Cyber Resilience Act: Obligations, Deadlines, and Fines for Automotive and Electronics

The Cyber Resilience Act (CRA) redefines the rules for market access and product security across the EU single market. The CRA has been in force since 10 December 2024. Reporting obligations for actively exploited vulnerabilities and severe security incidents already apply from 11 September 2026. Full applicability of all cybersecurity requirements follows after a 36-month transition period on 11 December 2027.

Every product with digital elements must be demonstrably secure from development through the end of its lifecycle. Companies that miss the deadlines risk significant penalties, up to and including a ban on placing the product on the market.

Helen Gallwas
Marketing Communication Manager
Contact us

What the CRA Actually Requires

The CRA introduces binding obligations covering the entire product lifecycle. Security becomes an integral part of the product, not an afterthought.

  • Secure by design: Security must be built into the product architecture from the start.
  • Continuous risk management: Manufacturers must actively monitor products for vulnerabilities throughout their lifecycle and fix them through updates.
  • Complete documentation: All security-relevant processes and the Software Bill of Materials (SBOM) must be transparently documented and available for audits.
  • Extended responsibility and liability: Responsibility for security vulnerabilities lies with the manufacturer — with correspondingly higher liability risks for management.
  • CE marking: Products must carry CE conformity marking confirming the product's CRA compliance.

What This Means for Automotive

For the automotive industry, already shaped by UNECE R155 (CSMS), R156 (SUMS), and ISO/SAE 21434, the CRA closes a gap. Existing regulations primarily cover safety-critical vehicle systems such as brakes or steering. The CRA extends requirements to all other digital components — from infotainment systems to fleet management software to third-party apps.

Complete vehicles are excluded from CRA regulation, as they already fall under UN R155. Automotive components, control units, supplier parts, and aftermarket products with digital elements, however, must meet CRA requirements.

What This Means for Electronics Manufacturers

For electronics manufacturers outside automotive regulation, the CRA applies more directly, since there are no comparable sector-specific rules already covering individual requirements. This affects IoT devices, industrial and control electronics, consumer electronics, and components for smart home and smart city applications, among others.

For these manufacturers, the CRA often represents the first binding cybersecurity framework for their products at all. Anyone who hasn't yet run structured vulnerability management or SBOM documentation now has to build these processes from scratch — including the ability to report within 24 hours when an incident occurs.

Why the Supply Chain Is Affected

Responsibility doesn't end at the factory gate. The CRA requires auditability across the entire supply chain. OEMs and brand manufacturers pass these requirements on to their suppliers — supply chain security becomes a selection criterion for partners and suppliers.

Companies unable to demonstrate verifiable process security risk losing their place in the chain. This applies not only to technical documentation, but also to whether a supplier can credibly demonstrate its own security standard — for example, through the TISAX® assessment process.

Where btv TAK® and btv SEEL® Come In

btv technologies documents processes across component supply — from procurement through storage and processing to delivery. This evidence is generated within the ongoing process, not created afterward for an audit.

btv TAK® makes these steps traceable at the level of the individual packaging unit. For programmable components, btv SEEL® extends this chain of evidence to programming and initialization — down to the level of the individual component.

The programming process itself runs in a secured environment: sensitive firmware is processed exclusively in temporary volatile memory (RAM) and completely and irreversibly deleted once programming is complete. Customers who want to integrate their own PKI infrastructure connect a certificate-based data space through btv SEEL® INTERCONNECT — root certificates and private keys remain with the customer at all times. For serial production requiring individual device identities, btv SEEL® UNLIMITED scales the approach: each certificate is uniquely assigned to a microcontroller, and every process step is documented and signed.

The distinction matters: btv SEEL® is a programming service, not a CRA-regulated product. Conformity of the end product remains the manufacturer's responsibility. What btv delivers is evidence from its own process area that can feed into the customer's conformity assessment.

btv TAK®

 btv SEEL®

What Happens in the Event of Non-Compliance

The CRA provides for a tiered fine system:

  • Up to €15 million or 2.5% of global annual turnover for violations of essential security requirements.
  • Up to €10 million or 2% of global annual turnover for other obligations, such as reporting or documentation requirements.
  • Up to €5 million or 1% of global annual turnover for incorrect, incomplete, or misleading information provided to authorities.

In addition, products can be withdrawn from the market or recalled.

Certifications and Memberships

btv technologies is certified to ISO 9001 and IATF 16949, and has completed the TISAX® assessment process, with results published on the ENX portal. As a member of the VDA (German Association of the Automotive Industry), btv actively contributes to the standards that put these requirements into practice.

FAQ: The most important questions about CRA

The CRA has been in force since 10 December 2024. Reporting obligations for actively exploited vulnerabilities and severe security incidents already apply from 11 September 2026. Full applicability for most products follows after a 36-month transition period on 11 December 2027.

UNECE R155 focuses on the Cybersecurity Management System (CSMS) for the entire vehicle. The CRA complements this by setting concrete security requirements for individual hardware and software products in the vehicle that aren't directly safety-critical — such as infotainment systems.

Yes, even more directly. For many electronics manufacturers — for example, in IoT, industrial electronics, or consumer electronics — the CRA is the first binding cybersecurity framework for their products. There are no existing sector-specific regulations here, as there are in the automotive industry, that already cover individual requirements.

Traceable processes help companies show in an audit which component, software state, and process step belong together. btv TAK® documents this information at the level of the individual packaging unit; for programmable components, btv SEEL® extends it to the level of the individual component. The actual conformity assessment remains the manufacturer's responsibility.

A Software Bill of Materials is a complete list of all software components in a product. The CRA requires this transparency to enable quick identification and remediation of vulnerabilities.

Violations of essential security requirements can result in fines of up to €15 million or 2.5% of global annual turnover. Other obligation violations carry fines of up to €10 million or 2%, and incorrect information provided to authorities carries fines of up to €5 million or 1%. Products can also be withdrawn from the market or recalled.

Let's Talk About Your Roadmap

The Cyber Resilience Act isn't a distant regulation — it's a concrete business task, for automotive and electronics manufacturers alike. Let's look together at which components are affected and what evidence from your supply chain already exists today.

 

GET IN TOUCH

Sebastian Gersmann
Key Account Manager
CHOOSE A TIME
Thomas Hase
Key Account Manager
CHOOSE A TIME
Christian Schoregge
Key Account Manager
CHOOSE A TIME

More articles

What btv SEEL® Really Contributes to CRA Compliance

CRA reporting obligations apply from September 2026. What that means for your programming process — and where btv SEEL® fits in.

Automotive Cost-Saving Alliances: Built for Resilience

Automotive partnerships can reduce cost pressure when they cut complexity without creating new supply risks. Four models and the decisions that make them work.

NIS2 or the CRA — or Both?

Two frameworks, two different goals. We break down NIS2 and the CRA, connect them to BSI TR-03183 and EN 18031 — and explain what this means for your components.