Can you prove today which firmware version is running on which batch of your components — and who programmed it? From 11 December 2027, that will no longer be a rhetorical question. The Cyber Resilience Act's reporting obligations for actively exploited vulnerabilities and severe security incidents already apply from 11 September 2026.

The CRA was formally approved by the Council of the EU on 10 October 2024 and entered into force on 10 December 2024. It applies to all products with digital elements — from smartwatches to industrial control systems — and requires security across the entire product lifecycle, from development to end of life.

Helen Gallwas
Marketing Communication Manager
Contact us

What the CRA Actually Requires

Take connected thermostats as an example. Under the CRA, manufacturers must:

  • build in security from the design stage (security by design)
  • provide regular security updates
  • maintain detailed cybersecurity documentation
  • report actively exploited vulnerabilities within 24 hours (early warning), 72 hours (notification), and 14 days (final report)

Twenty-four hours isn't enough time to reconstruct which batch was affected after the fact. Either the data is already available, or you report without being able to narrow it down.

Where the Programming Process Becomes the Weak Point

Many manufacturers invest significant budgets in securing their application software. The actual programming process, however — the moment firmware and keys are physically flashed onto the microcontroller — remains the weak point in many manufacturing chains. If plaintext firmware or private keys fall into the wrong hands here, the trust model for an entire device generation collapses.

This is exactly where btv SEEL® comes in.

What btv SEEL® Actually Does

btv SEEL® processes encrypted firmware exclusively in the volatile memory of the programming environment — RAM-only, with no persistent data traces. Once programming is complete, an automated, irreversible memory wipe follows. Asymmetric 4K encryption, individual key pairs per chip, and signature-based authentication protect the flashing process against manipulation.

For customers who want to integrate their own PKI infrastructure instead of handing over root certificates, btv SEEL® INTERCONNECT uses standardized protocols such as HTTPS, SSH, and PGP for data exchange, while root certificates remain 100 percent under the customer's own control. For serial production requiring individual device identities — for example, for later OTA updates — btv SEEL® UNLIMITED scales this approach: each certificate is uniquely assigned to a microcontroller, and every process step is automatically documented and cryptographically signed.

Linking to the video streaming service is disabled to protect your privacy. Click here to activate it. By loading the video, you accept the privacy policy of the video streaming service. Further information about the privacy policy can be found here: Google - Privacy & Terms

What This Means for Your CRA Preparation

The distinction matters: btv SEEL® is a programming service, not a CRA-regulated product. The regulation addresses the product placed on the market — not the service provider carrying out one step of that process. What btv SEEL® delivers is chip-level traceability, the evidence needed for your own conformity assessment: programming, certificate issuance, and audit trail, documented and clearly linked to the specific component.

The practical difference: the evidence is ready when the audit happens. It isn't reconstructed afterward.

Certifications and Standards

btv technologies is certified to ISO 9001 and IATF 16949, and has completed the TISAX® assessment process, with results published on the ENX portal. This foundation — combined with a programming capacity of 75 million components per year and a broad range of component families — underpins what btv SEEL® delivers.

Evidence, Not Reconstruction

If you already document what happened to a component, there's nothing left to piece together when an incident occurs. That's exactly the difference: presenting data instead of searching for it.

Frequently Asked Questions

Is btv SEEL® CRA-compliant?

Not in a literal sense — and that isn't the right standard to apply. The CRA applies to products with digital elements placed on the market, not to a programming service. btv SEEL® provides the evidence needed for your own product's conformity: traceability down to the individual chip, documented key sovereignty, and a signed audit trail for every process step. Conformity of your end product remains your responsibility.

Reporting obligations for actively exploited vulnerabilities and severe security incidents apply from 11 September 2026. Full applicability of all cybersecurity requirements for newly placed products takes effect from 11 December 2027.

Encrypted firmware is processed exclusively in volatile memory. Once programming is complete, an automated, irreversible memory wipe follows. No unencrypted temporary files and no persistent copies are created on storage media.

btv SEEL® CORE secures the flashing process itself through the RAM-only principle. btv SEEL® INTERCONNECT integrates the customer's own PKI infrastructure, so root certificates never leave the customer's premises. btv SEEL® UNLIMITED scales this to individual device identities in serial production, with an automatically documented, cryptographically signed audit trail for every process step.

btv technologies is certified to ISO 9001 and IATF 16949, and has completed the TISAX® assessment process, with results published on the ENX portal.

Let's Talk About Your Roadmap

You don't have to wait until 2027. The reporting obligations already apply from 11 September 2026. Let's look together at which components are affected, what evidence already exists, and where your programming process should start.

GET IN TOUCH

Sebastian Gersmann
Key Account Manager
GET IN TOUCH
Thomas Hase
Key Account Manager
GET IN TOUCH
Christian Schoregge
Key Account Manager
GET IN TOUCH

More articles

What Really Happened to Your Component?

A component passes through many stations — from goods receipt to handover. Why the link between component, process step, and outcome often gets lost, and how a Chain of Trust fixes that.

After the Chip Crisis Comes the Next One — and This Time It's Structural

A new ZVEI study shows: Europe's semiconductor demand will double by 2040, equivalent to 65 new fabs. New capacity is being built in Asia. What this means for your parts supply — and what you can do today.

Electronic Component Storage for 25+ Years: Requirements, Risk Levels & the Right Strategy

A 30-cent component going end-of-life can shut down a production line worth half a million euros per hour. Long-term storage is your insurance – but only if it's done right. Discover the three levels that make the difference.