Cyber Resilience Act & firmware

Cyber Resilience Act firmware engineering for global manufacturers

Unix Consulting supports global manufacturers, including Chinese and Asian OEMs and ODMs, with firmware engineering, vulnerability management and Cyber Resilience Act evidence for products entering the European Union market.

Run the CRA program for an international manufacturer

We turn European requirements into an execution program aligned with the product, OEM/ODM supply chain and existing engineering teams. Work covers product scoping, manufacturer-importer-distributor roles, cybersecurity risk assessment, CRA classification and the conformity path before the product enters the EU market.

Manufacturer and OEM/ODM use cases

  • Connected device, IoT gateway, camera, sensor or controller entering the EU market: secure access, secure defaults, signed updates and installed-fleet management.
  • Router, access point, firewall, appliance or industrial equipment: hardening of services, protocols, administration interfaces, logs and recovery mechanisms.
  • European-branded product manufactured in China: clarify ownership of source code, signing keys, SBOM, fixes and support across the OEM, ODM, brand and importer.
  • Linux, OpenWrt, RTOS or microcontroller firmware: control the BSP, bootloader, toolchain, open-source components, CVEs and delivered versions.
  • Product already on the market without a structured security process: rebuild the inventory, establish the reporting channel, create the vulnerability backlog and drive the upgrade path.
  • Product relying on a mobile application, API or remote backend: review interfaces and remote data processing required for secure product operation.

Three engagement models

  • Takeover and hardening: audit firmware, build chain and update mechanisms, then remediate priority gaps and transfer the operating model to the manufacturer’s team.
  • Co-development: work inside the product team to design controls, automate evidence and support each release through EU market entry.
  • Managed firmware security: continuously operate SBOM, component monitoring, report triage, patch coordination, advisories, releases and support indicators.
  • European CRA coordination: maintain the compliance matrix and provide the technical interface for the brand, importer, distributor, laboratory or assessment body.

Firmware engineering and secure release lifecycle

  • Firmware review or development: architecture, attack surface, debug interfaces, secrets, permissions, cryptography and secure-by-default configuration.
  • Controlled build chain: dependencies, versions, reproducibility, source governance, artifact signing and environment separation.
  • Secure boot, signed updates, integrity verification, anti-rollback where required and a documented recovery process.
  • Security testing, static and dynamic analysis, targeted fuzzing, protocol review and update mechanism validation.

SBOM, vulnerability management and security maintenance

  • Actionable SBOM, third-party component inventory and version tracking for every release.
  • PSIRT and coordinated vulnerability disclosure process to receive, triage, fix and communicate vulnerabilities.
  • CVE and supplier monitoring, product impact analysis, prioritization, fixes, advisories and remediation evidence.
  • Security support, update and CRA reporting operations throughout the declared support period.

Technical documentation and European coordination

  • Requirement-risk-control-evidence matrix and technical material for the CRA documentation package.
  • Architecture, secure development, testing, vulnerability handling and release-history documentation.
  • User information, support policy, update instructions and input for the EU declaration of conformity.
  • Coordination with the importer, authorised representative, distributor, laboratories and notified body where the applicable route requires one.

Does the Cyber Resilience Act apply to manufacturers outside the EU?

Yes, when a hardware or software product with digital elements is made available on the EU market. Chinese, Asian, American and other non-EU manufacturers must therefore address CRA requirements in the product and European distribution chain.

Which products can you support?

Typical scopes include connected devices, network equipment, gateways, appliances, industrial controllers, embedded products and their associated software components or remote services. The exact regulatory scope is confirmed during scoping.

Can Unix Consulting take over firmware development and maintenance?

Yes. The engagement can range from reviewing existing firmware to securing the build chain, developing fixes, publishing signed releases and operating the vulnerability-management process.

Does Unix Consulting replace the manufacturer’s legal responsibility?

No. Unix Consulting acts as a technical and compliance partner. The manufacturer retains the responsibilities assigned by the regulation, and notified-body assessment remains independent where required.

Which CRA dates matter now?

Reporting obligations apply from 11 September 2026 and the regulation becomes fully applicable on 11 December 2027. Firmware lifecycle, evidence and vulnerability handling should be operational before those deadlines.

How long must security fixes be maintained?

The support period must reflect the expected product lifetime and is generally at least five years unless the expected use time is shorter. It must be defined, justified and communicated.