Independent information resource Product security · EU CRA
CRA software supply chain / 13

Assessing Security Risks in OEM Components

How manufacturers can assess cybersecurity risk in OEM-supplied software, firmware and hardware components under the Cyber Resilience Act.

IN BRIEF

An OEM may perform substantial engineering, but the finished-product manufacturer still needs enough evidence to understand and manage the cybersecurity effect of the integrated component. High-trust or high-privilege components deserve deeper review than low-impact commodity parts.

01 / 08

OEM Is a Commercial Label, Not a CRA Risk Category

The CRA does not assign a special security status to OEM components. Assess the actual component, how it is integrated and what cybersecurity consequences it can create in the finished product.

02 / 08

Map Component Privileges and Connectivity

Identify whether the component can access networks, credentials, sensitive data, update channels, boot processes or security-critical functions. Greater privilege and exposure generally justify deeper supplier and technical review.

03 / 08

Review Firmware and Embedded Software

OEM hardware frequently includes firmware or embedded libraries that are easy to overlook in a software-only inventory. Those elements can introduce vulnerabilities and should be represented in component records where relevant to product security.

04 / 08

Assess Update Capability

Determine how the OEM provides security fixes, whether the manufacturer can distribute them safely and how long the supplier will support the component. An unpatchable core component can create long-term product risk.

05 / 08

Check Provenance and Authenticity

Understand the supplier, manufacturing or software source, release identifiers and any signing or authenticity controls available. Provenance supports confidence that the component integrated into the product is the one that was assessed.

06 / 08

Review Known Vulnerabilities and Security History

Use advisories, vulnerability databases and supplier records to understand past security issues and response quality. A history of delayed fixes or unsupported versions can be relevant to selection risk.

07 / 08

Assess Integration-Specific Threats

Supplier testing may not cover the exact privileges, interfaces or configurations used in the finished product. Include OEM components in the product cybersecurity risk assessment and perform additional testing where integration creates new attack paths.

08 / 08

Preserve Evidence and Reassess Material Changes

Keep supplier evidence, component versions, firmware records, support commitments and assessment decisions. Reassess when the OEM changes a security-relevant component, firmware branch, supplier or support model.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.