Can you prove today which firmware version is running on which batch of your components — and who programmed it? From 11 December 2027, that will no longer be a rhetorical question. The Cyber Resilience Act's reporting obligations for actively exploited vulnerabilities and severe security incidents already apply from 11 September 2026.
The CRA was formally approved by the Council of the EU on 10 October 2024 and entered into force on 10 December 2024. It applies to all products with digital elements — from smartwatches to industrial control systems — and requires security across the entire product lifecycle, from development to end of life.
What the CRA Actually Requires
Take connected thermostats as an example. Under the CRA, manufacturers must:
- build in security from the design stage (security by design)
- provide regular security updates
- maintain detailed cybersecurity documentation
- report actively exploited vulnerabilities within 24 hours (early warning), 72 hours (notification), and 14 days (final report)
Twenty-four hours isn't enough time to reconstruct which batch was affected after the fact. Either the data is already available, or you report without being able to narrow it down.
Where the Programming Process Becomes the Weak Point
Many manufacturers invest significant budgets in securing their application software. The actual programming process, however — the moment firmware and keys are physically flashed onto the microcontroller — remains the weak point in many manufacturing chains. If plaintext firmware or private keys fall into the wrong hands here, the trust model for an entire device generation collapses.
This is exactly where btv SEEL® comes in.
What btv SEEL® Actually Does
btv SEEL® processes encrypted firmware exclusively in the volatile memory of the programming environment — RAM-only, with no persistent data traces. Once programming is complete, an automated, irreversible memory wipe follows. Asymmetric 4K encryption, individual key pairs per chip, and signature-based authentication protect the flashing process against manipulation.
For customers who want to integrate their own PKI infrastructure instead of handing over root certificates, btv SEEL® INTERCONNECT uses standardized protocols such as HTTPS, SSH, and PGP for data exchange, while root certificates remain 100 percent under the customer's own control. For serial production requiring individual device identities — for example, for later OTA updates — btv SEEL® UNLIMITED scales this approach: each certificate is uniquely assigned to a microcontroller, and every process step is automatically documented and cryptographically signed.
What This Means for Your CRA Preparation
The distinction matters: btv SEEL® is a programming service, not a CRA-regulated product. The regulation addresses the product placed on the market — not the service provider carrying out one step of that process. What btv SEEL® delivers is chip-level traceability, the evidence needed for your own conformity assessment: programming, certificate issuance, and audit trail, documented and clearly linked to the specific component.
The practical difference: the evidence is ready when the audit happens. It isn't reconstructed afterward.
Certifications and Standards
btv technologies is certified to ISO 9001 and IATF 16949, and has completed the TISAX® assessment process, with results published on the ENX portal. This foundation — combined with a programming capacity of 75 million components per year and a broad range of component families — underpins what btv SEEL® delivers.
Frequently Asked Questions
Is btv SEEL® CRA-compliant?
Not in a literal sense — and that isn't the right standard to apply. The CRA applies to products with digital elements placed on the market, not to a programming service. btv SEEL® provides the evidence needed for your own product's conformity: traceability down to the individual chip, documented key sovereignty, and a signed audit trail for every process step. Conformity of your end product remains your responsibility.
btv SEEL® CORE secures the flashing process itself through the RAM-only principle. btv SEEL® INTERCONNECT integrates the customer's own PKI infrastructure, so root certificates never leave the customer's premises. btv SEEL® UNLIMITED scales this to individual device identities in serial production, with an automatically documented, cryptographically signed audit trail for every process step.