Man smiling as he works on his computer with the doubleSlash Update Manager, while networked symbols for cloud, security and data transmission represent the digital workplace - a symbolic image for cyber resilience and modern IT infrastructure.

The Cyber Resilience Act (CRA): What manufacturers need to know now

The Cyber Resilience Act demands new security standards for networked products with clear obligations for manufacturers. Find out here how you can strategically position yourself now and ensure your compliance with centralized update management.

How secure are your connected products really?

The Cyber Resilience Act (CRA) of the EU requires a consistent security concept for networked devices. Manufacturing companies - especially larger SMEs and corporations with IoT or industrial devices - must now meet mandatory requirements:

This includes security by design, i.e. integrating security into product development right from the start.

Regular security updates are also mandatory in order to close vulnerabilities quickly.

The CRA also requires complete and comprehensible documentation of all safety measures. Depending on the risk level, there is also a long-term maintenance obligation over several years.

These requirements are legally binding and non-negotiable.

At a glance: Cyber Resilience Act (CRA)

  • Target: Greater security for networked products
  • Entry into force: Expected 2026
  • Affected products: IoT devices, industrial systems, medical systems and more
  • Core requirements: Security-by-design, regular updates, complete documentation
  • Consequences of non-compliance: High fines and market bans in the EU

Why the Cyber Resiliance Act is a challenge for companies

Implementing the new CRA rules is a challenge for many companies - very similar to the already applicable NIS-2 Directive.

  • Complex update distribution due to different device variants and regional adaptations
  • Lack of overview of device status and patch level
  • Legal and economic risks in the event of security incidents

Practical example: Successful rollout of centralized update management

A global manufacturer of optical and medical technology systems shows how Centralized update management succeeds:

Initial situation:

Service technicians had to make time-consuming and costly trips to customers all over the world and install software updates via USB sticks or DVDs.
The infrastructure was heterogeneous and difficult to maintain. A lack of transparency led to high compliance risks.

Solution:

Implementation of a central device and update management system with:

  • Platform-independent integration (e.g. Azure IoT, AWS IoT, mender.io).
  • Rule-based update rollout (by device type, software version or region).
  • Gradual rollout (internal, pilot phase, global).
  • Automatic provisioning also for offline devices.
  • Monitoring and reporting for end-to-end compliance.

Achievements:

The new central system ensured significantly faster updates and better regulatory compliance. The operational reliability of the devices increased considerably, which significantly improved the user experience. Thanks to complete transparency, the compliance and security risk was significantly reduced.

  • Efficient and fast update cycles
  • Sustainable compliance security through documented processes
  • Significantly higher system availability and user satisfaction
  • Noticeable reduction in safety and liability risk

How does central device and update management help with the Cyber Resiliance Act?

The CRA requires reliable update distribution, automatic compliance documentation and transparency regarding rollout status. A centralized update management system supports precisely this and forms the core of a comprehensive security strategy.

Conclusion: act now instead of waiting

Manufacturers must take action now and establish CRA-compliant processes at an early stage. These include:

  • Early introduction of centralized update processes.
  • Establishment of central device management systems.
  • Implementation of all technical and organizational requirements of the CRA.

Don't wait until the Cyber Resilience Act is mandatory. Proactive action ensures compliance, strengthens customer confidence and ensures competitive advantages in the long term.

Jonas Kaltenbach

About ME

Jonas Kaltenbach studied Business Informatics (B.Sc.) at the DHBW in Ravensburg and has been working at doubleSlash since 2016. He works as an IT consultant and has several years of experience in supporting and advising Internet of Things projects at Carl Zeiss, ZF and Rolls Royce. He has extensive know-how in the following areas Project management, conception and Design and SCRUM.

All contributions from Jonas Kaltenbach

Learn more

Further information on our website and in our newsletter

Arrow up