The CRA for embedded & firmware teams
The Cyber Resilience Act applies to devices with digital elements, but firmware needs vendor SBOM plus binary-derived inventory, honesty about HEX/encrypted images, and a long-support rebuild path.
Generic CRA guidance assumes a simple software supply chain. Embedded and IoT products break that assumption: the firmware is cross-compiled, may lack package metadata, ships on hardware you support for years, and updates over the air. Here is what changes.
Why embedded CRA compliance is different
Vendor SBOM vs what is in the binary
Yocto/Buildroot/Android-like images often ship an incomplete vendor document. Deriving an inventory from the image and comparing closes the gap market surveillance cares about.
Bare-metal and encrypted images
Intel HEX, S-record, and encrypted images may yield an empty derived SBOM. The honest path is a vendor SBOM from the build system, and saying so before analysis, not after.
Long support windows
Security updates are required for the support period, a minimum of five years. You need a rebuild path when a patch is required years later.
Article 14 on shipped firmware
From 11 Sep 2026 you must know if an actively exploited CVE appears in a product already on the market, and when you became aware.
Where alloy-it fits
alloy-it treats products and releases as the CRA unit of record: vendor SBOM upload, on-demand firmware-derived inventory, compare, continuous rescan, triage, Article 14 awareness, and evidence packs. Blueprints close the reproduce leg when you must rebuild an affected release years into the support period.
It is not a complete legal-compliance or CE-marking solution, and it does not submit to ENISA. See the CRA compliance checklist →
CRA compliance hub
CRA overview for embedded & firmware
What the Cyber Resilience Act requires, the deadlines, and how manufacturers of products with digital elements comply.
CRA SBOM requirements
Format, scope, and per-version rules for a CRA-compliant product Software Bill of Materials.
CRA compliance checklist
A practical checklist mapping each CRA obligation to what your team must do.
Vulnerability handling & Article 14
24h / 72h / 14-day reporting, KEV/EUVD, awareness clock, and what Sep 2026 actually requires.
Build-environment SBOM
Toolchain and build-time dependencies for technical docs: useful depth, but not what Sep 2026 reporting requires.
This page provides general information about the EU Cyber Resilience Act and is not legal advice. The regulation and its harmonised standards are still evolving: consult the official EU, ENISA, and BSI sources and qualified counsel for your specific product. alloy-it helps with product inventory, SBOM monitoring, triage, Article 14 evidence, and the rebuild path; it is not CE-marking software, not a notified body, and does not submit reports to ENISA or national CSIRTs.
Run CRA operations on your firmware
Product inventory, vendor vs derived SBOM, triage, and Article 14 readiness, start free.