio.
| Date | What applies |
|---|---|
| 10 Dec 2024 | CRA in force, transition period begins |
| 11 Sep 2026 | Reporting obligations for actively exploited vulnerabilities and severe incidents |
| 11 Dec 2027 | Full application; new products require conformity assessment and CE marking |
From 11 September 2026 a three-stage reporting chain applies: early warning within 24 hours, a detailed report after 72 hours, and a final report once the issue is resolved. This is an organisational challenge more than a technical one – anyone who first has to work out which devices carry which software version will not meet a 24-hour deadline.
SBOM: the inventory that decides everything
A Software Bill of Materials lists every component in your product with its version and origin. When a vulnerability in a widely used library becomes known tomorrow, the SBOM answers in minutes what would otherwise take weeks: which of our products are affected, in which versions, at which customers?
What we put in place:
- SBOM generation automatically during the build (CycloneDX or SPDX), not as a one-off manual exercise – aligned with BSI TR-03183
- Matching components against vulnerability databases, with alerts on hits
- Mapping serial number to software version, so affected devices can be identified
- An update path that actually delivers the fix to the field – signed and fail-safe
What we do, concretely
- Gap analysis – we assess your product or product family against RED/EN 18031 and the CRA requirements and name the gaps along with the effort involved.
- Security architecture – secure boot, key management, secure interfaces, roles and permissions, update mechanism.
- Implementation in hardware and firmware – from the bootloader through the radio link to the cloud interface.
- SBOM and processes – build pipeline, vulnerability monitoring, reporting process with responsibilities and templates.
- Documentation for the conformity assessment – risk assessment, technical documentation, support period.
Why work with us
We are not a test house or a pure consultancy – we build the devices ourselves. That means we know what a secure boot concept actually costs on a Cortex-M with limited flash, and we will not propose an architecture that does not survive your series price.
Legal status of this page: September 2026. Sources: Delegated Regulation (EU) 2022/30, Implementing Decision (EU) 2025/138 (EN 18031-1/-2/-3), Regulation (EU) 2024/2847 (Cyber Resilience Act). This page is a technical summary and does not constitute legal advice.