Cyber Resilience Act (CRA)
What is the Cyber Resilience Act (CRA)?
The Cyber Resilience Act (CRA) is a European Union (EU) regulation, Regulation (EU) 2024/2847, that establishes mandatory cybersecurity requirements for products with digital elements sold (formally, placed on the market) in the EU. Unlike earlier regulations that focused primarily on data protection or organizational processes, the CRA places cybersecurity directly into the product development lifecycle. Manufacturers are expected to build security into products from the outset, maintain that security throughout the supported life of the product, and demonstrate that cybersecurity risks have been identified, mitigated, documented, and managed.
Why does the Cyber Resilience Act matter?
The CRA reflects a fundamental shift in how cybersecurity is viewed. Security is evolving from a competitive feature to a measurable product requirement, forcing organizations to think beyond initial product release to encompass vulnerability management, coordinated disclosure, secure updates, technical documentation, and long-term support. For semiconductor companies, this aligns security with other engineering priorities, such as performance, power efficiency, functional safety, reliability, and time to market.
Why is the CRA important for semiconductor companies?
The CRA signals a broader global movement toward product accountability. The CRA regulates products with digital elements. A definition that also includes hardware components sold separately. Chips with security-related functionality are expressly named, and chips or IP blockd delivered only to an integrator are regulated through the finished product that contains it.
Today’s SoCs integrate CPUs, GPUs, NPUs, memories, chiplets, firmware, NoCs, security IP, and extensive third-party intellectual property. Security weaknesses in any layer can affect the resilience of the finished product. As a result, semiconductor companies are increasingly expected to provide evidence that security has been considered throughout architecture, integration, verification, validation, and lifecycle support.
What are the key CRA principles?
- Security by design and by default
- Cybersecurity risk assessment throughout development
- Technical documentation and traceability
- Coordinated vulnerability disclosure
- Secure software and firmware update mechanisms
- Lifecycle vulnerability management
- Clear support and end-of-support transparency
What is security by design?
The CRA requires manufacturers to address cybersecurity during the architecture phase, and that expectation reaches down to silicon and IP. This means understanding how security-sensitive assets move through a system, identifying trust boundaries, evaluating third-party IP, documenting security assumptions, and maintaining visibility into dependencies. As AI systems, heterogeneous computing, and chiplet-based architectures become more complex, proving that a design is trustworthy becomes increasingly important.
Hardware assurance and regulatory readiness
Hardware assurance provides confidence that a design behaves as intended while reducing exposure to unintended functionality or exploitable weaknesses. The CRA’s emphasis on accountability increases demand for architectural visibility, traceability, security evidence, and collaboration between engineering, product security, compliance, and supply-chain teams. Organizations that can demonstrate these capabilities will be better positioned to meet evolving customer and regulatory expectations.
How does this relate to Arteris?
Arteris helps semiconductor organizations manage growing design complexity through intelligent network-on-chip (NoC) technology, SoC automation, and hardware security assurance capabilities from Cycuity. Together these technologies improve visibility into SoC architectures, data movement, security-sensitive assets, and security relationships, helping engineering teams strengthen security-by-design practices while generating the evidence needed to support increasingly rigorous cybersecurity and compliance requirements.
Frequently asked questions
When does the CRA take effect?
Reporting obligations (Article 14) begin September 11, 2026.
Essential requirement, conformity assessment, and CE marking from December 11, 2027.
What products are covered by the Cyber Resilience Act?
Most products with digital elements placed on the EU market are covered, including connected hardware, software, firmware, IoT devices, industrial systems, and embedded products, although requirements vary by product category.
Are any products excluded from the Cyber Resilience Act?
Yes. Certain products are excluded from the CRA because they are already subject to sector specific EU legislation. Examples include medical devices, in vitro diagnostic medical devices, motor vehicles and their components covered by EU vehicle type-approval regulations, as well as aircraft and certain aviation products governed by EU aviation regulations. It is worth searching for exclusions that may be relevant to you.
Does the CRA apply directly to semiconductor companies?
It can. A chip placed on the EU market on its own is a regulated product in its own right. A chip or IP block so to an integrator is reached/regulated indirectly: Article 13(5) requires the integrating manufacturer to exercise due diligence over third-party components. Basically, the responsibility cascades down from in market product down to IP level. Each layer should prepare to answer questions from their customers higher up in the value chain.
What does security by design mean under the CRA?
It means cybersecurity should be incorporated from the earliest stages of development through architecture, implementation, validation, deployment, maintenance, and end-of-support rather than added late in development.
How can semiconductor companies prepare for CRA compliance?
Organizations should strengthen hardware security assurance, improve architectural visibility and traceability, document cybersecurity decisions, manage third-party dependencies, establish vulnerability management processes, and plan for long-term lifecycle support.
Resources
Lorem Ipsum has been the industry’s standard dummy text ever since the 1500s, when an printer.
Latest News