An OEM may perform substantial engineering, but the finished-product manufacturer still needs enough evidence to understand and manage the cybersecurity effect of the integrated component. High-trust or high-privilege components deserve deeper review than low-impact commodity parts.
OEM Is a Commercial Label, Not a CRA Risk Category
The CRA does not assign a special security status to OEM components. Assess the actual component, how it is integrated and what cybersecurity consequences it can create in the finished product.
Map Component Privileges and Connectivity
Identify whether the component can access networks, credentials, sensitive data, update channels, boot processes or security-critical functions. Greater privilege and exposure generally justify deeper supplier and technical review.
Review Firmware and Embedded Software
OEM hardware frequently includes firmware or embedded libraries that are easy to overlook in a software-only inventory. Those elements can introduce vulnerabilities and should be represented in component records where relevant to product security.
Assess Update Capability
Determine how the OEM provides security fixes, whether the manufacturer can distribute them safely and how long the supplier will support the component. An unpatchable core component can create long-term product risk.
Check Provenance and Authenticity
Understand the supplier, manufacturing or software source, release identifiers and any signing or authenticity controls available. Provenance supports confidence that the component integrated into the product is the one that was assessed.
Review Known Vulnerabilities and Security History
Use advisories, vulnerability databases and supplier records to understand past security issues and response quality. A history of delayed fixes or unsupported versions can be relevant to selection risk.
Assess Integration-Specific Threats
Supplier testing may not cover the exact privileges, interfaces or configurations used in the finished product. Include OEM components in the product cybersecurity risk assessment and perform additional testing where integration creates new attack paths.
Preserve Evidence and Reassess Material Changes
Keep supplier evidence, component versions, firmware records, support commitments and assessment decisions. Reassess when the OEM changes a security-relevant component, firmware branch, supplier or support model.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.