Skip to content

INDUSTRY · Connected products

Connected products and consumer IoT under the CRA

Consumer and general connected products are the CRA's baseline case: the requirements that apply to everything else are calibrated against this population.

LAST REVIEWED

Regulatory picture

The CRA's essential requirements in Annex I apply to any product with digital elements — hardware or software — placed on the EU market, unless a sector-specific exclusion applies (defence, certain medical devices, type-approved vehicles, and similar). For consumer IoT, smart home devices, wearables, connected appliances and general-purpose software, no such exclusion typically applies, making this the sector the CRA was primarily designed around. Relevant baseline technical guidance includes ETSI EN 303 645 for consumer IoT security, though harmonised standards specific to the CRA are still being developed. Products classified as 'important' under Annex III — such as identity management systems, browsers, password managers, firewalls, smart home general-purpose virtual assistants and certain other categories — face stricter conformity assessment; most other consumer and general connected products can use manufacturer self-assessment.

Typical engineering challenges

  • Establishing a secure development lifecycle proportionate to product cost and margin, since consumer IoT products often operate on thin engineering budgets relative to enterprise or industrial equipment.
  • Defining and communicating a realistic support period at the point of sale, then actually delivering vulnerability handling and updates for that period.
  • Building a software bill of materials (SBOM) for products that integrate significant third-party and open-source components, often with limited visibility into upstream dependencies.
  • Designing secure default configurations and update mechanisms for products that may be resold, given away or go unmonitored by the end user for years.
  • Meeting the 24 and 72-hour vulnerability and incident reporting timelines with engineering teams sized for feature development rather than security operations.

How CRA interacts with sector rules

For most connected products, the CRA is the primary and often only applicable EU product cybersecurity regulation, though radio-connected products additionally intersect with the RED cybersecurity delegated act, and this population is also the one most directly targeted by evolving harmonised standards and CRA-specific guidance as they are published. Because there is usually no competing sector-specific regime to lean on, manufacturers in this category generally need to build CRA compliance capability from the essential requirements directly rather than adapting an existing sector framework.

What a typical engagement covers

  • Product classification against Annex III and Annex IV to confirm the available conformity assessment route.
  • Secure development lifecycle design proportionate to product scale and margin.
  • SBOM generation and third-party component risk assessment.
  • Vulnerability handling, disclosure and reporting process design against the 24 and 72-hour CRA timelines.

Frequently asked questions

Does the CRA apply to a simple smart plug or connected light bulb?

Yes. Any product with digital elements that can connect to a network or another device falls within the CRA's broad definition, and simple consumer IoT devices such as smart plugs are squarely in scope, generally using the self-assessment conformity route unless classified otherwise.

What conformity route applies to most consumer IoT products?

Most consumer IoT and general connected products are not listed in Annex III or Annex IV and can use manufacturer self-assessment (internal control), provided the manufacturer produces complete technical documentation and a genuine risk assessment.

Is open-source software used in a connected product subject to the CRA?

Open-source software supplied outside the course of a commercial activity is generally not itself directly regulated, but a manufacturer that integrates open-source components into a commercial product remains responsible for the security of the finished product, including understanding and managing the risk those components introduce.

What happens if a manufacturer stops supporting a connected product?

The manufacturer must define a support period at the point of sale and provide vulnerability handling for that period. Once the defined and communicated support period ends, active vulnerability handling obligations for that product generally end too, provided the end of support was properly disclosed to users.

Do smart home virtual assistants face stricter CRA requirements?

General-purpose virtual assistant products are among the categories identified under Annex III as 'important', which can require stricter conformity assessment than the default self-assessment route, depending on the specific classification and any applicable harmonised standards.