Cyber ​​Resilience Act: Is your connected product ready?

Is your connected product ready for the CRA?

Designing a connected product is no longer just about ensuring its performance, electrical safety, or connectivity. Today, cybersecurity is becoming an essential criterion for accessing the European market.

With the advent of the Cyber Resilience Act (CRA) and the tightening of requirements under the Radio Equipment Directive (RED), manufacturers must integrate cybersecurity from the earliest stages of development.

Which products are affected?

Many pieces of equipment are potentially affected:

  • consumer connected devices,
  • home automation equipment,
  • industrial IoT products,
  • connected radio equipment,
  • connected devices for professionals.
In other words, as soon as a product exchanges data or communicates via a network, cybersecurity becomes an issue that must be anticipated.


    CRA, RED, and ETSI EN 303 645: how to navigate the landscape?

    The Cyber ​​Resilience Act aims to strengthen the cybersecurity of digital products throughout their lifecycle. At the same time, certain requirements of the RED Directive already mandate protective measures for connected radio equipment.

    ETSI EN 303 645 is currently one of the key standards used to assess the cybersecurity of connected devices, with requirements covering, in particular:

    • passwords and authentication
    • software updates
    • data protection
    • vulnerability management



    How can compliance be demonstrated?

    One of the most common mistakes is waiting until the end of development to address cybersecurity. To avoid delays in bringing the product to market, it is recommended to take a proactive approach:

    • applicable regulatory requirements
    • the necessary technical documentation
    • evaluations and tests demonstrating conformity
    • les mécanismes de sécurité intégrés au produit



    Plan ahead to save time

      Cybersecurity is now a key step in the compliance journey for connected products. Integrating it at the design stage allows for a smoother approach to the evaluation, certification, and market launch phases.

      The teams and laboratories at LCIE Bureau Veritas assist manufacturers in identifying applicable requirements and demonstrating the compliance of their connected products.

Cyber ​​Resilience Act, RED, ETSI EN 303 645: are you ready? Contact us today to find out which requirements you need to anticipate to ensure the secure market launch of your connected products.