Can you prove today which firmware version is running on which batch of your components — and who programmed it?

The Cyber Resilience Act has been in force since 10 December 2024. From 11 December 2027, that will no longer be a rhetorical question, since full applicability takes effect then. The Cyber Resilience Act makes traceability, auditability, and recall readiness mandatory — for manufacturers and their entire supply chain.

The first deadline already applies from 11 September 2026: from this date, actively exploited vulnerabilities must be reported to the national CSIRT and ENISA within 24 hours. Anyone without a reporting process today — or whose suppliers can't deliver evidence at packaging-unit level — carries a structural risk.

Helen Gallwas
Marketing Communication Manager
Contact us

What is the Cyber Resilience Act – and who does it affect?

The Cyber Resilience Act (CRA) is an EU regulation that has been in force since 10 December 2024, with full applicability taking effect from 11 December 2027 — introducing binding cybersecurity requirements for all products with digital elements. It applies to manufacturers, importers, and distributors of connected and programmable products in the EU, including embedded systems, IoT devices, industrial controls, and automotive components.

The CRA isn't a cybersecurity directive for software companies. It's a product regulation covering the entire lifecycle of a product: from development through manufacturing to security updates and vulnerability reporting. Anyone developing or distributing products with digital elements in the EU today is affected.

An often-overlooked point: anyone placing products on the EU market under their own name or brand — including as an importer or distributor — is legally considered a manufacturer and carries all CRA obligations. White-labeling or modifying third-party components is enough to trigger full manufacturer responsibility.

For procurement, there's an added dimension: manufacturers must also be able to prove that their suppliers and service providers contribute to a secure, auditable process. This fundamentally changes supplier evaluations — and turns CRA compliance into a procurement issue.

Which software version was flashed onto which component, when, by whom, under what conditions? This question must be answerable at any time — not only internally, but also to authorities and customers.

When known vulnerabilities are identified, affected batches must be identifiable within 24 hours. Anyone lacking this data — or whose service provider can't deliver it — carries a structural risk.

These questions already appear in supplier evaluations today — particularly among Tier-1 suppliers who are themselves under IATF and NIS2 pressure. The right time to ask the right questions is therefore now.

The Journey of a Component — and Where Evidence Is Created

At its core, the CRA requires proof of an unbroken chain of trust: every step in the supply chain — from procurement through storage and processing to programming and delivery — must be documented, traceable, and auditable. This isn't an abstract requirement; it's concrete evidence that authorities can demand at any time.

At btv technologies, this chain of evidence is built along the entire journey a component takes through manufacturing.

btv TAK® Documents the Starting Point

It's fully documented which component comes from which source, when it was put into storage, under what conditions it's stored, and when it's delivered into production. Every batch is traceable at the level of the individual packaging unit, across all production sites, Tier-1 suppliers, and EMS partners.

btv TAK® is more than a documentation tool: it's a supply chain solution that can also serve as a one-stop solution — covering procurement, storage, and delivery to the line, all from a single partner. This is the foundation of every CRA audit.

btv TAK®

Component Services Extend the Chain of Evidence to Every Processing Step

In testing, reconditioning, drying and baking, taping, or repackaging, every action, every operator, and every goods movement is documented — along with storage conditions such as climate and ESD values during processing. This creates a chain of evidence that covers not just goods receipt and storage, but every process step a component goes through on its way to production.

Component Services

Long-term Storage

Programming Completes the Chain — Traceability Is Already Standard Here

The complete audit trail — batch, serial number, firmware version, timestamp, operator — is documented for every programming run, regardless of the method used, and reaches down to the level of the individual component. This data is exportable for QM, ERP, the technical file, and regulatory audits — closing the gap that exists for many manufacturers between component procurement and the finished product.

Programming

btv SEEL® Additionally Secures the Flashing Process Itself

btv SEEL® — patent-pending since 2023 — addresses a single point: securing the flashing process itself. Firmware and keys are provided exclusively in encrypted form and processed exclusively in volatile memory (RAM) — with no persistent data traces. Once programming is complete, an automated, irreversible memory wipe follows. Individual key pairs per chip and signature-based authentication additionally protect the process against manipulation.

Traceability is naturally already in place: btv SEEL® builds on the same programming process that is already fully documented in the standard workflow — the additional security mechanism supplements the audit trail, it doesn't replace it.

For devices that later need to uniquely identify and authenticate themselves within a network — for example, for OTA updates in the field — btv SEEL® UNLIMITED can additionally integrate individual certificates. Each certificate is uniquely assigned to a single component and documented accordingly.

btv SEEL® 

Together, btv TAK®, the component services, and btv SEEL® form a continuous, verifiable chain of trust — from the component to the programmed, production-ready assembly.

