Cyber Resilience Act, Part 3: Transparency becomes a product requirement With the Cyber Resilience Act, SBOMs, open-source governance, and supply-chain visibility are becoming essential for compliance and market access. In a three-part article series, eeNews examines various aspects of the CRA and, in particular, how companies should now proceed. As outlined in the first installment of the article series, the EU’s Cyber Resilience Act (CRA), or Regulation (EU) 2024/2847, will make cybersecurity a mandatory CE requirement for connected products starting in 2027. The second part focuses on why “Security by Design” and “Secure by Default” will become mandatory, and what this specifically means for embedded and IoT developers. Now this third part brings together compliance and supply chain aspects. By the way, eeNews, together with Lemberg Solutions, is also organizing the free webinar “Building CRA-ready IoT products: the practical side of compliance” on 10 September, 2026. This webinar will show what a CRA-compliant SDLC looks like in practice. Registration for the webinar is now open. The new transparency requirement CRA is often discussed in the context of secure product design, vulnerability management, and software updates. However, one of its most significant implications lies elsewhere: transparency. Manufacturers will not only have to build secure products, they will also have to demonstrate that they understand exactly what is inside them, how security risks are managed, and how vulnerabilities are addressed throughout the product lifecycle. For embedded and IoT manufacturers, this represents a fundamental shift. Modern products are assembled from a complex mix of commercial software, open-source components, third-party libraries, cloud services, firmware modules, and increasingly sophisticated hardware platforms. Maintaining visibility across this ecosystem is becoming not merely a best practice, but a regulatory necessity. The CRA’s lifecycle approach means that security management does not end once a product reaches the market. Instead,
Cyber Resilience Act, Part 3: Transparency becomes a product requirement
Read the original article
eenewseurope.com →