For connected hardware, good CRA user information links the physical product, its firmware and its network or cloud environment. Users need to know exactly which device they have, how to commission and update it securely, how long security support lasts and how to remove data and trust relationships when the device is retired or transferred.
Use Product Identification That Works for Physical Devices
Annex II point 3 requires the product name and type together with information enabling unique identification. Connected hardware can require model numbers, hardware revisions, serial ranges or firmware versions because the same commercial product name can cover devices with different security characteristics or update paths.
- Product name and type.
- Model identifier.
- Hardware revision where relevant.
- Firmware version where relevant.
Explain the Intended Security Environment
Annex II point 4 requires the intended purpose and security environment provided by the manufacturer. For connected hardware, this can include expected network placement, physical-access assumptions, supported wireless protocols, cloud dependencies, administrative roles and the trusted devices or applications used to manage the product.
- Network placement assumptions.
- Physical-access assumptions.
- Supported connection methods.
- Cloud or management dependencies.
Make Secure Commissioning Steps Explicit
Annex II point 8(a) requires measures during initial commissioning and throughout the product lifetime to ensure secure use. Connected-device instructions should explain secure pairing, administrator creation, credential changes where relevant, update checks, network onboarding and any security-sensitive default settings that users need to understand.
- Secure pairing or enrolment.
- Administrator or owner setup.
- Initial firmware update check.
- Security-sensitive default settings.
Communicate Physical and Network Risk Conditions
Annex II point 5 requires known or foreseeable circumstances that may lead to significant cybersecurity risks. For connected hardware, those circumstances can include installation in an exposed physical location, direct internet exposure of a management interface, use on an unsuitable network, disabled authentication or continued operation with unsupported firmware.
- Unsafe physical exposure.
- Unsafe network exposure.
- Disabled security controls.
- Unsupported firmware or deployment.
Explain Firmware and Security Update Installation
Annex II point 8(c) requires instructions on how security-relevant updates can be installed. Connected hardware documentation should explain whether firmware updates are automatic, delivered through a companion application, installed locally or applied through another management system. Users also need to understand power, connectivity or restart requirements that can affect successful installation.
- Firmware update mechanism.
- Automatic or manual behaviour.
- Connectivity and power prerequisites.
- How to verify the installed version.
Explain Automatic Security-Update Controls
Annex II point 8(e) requires information explaining how the default setting enabling automatic installation of security updates can be turned off. Where connected hardware exposes that control, the instructions should accurately identify it and explain relevant security consequences so users understand the tradeoff involved in disabling automatic security updates.
- Identify the automatic-update setting.
- Explain how it can be changed.
- Explain relevant security consequences.
- Keep instructions aligned with actual device behaviour.
State Device Security Support Separately From Cloud Service Marketing
Annex II point 7 and Article 13(19) require clear security-support information and the support end date. Connected products can depend on cloud services or subscriptions with different commercial terms. Manufacturers should make clear how long product vulnerability handling and security updates are provided rather than forcing users to infer cybersecurity support from a cloud subscription or warranty period.
- State the security support end date.
- Identify firmware support expectations.
- Separate commercial subscription terms.
- Explain material cloud dependency where relevant.
Cover Ownership Transfer and Secure Decommissioning
Annex II point 8(d) requires secure decommissioning instructions including secure removal of user data. Connected hardware can retain Wi-Fi credentials, tokens, account links, local recordings, access codes or cryptographic material. Retirement or transfer instructions should explain how to remove those relationships rather than treating a physical factory reset as sufficient without verification.
- Remove local user data.
- Remove network credentials.
- Revoke account or cloud associations.
- Reset access credentials and ownership state.
Keep Hardware User Information Version-Aware
Connected hardware often combines a long-lived physical platform with changing firmware. User information should identify which instructions apply to which hardware and firmware combinations. A current firmware interface should not silently replace historical guidance for supported devices that still use a different update or configuration path.
- Map instructions to hardware revisions.
- Map instructions to firmware versions.
- Preserve supported historical guidance.
- Review instructions after major firmware changes.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.