If this process isn't documented, a gap emerges in the technical file — the core document manufacturers use to demonstrate CRA conformity to authorities. A technically flawless component without process evidence is regulatorily worthless.

There's also the update obligation: the CRA requires that security updates can be provided throughout the entire product lifecycle. Anyone programming today must therefore consider how later changes, reprogramming, and version records will remain possible at all.

Checklist

What a Provider of CRA-Relevant Evidence Should Deliver

  • Documented, reproducible programming process (ISO/IATF-compliant)
  • Complete audit trail: batch, serial number, firmware version, timestamp
  • Exportable data for QM, audits, ERP, and compliance documentation
  • Contractually agreed response times for incidents (SLA)
  • Long-term storage of firmware states and device configurations
  • Verifiable storage conditions: climate, ESD, test intervals
  • Evidence at packaging-unit level, and at individual-component level for programming

This isn't a claim to completeness. It's a realistic starting point for conversations with suppliers who take the topic seriously.

The CRA thinks in lifecycles. Products must remain secure over years — often ten to twenty years for industrial and automotive-adjacent applications. Secure programming without long-term availability remains a fragment. Long-term storage without documented process and version security is equally incomplete. Only together do they create a resilient lifecycle approach that can withstand a CRA audit.

What Happens in the Event of Non-Compliance

The CRA provides for a tiered fine system: up to €15 million or 2.5% of global annual turnover for violations of essential security requirements, up to €10 million or 2% for other obligations such as reporting or documentation requirements, and up to €5 million or 1% for incorrect or misleading information provided to authorities. In addition, products can be withdrawn from the market or recalled.

Next Steps

  • Keep the first deadline in view: reporting obligations for actively exploited vulnerabilities apply from 11 September 2026
  • Ask existing service providers what evidence they can already deliver today — audit trail, traceability, response times
  • Bring together internal requirements from procurement, QM, development, and cybersecurity — CRA isn't an IT topic you can delegate
  • Stop evaluating suppliers purely as operational executors; treat them as part of your own evidence and risk chain
  • Ensure full CRA conformity by 11 December 2027

With btv TAK®, the component services, and btv SEEL®, the building blocks for a verifiable chain of trust are already in place — for your supply chain.

Maximilian Krane
CEO

Auditable Supply Chain – What that means in practice

Programming, traceability, and long-term storage as a lifecycle solution. Talk to us about how btv already provides CRA-relevant building blocks today.

GET IN TOUCH

Christian Schoregge
Key Account Manager
CHOOSE A TIME
Sebastian Gersmann
Key Account Manager
CHOOSE A TIME
Thomas Hase
Key Account Manager
CHOOSE A TIME

Frequently asked questions about the Cyber Resilience Act

The Cyber Resilience Act (CRA) is an EU regulation introducing binding cybersecurity requirements for all products with digital elements — from IoT devices to embedded systems to automotive components.

The CRA has been in force since 10 December 2024. Reporting obligations for actively exploited vulnerabilities apply from 11 September 2026, with full applicability of all requirements from 11 December 2027.

Manufacturers, importers, and distributors of products with digital elements placed on the EU market. Anyone distributing products under their own name or modifying third-party components is also legally considered a manufacturer.

The chain of trust refers to the unbroken, auditable evidence of every process step along the supply chain — from component procurement through storage and processing to programming and delivery. btv TAK® and the component services provide traceability; programming — whether standard or btv SEEL® — provides the complete audit trail down to component level.

Procurement and supply chain teams must ensure that suppliers and service providers operate auditable, documented processes. Firmware traceability, audit trails, and response times for security incidents become procurement criteria.

Not traceability — that applies equally to both processes, including traceability down to individual-component level. The difference lies solely in securing the flashing process itself: btv SEEL® processes firmware and keys exclusively in encrypted form and exclusively in volatile memory, with an automated memory wipe once programming is complete. With btv SEEL® UNLIMITED, individual certificates can additionally be integrated — for example, for unique device identification on a network or for later OTA updates.

No. Around 90% of affected products can complete conformity assessment through self-declaration (Module A). Only critical product classes require external assessment bodies. The evidence obligation — particularly the technical file and audit trail — applies to all, however.

More articles

Connected Medical Devices: Why MDR Alone Isn't Enough

One medical device, two legal frameworks: why MDR approval doesn't protect you from CRA obligations — and what that means for firmware and evidence.

What btv SEEL® Really Contributes to CRA Compliance

CRA reporting obligations apply from September 2026. What that means for your programming process — and where btv SEEL® fits in.

Automotive Cost-Saving Alliances: Built for Resilience

Automotive partnerships can reduce cost pressure when they cut complexity without creating new supply risks. Four models and the decisions that make them work.