Set It and Forget It – Cyber Resilience Act Ends the Free Ride for Disposable IoT
Remember 2022? Back in Brussels, officials were drafting a paper with the clunky name Cyber Resilience Act (CRA). Most IoT manufacturers greeted the early drafts with a tired smile, following the old motto: just EU bureaucracy. It’ll take years to come into force, and by the time it does, it won’t be as bad as it sounds.
- The Cyber Resilience Act obligates IoT manufacturers to security-by-design and mandatory updates for the full expected lifetime of a product, at least five years.
- Starting September 11, 2026, manufacturers must report actively exploited vulnerabilities within 24 hours to ENISA and the relevant national CSIRT.
- Manufacturers that keep relying on cheap hardware without ongoing software maintenance risk being shut out of the EU market once the CRA’s obligations take full effect at the end of 2027.
Those years have almost passed. It’s summer 2026 – and the Brussels paper tiger has turned into a sharp legal sword whose transition periods are running out mercilessly. Suddenly, development departments and boardrooms at hardware manufacturers are gripped by real anxiety. Because the CRA demands something that used to spell commercial ruin in classic consumer IoT: lasting responsibility for your own software.
The Golden Age of Disposable IoT Is Over
The standard recipe for many IoT vendors used to be simple: take a dirt-cheap microcontroller from the Far East, slap together some firmware, wrap it all in nice plastic, and sell it for 19.99 euros at the hardware store, the discounter, or on Amazon. Once the device reached the customer, the motto was: close your eyes and carry on. Security updates? Too expensive. Vulnerability management? Not part of the plan.
When the firmware turned into a wide-open door for botnets after two years, manufacturers simply released “Version 2.0” and let the old model wither on the vine. The Cyber Resilience Act now puts a swift end to this cheerful practice. Its core requirement is simple: security-by-design and a guaranteed update obligation for the full expected lifetime of the product (at least five years, though). Just how far this is from a minor formality is illustrated by this case – even though, under current law, it doesn’t yet constitute a violation, but rather exposes exactly the gray zone that will close once the update obligation takes effect.
The Server Room Nightmare: The Over-the-Air Dilemma
What sounds like a dream to consumers and IT security experts is, for many manufacturers, an organizational and financial disaster. Companies that used to see themselves as pure plastic-and-hardware shops suddenly have to build complex software infrastructure:
Secure OTA updates: How do you roll out cryptographically signed firmware patches reliably across millions of scattered smart-home devices, without the device turning into a useless paperweight the moment the connection drops?
24-hour reporting duty: Starting September 11, 2026, actively exploited vulnerabilities must be reported within 24 hours to ENISA and the relevant national CSIRT. Ever tried assembling an emergency patching team at 3 a.m. on a Sunday for a 15-euro smart relay – knowing full well that this clock will soon be ticking for real?
The cost trap: The one-time margin from selling the device is used up within two months. But the cost of maintaining the software supply chain (bill of materials) keeps running for years.
When Regulators Become Software Architects
The irony: it’s the often-maligned EU bureaucracy that is forcing the tech industry into a discipline it never adopted on its own. The CRA is radically reshuffling the market. Anyone who wants to sell connected hardware in the EU going forward has to treat software competence as a core product, not an afterthought. The days when IoT devices flooded networks as digital throwaway items are numbered.
For manufacturers, that means one of two things: either they learn, fast, how to run professional software lifecycles – or they disappear from the market. No need to feel sorry for them. Anyone still surprised in 2026 that connected hardware also needs to be secured heard the warning shot four years ago… and simply chose to ignore it.
PS: And the next EU requirement is already waiting in the wings: the migration of critical systems to quantum-safe cryptography by 2030 – currently formulated as a roadmap by the member states, not yet binding law. Maybe manufacturers will learn something from 2022 after all …
The Cyber Resilience Act is an EU regulation that sets binding cybersecurity requirements for products with digital elements. It obligates manufacturers to security-by-design, ongoing vulnerability management, and software updates for the full expected lifetime of the product.
The reporting obligation for actively exploited vulnerabilities takes effect on September 11, 2026. Manufacturers must report such incidents within 24 hours to ENISA and the relevant national CSIRT.
The CRA requires updates for the full expected lifetime of the product, but at least five years. This period applies regardless of whether the product has already been replaced on the market by a successor model.
Manufacturers must build infrastructure for secure OTA updates, ongoing vulnerability management, and reporting processes. These costs run for the entire product lifetime, while the sales margin is typically used up within just a few months.
Products that don’t meet the CRA’s requirements can no longer carry CE marking or be sold in the EU without a valid conformity declaration. For manufacturers that don’t build proper software lifecycles, this effectively means exclusion from the EU market.












