EU Cyber Resilience Act
CRA compliance for IoT devices
Connected IoT devices are squarely products with digital elements, so the Cyber Resilience Act applies. Most are default-category and can self-assess — if the firmware’s components, updates and vulnerability handling are documented.
Which IoT categories are “important”, not default
A handful of consumer-IoT functions are explicitly listed as important products under CRA Annex III, Class I — not default category: smart-home general-purpose virtual assistants; smart-home products with security functionality (smart door locks, security cameras, baby monitors, alarm systems); internet-connected toys with social-interactive or location-tracking features; and personal wearables with a health-monitoring purpose that aren't already covered by EU medical-device rules.
If your device falls into one of these, it follows a stricter conformity route than the rest of this page describes — see our guide on notified bodies for what that actually changes.
The firmware SBOM problem
Most IoT compliance work is really an SBOM problem: firmware often bundles a Linux distribution, a vendor SDK, and third-party libraries with no clean manifest anywhere. An accurate SBOM has to come from scanning the actual build artifact — the compiled firmware image — not just a source-code repository, since a shipped image can differ substantially from what's in source control (cross-compiled, patched, vendor blobs added at build time).
Secure updates over the device's lifetime
IoT devices are often deployed for years with little further attention from the manufacturer. The CRA's secure-update requirement (Annex I, Part I, (2)(c)) and the obligation to disseminate updates without delay and, ordinarily, free of charge (Annex I, Part II, (8)) mean an over-the-air update mechanism and a defined support period aren't optional extras — they're central to whether the product can self-assess at all.
What to focus on
- Check Annex III first — some smart-home and toy categories are important, not default.
- Scan the actual firmware image for your SBOM, not just source manifests.
- Ship an OTA update mechanism and a stated support period.
- Compile Annex VII documentation and sign the Declaration of Conformity for CE marking.
Frequently asked questions
- Does the CRA apply to IoT devices?
- Yes — connected IoT devices are products with digital elements and are in scope. Most are default-category and can self-assess.
- Which IoT products are “important” rather than default under the CRA?
- Smart-home general-purpose virtual assistants, smart-home security products (locks, cameras, baby monitors, alarms), certain connected toys, and some health-monitoring wearables are listed as important (Annex III, Class I). Everything else connected is typically default category.
General information about the EU Cyber Resilience Act — not legal advice. Normproof provides tooling and audit-ready evidence; the manufacturer self-declares conformity. For your specific product, run the free readiness check or consult a qualified advisor.