WebbyLab Blog IoT The EU Cyber Resilience Act: Why Legacy Firmware, Locked Vendor Clouds, and “The OEM’s Problem” Are Now Your Liability — and What to Build Before the Deadlines

The EU Cyber Resilience Act: Why Legacy Firmware, Locked Vendor Clouds, and “The OEM’s Problem” Are Now Your Liability — and What to Build Before the Deadlines

July 21, 2026
13 minutes to read

Written by:

Kostiantyn Oliynyk

Kostiantyn Oliynyk

Head of IoT at Webbylab

With a robust academic background in Telecommunication Systems Engineering, I apply my knowledge to lead innovations in the IoT domain. Starting as the first team member in the newly formed IoT department at WebbyLab, I've spearheaded its growth, fostering the expansion into embedded and hardware development alongside our core software projects. My dedication lies in pushing the boundaries of IoT technology, fostering a culture of innovation and excellence that profoundly impacts our clients' operational success.

FAQ

Does the EU Cyber Resilience Act apply to products already on the market?

Partially. Vulnerability and incident reporting obligations from 11 September 2026 cover products already made available on the EU market. Full requirements apply to products placed on the market from 11 December 2027 — and substantially modified existing products can fall into full scope.

Our legacy devices have no update mechanism — what does the CRA require?

The CRA requires manufacturers to provide security updates for a declared support period — generally at least five years. For legacy fleets, that means retrofitting update capability, placing a secure gateway in front of legacy units, or planning support-period obligations into the next product generation.

Does the CRA apply to companies that rebrand OEM products?

Yes. Anyone who markets a product with digital elements under their own name or trademark is the manufacturer under the CRA, with full obligations — regardless of who physically built the product.

Is the OEM vendor’s cloud part of our CRA scope?

Generally yes. The CRA covers a product’s remote data processing solutions that are necessary for its functions. If your devices depend on the vendor’s cloud to work, that cloud is part of your product’s compliance scope — even if you can’t control it.

What are the CRA deadlines and penalties?

Reporting obligations apply from 11 September 2026; all requirements apply from 11 December 2027. The top penalty tier is €15 million or 2.5% of global annual turnover, whichever is higher, for breaching the essential requirements or the core manufacturer and reporting obligations. Lower tiers of €10 million / 2% and €5 million / 1% apply to other breaches.

What’s the fastest realistic path from a legacy stack to compliance?

It depends on your setup. For OEM-sourced hardware, start with the vendor: if they’ll re-point the module to your own endpoint, that’s usually the cheapest and fastest fix; if they won’t — or can’t, because they don’t own the stack — an off-the-shelf industrial gateway is the quickest fallback, though it adds per-unit cost. For in-house legacy firmware: targeted modernization (OTA, encrypted transport, per-device identity) plus your own EU-hosted platform. A staged build starting with a web MVP typically establishes the compliance foundation within months.

Does the CRA apply to manufacturers based outside the EU?

Yes. The CRA is market-based, not location-based: it applies to any product with digital elements made available on the EU market, regardless of where the company or the factory sits. Non-EU manufacturers must have an EU-based authorized representative or rely on their importer/distributor, and the reporting route runs through that chain.

What counts as a “product with digital elements”?

Almost any hardware or software that connects, directly or indirectly, to a device or network — plus any remote data processing solution the product needs to perform a function. Connected heat pumps, boilers with companion apps, routers, industrial controllers, sensors, and the standalone software and components that go with them are all in scope.

Does buying a SaaS IoT platform make us CRA compliant?

No. A SaaS subscription does not transfer your manufacturer obligations, and it never becomes your asset. You remain responsible for conformity, reporting, and the support period for the product you place on the market. A “CRA-compliant” badge on a datasheet is not evidence — the credible answer names a conformity route (self-assessment, notified body, or an EU certification scheme).

How is the CRA different from NIS2, GDPR, and the Data Act?

The CRA governs the cybersecurity of the products you ship. NIS2 governs the security of your company’s own operations and services. GDPR governs personal data processing. The EU Data Act governs users’ access to the data their connected products generate. They overlap but don’t substitute for each other — a connected-product manufacturer typically touches all four.

Do connected products need CE marking for cybersecurity?

From 11 December 2027, products with digital elements placed on the EU market must carry CE marking backed by an EU Declaration of Conformity demonstrating CRA conformity. Without it, the product can’t legally be placed on the EU market from that date.

Does the CRA require an SBOM?

Yes. Manufacturers must draw up a software bill of materials in a commonly used, machine-readable format, covering at least the top-level dependencies of the product. It underpins vulnerability handling — you can’t triage what you can’t inventory.

What happens if we miss the 11 September 2026 reporting deadline?

The reporting duty under Article 14 becomes enforceable from that date for products on the EU market, including legacy fleets. Failing to report actively exploited vulnerabilities and severe incidents exposes you to the top penalty tier, alongside the practical risk of a public incident you had no process to handle. Microenterprises and small enterprises get relief specifically on the reporting-deadline timing, but not on the underlying obligations.

Rate this article !

27 ratingsAvg  / 5

You may also like
Up

2026 WEBBYLAB LLC. All rights reserved.