INDUSTRIES
Sector-specific regulatory pictures for connected products.
How safety and cybersecurity obligations combine in each sector, and what a typical engagement covers.
- DefenceDefence: system safety and cybersecurity readinessDefence programmes sit partly outside CRA scope but face equally demanding, often stricter, national safety and security assurance regimes.
- TelecomTelecom: connected infrastructure and CRA/NIS2 overlapTelecom sits at the intersection of infrastructure-operator regulation and product-manufacturer regulation, often within the same organisation.
- AutomotiveAutomotive: functional safety, cybersecurity and type approvalThe vehicle itself has its own dedicated regulatory stack; CRA relevance in automotive concentrates on non-type-approved connected accessories and aftermarket products.
- Medical devicesMedical devices: MDR, IEC 62304 and CRA interactionMedical devices sit largely outside the CRA by design, but MDR-driven cybersecurity expectations have converged substantially with what the CRA would otherwise require.
- Industrial automationIndustrial automation: IEC 62443, machinery safety and CRAIndustrial automation carries the heaviest overlap of any sector: functional safety, cybersecurity and product regulation all apply simultaneously with no broad exclusions.
- EnergyEnergy: NIS2, critical infrastructure and connected equipmentEnergy combines the heaviest NIS2 operator obligations with full CRA exposure for the connected equipment that increasingly makes up grid infrastructure.
- Connected productsConnected products and consumer IoT under the CRAConsumer and general connected products are the CRA's baseline case: the requirements that apply to everything else are calibrated against this population.