Independent information resource Product security · EU CRA
CRA scope / 12

Does the CRA Apply to Connected IoT Products?

Learn how the Cyber Resilience Act applies to connected IoT products, including connected hardware, embedded software, direct and indirect data connections, cloud functionality, components and product classification.

IN BRIEF

Many IoT devices are strong candidates for CRA scope because they combine digital hardware or software with direct or indirect connections to devices or networks. The complete product boundary can also include necessary manufacturer-controlled cloud functionality, while classification depends on the product's core functionality rather than the IoT label alone.

01 / 09

IoT Is a Useful Industry Label, Not the CRA Legal Definition

The CRA does not depend on a product being marketed as an Internet of Things device. Its central concept is the product with digital elements. A connected hardware product containing software, capable of processing or transmitting digital data and intended to connect directly or indirectly to another device or network can enter CRA scope even when its manufacturer never uses the term IoT.

02 / 09

Connected Hardware Commonly Meets the Product Definition

IoT products often combine processors, sensors, firmware, embedded applications, radios, wired communications interfaces and other digital functions. CRA analysis should reflect that complete architecture. The cybersecurity risk assessment should not treat the hardware enclosure, firmware and connected software as unrelated systems when they operate together as one marketed product.

03 / 09

Direct Internet Access Is Not Required

Article 2 refers to direct or indirect logical or physical data connections to a device or network. An IoT device can therefore require CRA analysis even where it communicates only through a local gateway, hub, smartphone, industrial controller or other intermediary. Bluetooth, Zigbee, Wi-Fi, Ethernet, cellular links, wired interfaces and other forms of data connectivity can all be relevant depending on the product.

04 / 09

Indirectly Connected Products Can Still Create Cybersecurity Risk

The CRA recitals recognise that products connected to larger electronic information systems can become attack vectors and that cyber threats can propagate through products before reaching another target. A device does not therefore become irrelevant merely because it sits behind a gateway or has limited network functionality. The manufacturer should assess how compromise of the product could affect users, connected devices and networks.

05 / 09

Manufacturer-Controlled Cloud Functions Can Form Part of the Product

Connected products frequently depend on manufacturer cloud services for command, configuration, authentication, storage or other functions. Where the remote software is designed and developed by the manufacturer or under its responsibility and its absence would prevent the product from performing one of its functions, it can qualify as a remote data processing solution. The CRA product boundary can therefore include necessary remote functionality as well as the physical device.

06 / 09

Third-Party Infrastructure Is Not Automatically Part of the Product

An IoT manufacturer can rely on cloud hosting, connectivity providers, analytics platforms and other external services. Those services do not automatically become part of the product merely because the product depends on the wider infrastructure. The remote data processing definition should be applied function by function, with particular attention to who is responsible for the relevant software and whether the processing is necessary for a product function.

07 / 09

Connected Components Need Supply-Chain Visibility

IoT products can include third-party radios, operating systems, protocol stacks, libraries, secure elements and other components. The finished-product manufacturer remains responsible for assessing cybersecurity risk arising from integrated components. Separately marketed components can also have their own CRA position. Maintaining version and supplier information is therefore important for both product security and vulnerability response.

08 / 09

Not Every IoT Product Has the Same CRA Classification

A connected product being within CRA scope does not automatically make it an important or critical product. Classification depends on core functionality and the categories established by the Regulation and related implementing material. Some connected security products and other specified categories receive stricter treatment, while many ordinary connected products remain within the general CRA product framework.

09 / 09

Build an IoT Product Boundary Before Mapping Annex I

For each connected product, record the marketed device, embedded software, firmware, communications interfaces, companion applications, necessary remote functions, third-party dependencies and supported versions. Identify which remote services meet the CRA remote data processing definition. This architecture record provides the foundation for scope, classification, cybersecurity risk assessment, vulnerability handling and technical documentation.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.