Woman with airconditioning

The European Cyber Resilience Act: strengthening trust in connected products

Trust is the foundation of the connected world. The European Cyber Resilience Act is setting new standards for cybersecurity in digital products, pushing security beyond compliance and toward a lasting competitive advantage. Discover what the CRA requires and how Infineon enables customers to build resilient, trusted products from the ground up.

Security
Article

From smart thermostats and home security systems, to industrial sensors and consumer software:, products with digital elements are now embedded in almost every aspect of life. But the more connected our world becomes, the more critical it is that these products can be trusted. That is exactly where the European Union’s Cyber Resilience Act (CRA) comes in: it sets mandatory security requirements for products with digital elements placed on the EU market making them more reliable, secured and better protected throughout their entire lifecycle.

The CRA applies to a broad range of hardware and software products with digital elements. It requires manufacturers to integrate cybersecurity from the design and development phase and to support products throughout their lifecycle, including vulnerability handling, documentation and clear responsibilities across the value chain.

The regulation entered into force in December 2024 and will become fully applicable on 11 December 2027. Reporting obligations start earlier: from 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents having an impact on the security of products with digital elements.

The CRA covers a broad range of products with digital elements placed on the EU market, including consumer devices, software, operating systems, industrial controllers, routers and products with embedded software or network communication capabilities.

Certain categories are explicitly out of scope, including Software as a Service (SaaS), open-source software not intended for commercial activity, and products developed solely for national security or military purposes.

In practice, the CRA is relevant to any manufacturer, importer or distributor placing a product with digital elements on the EU market commercially.

Security starts at the component level. Semiconductor solutions enable trusted identity, protected data, authenticated updates and secured lifecycle support, key capabilities for building resilient connected products. Infineon supports customers with hardware-based security, secured authentication, protected key storage and trusted update mechanisms for industrial, automotive, consumer and IoT applications.

Our solutions help customers build CRA-relevant security capabilities through security-hardened microcontrollers, wireless solutions, secure elements and security controllers, as well as cryptographic software libraries and development tools that support cybersecurity by design. They enable secured authentication, hardware-based root of trust, encrypted communication, secured boot and secured updates. This helps customers reduce complexity and establish a strong, technical foundation for vulnerability management, product security maintenance and other CRA-related obligations.

Learn more about Infineon and the CRA here

The CRA is more than a regulatory obligation. It is an opportunity to strengthen trust in digital products and connected ecosystems by embedding cybersecurity as an integral, enduring quality attribute that delivers long-term value.