Cyber Resilience Act compliance for IoT - from firmware to CE mark.
The Cyber Resilience Act makes cybersecurity a legal requirement for every product with digital elements sold in the EU. Matproof automates CRA compliance for IoT manufacturers - SBOM management, vulnerability disclosure, security-by-design documentation, and CE marking - so your engineering team builds products, not compliance paperwork.
Matproof for CRA
Your CRA programme, on one screen.
Security-by-design, SBOMs and vulnerability handling for products with digital elements — ENISA-ready.
- ✓Map controls once, reuse across every framework
- ✓Evidence collected and time-stamped automatically
- ✓Audit-ready packages generated on demand
CRA coverage
updated just nowThe Challenge
Why the CRA changes everything for IoT manufacturers
For the first time, cybersecurity is a mandatory requirement for market access in the EU. The CRA applies to every connected product - from industrial sensors to smart home devices. No CE mark without cybersecurity compliance means no EU market access.
Security-by-design is now a legal requirement
The CRA mandates that manufacturers integrate cybersecurity throughout the entire product lifecycle - from design through end-of-life. This means secure default configurations, minimal attack surfaces, and protection of data at rest and in transit. For IoT manufacturers used to shipping firmware updates reactively, this requires a fundamental shift in product development processes.
SBOM management across complex supply chains
The CRA requires manufacturers to identify and document all components in their products, including third-party and open-source software. For IoT devices with complex firmware stacks, embedded Linux distributions, and multiple third-party libraries, creating and maintaining accurate Software Bills of Materials is an ongoing operational challenge.
Vulnerability disclosure and handling obligations
Manufacturers must establish coordinated vulnerability disclosure processes, report actively exploited vulnerabilities to ENISA within 24 hours, and provide security updates for the expected product lifetime (minimum 5 years). For companies with hundreds of product variants in the field, tracking and patching vulnerabilities across all supported versions is a massive undertaking.
CE marking now includes cybersecurity
Products with digital elements cannot carry the CE mark without demonstrating CRA compliance. This means cybersecurity conformity assessment becomes a gate for market access across the entire EU. Manufacturers must produce technical documentation, undergo assessment procedures, and maintain compliance throughout the product support period.
Your Compliance Journey
From product audit to CE mark in weeks
Product Assessment
Inventory all products with digital elements across your portfolio. Matproof classifies each product against CRA risk categories (default, important Class I, critical Class II) and maps applicable requirements.
SBOM & Gap Analysis
Import or generate SBOMs for your product firmware and software. Matproof identifies known vulnerabilities, missing components, and gaps in your security-by-design processes against CRA essential requirements.
Compliance Implementation
Generate vulnerability handling policies, security update procedures, technical documentation, and conformity assessment evidence. Integrate vulnerability monitoring into your CI/CD pipeline.
Continuous Compliance
Automated SBOM monitoring for new vulnerabilities, incident reporting workflows for ENISA notifications, security update tracking across all product versions, and CE marking documentation maintenance.
Key Requirements
CRA requirements that matter most for IoT manufacturers
Essential Cybersecurity Requirements
- Security-by-design and security-by-default (Annex I, Part I)
- Secure default configuration and minimal attack surface
- Protection of data confidentiality, integrity, and availability
- Protection against unauthorized access and denial of service
- Secure update mechanisms and ability to revert updates
- Documentation of all security-relevant aspects of the product
Vulnerability Handling & Reporting
- Coordinated vulnerability disclosure policy (Art. 11)
- Actively exploited vulnerability notification to ENISA within 24h (Art. 14)
- Security updates for minimum product support period (5 years) (Art. 11)
- SBOM covering at minimum top-level components (Art. 11)
- Vulnerability remediation without delay and free of charge
- Regular testing and review of product security
Conformity Assessment & CE Marking
- Technical documentation covering all essential requirements (Art. 23)
- Conformity assessment procedure based on product risk class (Art. 18-20)
- EU Declaration of Conformity for each product type (Art. 21)
- CE marking affixed before placing on the market (Art. 22)
- Market surveillance cooperation with national authorities
- 10-year documentation retention after product placed on market
Why Matproof
Built for product security compliance
Product portfolio risk classification
Matproof classifies your entire product portfolio against CRA risk categories. Default products, Important Class I, and Critical Class II each have different conformity assessment paths - Matproof ensures you follow the right process for each product.
Automated SBOM monitoring
Import SBOMs from your build pipeline and Matproof continuously monitors for new CVEs affecting your components. When a vulnerability is discovered, automated workflows trigger assessment, prioritization, and patch tracking across all affected product versions.
ENISA reporting workflows
When an actively exploited vulnerability is discovered, the 24-hour ENISA notification clock starts immediately. Matproof generates the notification in the required format, tracks the reporting timeline, and manages follow-up notifications as remediation progresses.
CE marking documentation package
Generate and maintain the complete technical documentation package required for CE marking. Matproof tracks conformity against all essential requirements and produces the EU Declaration of Conformity with full traceability to supporting evidence.
Frequently asked questions
- Which products are covered by the Cyber Resilience Act?
- The CRA covers all products with digital elements - any software or hardware product with a direct or indirect logical or physical data connection to a device or network. This includes IoT devices, industrial controllers, smart home products, networking equipment, operating systems, and standalone software. Products already regulated under specific sectoral legislation (medical devices, automotive, aviation) may be partially or fully exempt.
- What is the difference between default, Important, and Critical product categories?
- Default products (about 90% of covered products) can use self-assessment. Important Class I products (e.g., password managers, network management systems, firewalls) require third-party assessment or use of harmonized standards. Critical Class II products (e.g., hardware security modules, smartcard readers, operating systems) require mandatory third-party conformity assessment by a notified body.
- When does the CRA enter into force?
- The CRA was published in the Official Journal in late 2024. Manufacturers have a 36-month transition period for most obligations, meaning full compliance is required by late 2027. However, vulnerability reporting obligations to ENISA apply 21 months after entry into force (approximately mid-2026). Matproof recommends starting compliance work now to meet the earlier vulnerability reporting deadline.
- How does the CRA interact with NIS2?
- The CRA focuses on product security (manufacturers and their products), while NIS2 focuses on organizational security (operators of essential and important services). IoT manufacturers may need to comply with both - NIS2 for their organizational cybersecurity, and CRA for the products they sell. Matproof manages both frameworks in one platform, identifying where controls serve dual purposes.
Ship secure products. Keep your CE mark.
Book a 30-minute demo and see how Matproof automates CRA compliance for your product portfolio - SBOM monitoring, vulnerability disclosure, and CE marking documentation.
Not ready for a demo?
Let's talk compliance
Leave your email and we will reach out personally to discuss your compliance needs.
We follow up personally within 24 hours. No automated spam.