CRA reporting duty from 11 Sept 2026. Clarify your exposure in a free intro call Request now

CRA readiness for embedded and IoT manufacturers

Technical assessment and implementation at firmware level – complemented by our partner law firm where needed.

From 11 September 2026, the CRA reporting obligations apply to actively exploited vulnerabilities and severe security incidents. The initial early warning is generally due within 24 hours.

From 11 December 2027, the essential requirements of the Cyber Resilience Act apply to products in scope, including conformity assessment and CE marking.

Which market this page is about

The Cyber Resilience Act is EU regulation and applies across all member states. What I advise on is the concrete implementation for the German market: the German authorities and notified bodies, the documentation practice expected here, and, where legal questions arise, our German partner law firm. I work with you in English, but the regulatory context I know inside out is the German one.

Does any of this sound familiar?

What I do for you

Scope check

One day of analysis plus a written report: a technical pre-assessment of CRA exposure, product category and required actions. Legal edge cases can be reviewed separately by our partner law firm on request.

You receive a technical assessment with open legal questions, priorities and next steps. Fixed price, credited against a follow-up engagement.

Gap analysis, Annex I

Your products checked against the essential requirements of the CRA, directly at firmware level.

Reporting process by 11 September 2026

A working process for the 24-hour early warning, the subsequent 72-hour notification and the final report: roles, procedures and templates, verified in a test run.

Implementation in firmware

SBOM pipeline, secure boot, signed updates, vulnerability handling. This is the part you cannot read up on.

For clarity: I advise and prepare things technically; legal advice is provided exclusively by our partner law firm and is commissioned and billed separately. Responsibility for the declaration of conformity and CE marking remains with the manufacturer. Which conformity assessment procedure is required depends on the product category, the harmonised standards applied and any existing certifications. Certain important and critical products require an external assessment.

Reference: series-production IoT device with secure OTA

For torcbrain I developed large parts of the software of an IoT cordless high-torque screwdriver: embedded Linux, a secure bootloader with TrustZone-protected M4 firmware IP protection, secure OTA updates, remote management and device administration via the cloud. The system has been in the field for over two years, and idastroem runs the cloud operations to this day. More in the blog.

torcbrain IoT cordless high-torque screwdriver

Your contact

Markus Kräutner, Dipl.-Inf.

Markus Kräutner

Dipl.-Inf., Managing Director of idastroem GmbH

25 years of software development for electronics and industrial automation. I have shipped secure boot, encrypted firmware and secure OTA updates in series-production devices long before the CRA made them mandatory.

  • • Embedded security in series production: cordless tools, dosing technology, industrial controls
  • • SBOM, reporting processes and technical documentation under the CRA
  • • Embedded Linux, Buildroot/Yocto, STM32, Nordic, ESP32
  • • Cloud connectivity and operations, hosted in Germany

Clarify your exposure before 11 September

30 minutes are enough for a first assessment. Free of charge, no obligation. If I cannot help, I will tell you during the call.

Arrange a call now

How we work together

1

Free intro call

30 minutes: products, connectivity, deadlines. Afterwards you know whether you need to act.

2

Scope check at a fixed price

One day of analysis plus a written report: a technical pre-assessment of CRA exposure, product category and required actions. Legal edge cases can be reviewed separately by the partner law firm on request.

You receive a technical assessment with open legal questions, priorities and next steps. Fixed price, credited against a follow-up engagement.

3

Implementation

Gap analysis, reporting process, SBOM pipeline or firmware hardening, depending on what the check turns up. With clear milestones.