How secure are your connected products really?
The Cyber Resilience Act (CRA) of the EU requires a consistent security concept for networked devices. Manufacturing companies - especially larger SMEs and corporations with IoT or industrial devices - must now meet mandatory requirements:
This includes security by design, i.e. integrating security into product development right from the start.
Regular security updates are also mandatory in order to close vulnerabilities quickly.
The CRA also requires complete and comprehensible documentation of all safety measures. Depending on the risk level, there is also a long-term maintenance obligation over several years.
These requirements are legally binding and non-negotiable.
At a glance: Cyber Resilience Act (CRA)
- Target: Greater security for networked products
- Entry into force: Expected 2026
- Affected products: IoT devices, industrial systems, medical systems and more
- Core requirements: Security-by-design, regular updates, complete documentation
- Consequences of non-compliance: High fines and market bans in the EU
Why the Cyber Resiliance Act is a challenge for companies
Implementing the new CRA rules is a challenge for many companies - very similar to the already applicable NIS-2 Directive.
- Complex update distribution due to different device variants and regional adaptations
- Lack of overview of device status and patch level
- Legal and economic risks in the event of security incidents
Practical example: Successful rollout of centralized update management
A global manufacturer of optical and medical technology systems shows how Centralized update management succeeds:
Initial situation:
Service technicians had to make time-consuming and costly trips to customers all over the world and install software updates via USB sticks or DVDs.
The infrastructure was heterogeneous and difficult to maintain. A lack of transparency led to high compliance risks.
Solution:
Implementation of a central device and update management system with:
- Platform-independent integration (e.g. Azure IoT, AWS IoT, mender.io).
- Rule-based update rollout (by device type, software version or region).
- Gradual rollout (internal, pilot phase, global).
- Automatic provisioning also for offline devices.
- Monitoring and reporting for end-to-end compliance.
Achievements:
The new central system ensured significantly faster updates and better regulatory compliance. The operational reliability of the devices increased considerably, which significantly improved the user experience. Thanks to complete transparency, the compliance and security risk was significantly reduced.
- Efficient and fast update cycles
- Sustainable compliance security through documented processes
- Significantly higher system availability and user satisfaction
- Noticeable reduction in safety and liability risk

How does central device and update management help with the Cyber Resiliance Act?
The CRA requires reliable update distribution, automatic compliance documentation and transparency regarding rollout status. A centralized update management system supports precisely this and forms the core of a comprehensive security strategy.
Conclusion: act now instead of waiting
Manufacturers must take action now and establish CRA-compliant processes at an early stage. These include:
- Early introduction of centralized update processes.
- Establishment of central device management systems.
- Implementation of all technical and organizational requirements of the CRA.
Don't wait until the Cyber Resilience Act is mandatory. Proactive action ensures compliance, strengthens customer confidence and ensures competitive advantages in the long term.



