The Cyber Resilience Act (CRA) redefines the rules for market access and product security across the EU single market. The CRA has been in force since 10 December 2024. Reporting obligations for actively exploited vulnerabilities and severe security incidents already apply from 11 September 2026. Full applicability of all cybersecurity requirements follows after a 36-month transition period on 11 December 2027.
Every product with digital elements must be demonstrably secure from development through the end of its lifecycle. Companies that miss the deadlines risk significant penalties, up to and including a ban on placing the product on the market.
What the CRA Actually Requires
The CRA introduces binding obligations covering the entire product lifecycle. Security becomes an integral part of the product, not an afterthought.
- Secure by design: Security must be built into the product architecture from the start.
- Continuous risk management: Manufacturers must actively monitor products for vulnerabilities throughout their lifecycle and fix them through updates.
- Complete documentation: All security-relevant processes and the Software Bill of Materials (SBOM) must be transparently documented and available for audits.
- Extended responsibility and liability: Responsibility for security vulnerabilities lies with the manufacturer — with correspondingly higher liability risks for management.
- CE marking: Products must carry CE conformity marking confirming the product's CRA compliance.
What This Means for Automotive
For the automotive industry, already shaped by UNECE R155 (CSMS), R156 (SUMS), and ISO/SAE 21434, the CRA closes a gap. Existing regulations primarily cover safety-critical vehicle systems such as brakes or steering. The CRA extends requirements to all other digital components — from infotainment systems to fleet management software to third-party apps.
Complete vehicles are excluded from CRA regulation, as they already fall under UN R155. Automotive components, control units, supplier parts, and aftermarket products with digital elements, however, must meet CRA requirements.
What This Means for Electronics Manufacturers
For electronics manufacturers outside automotive regulation, the CRA applies more directly, since there are no comparable sector-specific rules already covering individual requirements. This affects IoT devices, industrial and control electronics, consumer electronics, and components for smart home and smart city applications, among others.
For these manufacturers, the CRA often represents the first binding cybersecurity framework for their products at all. Anyone who hasn't yet run structured vulnerability management or SBOM documentation now has to build these processes from scratch — including the ability to report within 24 hours when an incident occurs.
Why the Supply Chain Is Affected
Responsibility doesn't end at the factory gate. The CRA requires auditability across the entire supply chain. OEMs and brand manufacturers pass these requirements on to their suppliers — supply chain security becomes a selection criterion for partners and suppliers.
Companies unable to demonstrate verifiable process security risk losing their place in the chain. This applies not only to technical documentation, but also to whether a supplier can credibly demonstrate its own security standard — for example, through the TISAX® assessment process.
Where btv TAK® and btv SEEL® Come In
btv technologies documents processes across component supply — from procurement through storage and processing to delivery. This evidence is generated within the ongoing process, not created afterward for an audit.
btv TAK® makes these steps traceable at the level of the individual packaging unit. For programmable components, btv SEEL® extends this chain of evidence to programming and initialization — down to the level of the individual component.
The programming process itself runs in a secured environment: sensitive firmware is processed exclusively in temporary volatile memory (RAM) and completely and irreversibly deleted once programming is complete. Customers who want to integrate their own PKI infrastructure connect a certificate-based data space through btv SEEL® INTERCONNECT — root certificates and private keys remain with the customer at all times. For serial production requiring individual device identities, btv SEEL® UNLIMITED scales the approach: each certificate is uniquely assigned to a microcontroller, and every process step is documented and signed.
The distinction matters: btv SEEL® is a programming service, not a CRA-regulated product. Conformity of the end product remains the manufacturer's responsibility. What btv delivers is evidence from its own process area that can feed into the customer's conformity assessment.
What Happens in the Event of Non-Compliance
The CRA provides for a tiered fine system:
- Up to €15 million or 2.5% of global annual turnover for violations of essential security requirements.
- Up to €10 million or 2% of global annual turnover for other obligations, such as reporting or documentation requirements.
- Up to €5 million or 1% of global annual turnover for incorrect, incomplete, or misleading information provided to authorities.
In addition, products can be withdrawn from the market or recalled.
Certifications and Memberships
btv technologies is certified to ISO 9001 and IATF 16949, and has completed the TISAX® assessment process, with results published on the ENX portal. As a member of the VDA (German Association of the Automotive Industry), btv actively contributes to the standards that put these requirements into practice.
FAQ: The most important questions about CRA
Yes, even more directly. For many electronics manufacturers — for example, in IoT, industrial electronics, or consumer electronics — the CRA is the first binding cybersecurity framework for their products. There are no existing sector-specific regulations here, as there are in the automotive industry, that already cover individual requirements.
Traceable processes help companies show in an audit which component, software state, and process step belong together. btv TAK® documents this information at the level of the individual packaging unit; for programmable components, btv SEEL® extends it to the level of the individual component. The actual conformity assessment remains the manufacturer's responsibility.
Violations of essential security requirements can result in fines of up to €15 million or 2.5% of global annual turnover. Other obligation violations carry fines of up to €10 million or 2%, and incorrect information provided to authorities carries fines of up to €5 million or 1%. Products can also be withdrawn from the market or recalled.