VE MATPROOF EN TU STACK — RESERVA UNA DEMO DE 30 MINUTOS
All use cases
Cyber Resilience ActIoT & Manufacturing

Cyber Resilience Act compliance for IoT - from firmware to CE mark.

The Cyber Resilience Act makes cybersecurity a legal requirement for every product with digital elements sold in the EU. Matproof automates CRA compliance for IoT manufacturers - SBOM management, vulnerability disclosure, security-by-design documentation, and CE marking - so your engineering team builds products, not compliance paperwork.

Matproof for CRA

Your CRA programme, on one screen.

Security-by-design, SBOMs and vulnerability handling for products with digital elements — ENISA-ready.

  • Map controls once, reuse across every framework
  • Evidence collected and time-stamped automatically
  • Audit-ready packages generated on demand
app.matproof.com/craLive

CRA coverage

updated just now
0%Security
0%SBOM
0%Vuln. handling
SBOM · generated per releaseVERIFIED
Vulnerability disclosure · liveVERIFIED
CE technical file · 82%ON TRACK
DORANIS2ISO 27001SOC 2
Export audit pack →

The Challenge

Why the CRA changes everything for IoT manufacturers

For the first time, cybersecurity is a mandatory requirement for market access in the EU. The CRA applies to every connected product - from industrial sensors to smart home devices. No CE mark without cybersecurity compliance means no EU market access.

Security-by-design is now a legal requirement

The CRA mandates that manufacturers integrate cybersecurity throughout the entire product lifecycle - from design through end-of-life. This means secure default configurations, minimal attack surfaces, and protection of data at rest and in transit. For IoT manufacturers used to shipping firmware updates reactively, this requires a fundamental shift in product development processes.

SBOM management across complex supply chains

The CRA requires manufacturers to identify and document all components in their products, including third-party and open-source software. For IoT devices with complex firmware stacks, embedded Linux distributions, and multiple third-party libraries, creating and maintaining accurate Software Bills of Materials is an ongoing operational challenge.

Vulnerability disclosure and handling obligations

Manufacturers must establish coordinated vulnerability disclosure processes, report actively exploited vulnerabilities to ENISA within 24 hours, and provide security updates for the expected product lifetime (minimum 5 years). For companies with hundreds of product variants in the field, tracking and patching vulnerabilities across all supported versions is a massive undertaking.

CE marking now includes cybersecurity

Products with digital elements cannot carry the CE mark without demonstrating CRA compliance. This means cybersecurity conformity assessment becomes a gate for market access across the entire EU. Manufacturers must produce technical documentation, undergo assessment procedures, and maintain compliance throughout the product support period.

Your Compliance Journey

From product audit to CE mark in weeks

1

Product Assessment

Inventory all products with digital elements across your portfolio. Matproof classifies each product against CRA risk categories (default, important Class I, critical Class II) and maps applicable requirements.

2

SBOM & Gap Analysis

Import or generate SBOMs for your product firmware and software. Matproof identifies known vulnerabilities, missing components, and gaps in your security-by-design processes against CRA essential requirements.

3

Compliance Implementation

Generate vulnerability handling policies, security update procedures, technical documentation, and conformity assessment evidence. Integrate vulnerability monitoring into your CI/CD pipeline.

4

Continuous Compliance

Automated SBOM monitoring for new vulnerabilities, incident reporting workflows for ENISA notifications, security update tracking across all product versions, and CE marking documentation maintenance.

Key Requirements

CRA requirements that matter most for IoT manufacturers

Art. 6, Annex I

Essential Cybersecurity Requirements

  • Security-by-design and security-by-default (Annex I, Part I)
  • Secure default configuration and minimal attack surface
  • Protection of data confidentiality, integrity, and availability
  • Protection against unauthorized access and denial of service
  • Secure update mechanisms and ability to revert updates
  • Documentation of all security-relevant aspects of the product
Art. 11-14

Vulnerability Handling & Reporting

  • Coordinated vulnerability disclosure policy (Art. 11)
  • Actively exploited vulnerability notification to ENISA within 24h (Art. 14)
  • Security updates for minimum product support period (5 years) (Art. 11)
  • SBOM covering at minimum top-level components (Art. 11)
  • Vulnerability remediation without delay and free of charge
  • Regular testing and review of product security
Art. 18-24

Conformity Assessment & CE Marking

  • Technical documentation covering all essential requirements (Art. 23)
  • Conformity assessment procedure based on product risk class (Art. 18-20)
  • EU Declaration of Conformity for each product type (Art. 21)
  • CE marking affixed before placing on the market (Art. 22)
  • Market surveillance cooperation with national authorities
  • 10-year documentation retention after product placed on market

Why Matproof

Built for product security compliance

Product portfolio risk classification

Matproof classifies your entire product portfolio against CRA risk categories. Default products, Important Class I, and Critical Class II each have different conformity assessment paths - Matproof ensures you follow the right process for each product.

Automated SBOM monitoring

Import SBOMs from your build pipeline and Matproof continuously monitors for new CVEs affecting your components. When a vulnerability is discovered, automated workflows trigger assessment, prioritization, and patch tracking across all affected product versions.

ENISA reporting workflows

When an actively exploited vulnerability is discovered, the 24-hour ENISA notification clock starts immediately. Matproof generates the notification in the required format, tracks the reporting timeline, and manages follow-up notifications as remediation progresses.

CE marking documentation package

Generate and maintain the complete technical documentation package required for CE marking. Matproof tracks conformity against all essential requirements and produces the EU Declaration of Conformity with full traceability to supporting evidence.

Frequently asked questions

Which products are covered by the Cyber Resilience Act?
The CRA covers all products with digital elements - any software or hardware product with a direct or indirect logical or physical data connection to a device or network. This includes IoT devices, industrial controllers, smart home products, networking equipment, operating systems, and standalone software. Products already regulated under specific sectoral legislation (medical devices, automotive, aviation) may be partially or fully exempt.
What is the difference between default, Important, and Critical product categories?
Default products (about 90% of covered products) can use self-assessment. Important Class I products (e.g., password managers, network management systems, firewalls) require third-party assessment or use of harmonized standards. Critical Class II products (e.g., hardware security modules, smartcard readers, operating systems) require mandatory third-party conformity assessment by a notified body.
When does the CRA enter into force?
The CRA was published in the Official Journal in late 2024. Manufacturers have a 36-month transition period for most obligations, meaning full compliance is required by late 2027. However, vulnerability reporting obligations to ENISA apply 21 months after entry into force (approximately mid-2026). Matproof recommends starting compliance work now to meet the earlier vulnerability reporting deadline.
How does the CRA interact with NIS2?
The CRA focuses on product security (manufacturers and their products), while NIS2 focuses on organizational security (operators of essential and important services). IoT manufacturers may need to comply with both - NIS2 for their organizational cybersecurity, and CRA for the products they sell. Matproof manages both frameworks in one platform, identifying where controls serve dual purposes.

Ship secure products. Keep your CE mark.

Book a 30-minute demo and see how Matproof automates CRA compliance for your product portfolio - SBOM monitoring, vulnerability disclosure, and CE marking documentation.

Not ready for a demo?

Let's talk compliance

Leave your email and we will reach out personally to discuss your compliance needs.

We follow up personally within 24 hours. No automated spam.