Secure & comply
Embedded cybersecurity and Cyber Resilience Act readiness
Engineering support for manufacturers who must adapt their devices to the EU Cyber Resilience Act: secure boot, secure updates, SBOM and a working vulnerability-handling process.
· by BCF Embedded engineering team
What the CRA changes for device makers
The CRA applies in stages. Reporting obligations already apply, also to products placed on the market earlier.
December 2024
Regulation (EU) 2024/2847 enters into force
The Cyber Resilience Act becomes law, with staged application dates.
27 July 2026
Commission guidance for manufacturers
The European Commission publishes practical guidelines for manufacturers.
11 September 2026
Reporting obligations apply
Manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA and the competent national CSIRT through the Single Reporting Platform — also for products placed on the market before this date.
11 December 2027
Main obligations apply
Security-by-design requirements, SBOM, vulnerability handling and CE marking under the CRA apply to products placed on the EU market.
Reporting deadlines and penalties
- Early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident.
- Detailed notification within 72 hours.
- Final report: for vulnerabilities within 14 days after a fix or mitigation is available; for incidents within one month after the notification.
- Fines for breaching reporting obligations: up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher.
- Security updates must be provided for at least 5 years, or for the expected time of use if it is shorter.
Our engineering scope
Secure boot
A chain of trust from immutable code to the application. See secure boot and OTA.
Hardware crypto and key storage
Using the security features of your MCU or a secure element to protect keys.
Secure OTA
Signed, verified updates with rollback — designed with IoT & connectivity.
SBOM
Software bills of materials generated in the build for every release.
Vulnerability handling
Intake, triage, fixing and the 24/72-hour reporting procedure.
Logging
Security-relevant events recorded and available for incident analysis.
CRA readiness and gap analysis
A gap analysis compares your product and processes with the engineering requirements of the CRA and gives you a prioritised plan. Inputs, outputs and the format are described on the CRA readiness audit page.
What we do and what we don't
We do
- Assess firmware, hardware and update architecture against CRA engineering requirements
- Implement secure boot, secure OTA, SBOM generation and logging
- Set up a vulnerability-handling and reporting procedure with your team
- Prepare technical documentation that your legal and compliance advisers can use
We don't
- Provide legal advice or legal interpretations of the regulation
- Act as a conformity assessment (CE) body
- Certify products or issue declarations of conformity
Long-term support
CRA obligations last for the whole support period. We can maintain firmware, monitor components from the SBOM and prepare security patches for years after launch. For products already on the market, see legacy modernization.
Selected work
FAQ
Discuss your project
Describe your device and goal. An engineer replies within one business day.
Prefer e-mail?
[email protected]- Reply within one business day
- NDA available before any technical deep-dive
Our offices
Opole (Headquarters): ul. Technologiczna 2, 45-837 Opole
Wrocław (Office): ul. Strzegomska 42B, 53-611 Wrocław
Warsaw (Office): ul. Żurawia 6/12, 00-503 Warsaw