Design & Reuse
Catalog of SIP Cores
System on Chip design resources

Industry Expert Blogs

Securing the future of European connected devices: the Cyber Resilience Act (CRA)

Matthew Stubbs - PQShield
August 17, 2026

The regulatory landscape for connected devices in Europe is undergoing a massive shift.

The EU Cyber Resilience Act (CRA) is at the center of the transition. It mandates legally-binding obligations to manufacturers, developers and hardware vendors, ensuring the security of products with digital components, and it specifies milestones for compliance that are about to come into force.

The CRA is designed to be forward-looking, rather than demanding standard cybersecurity defenses. Like a regulatory lens, it helps focus organizations towards state-of-the-art cryptography, supply-chain transparency, and naturally, quantum readiness, all in advance of the next generation of threats.

Timelines

The CRA specifies a very clear roadmap for compliance.

  • Sep 11 2026: Mandatory vulnerability reporting to ENISA comes into effect. Organizations are required to have processes in place to identify and report security incidents
  • Dec 11 2027: The CE Mark is required for compliant, connected products, and all products with digital elements on the EU market must comply with the CRA requirements.

This aligns with a number of international guidelines, including the US CNSA 2.0 targeting PQC implementation by 2035, as well as BSI and ANSSI, pushing for a phasing out of classical cryptography in preference of hybrid post-quantum/classical solutions over the next few years.

The headline news is that over the next decade, classical cryptography will be phased out in favor of full migration to PQC by 2035.

Engineering blueprint

Meeting PQC transition objectives requires a blueprint. Our suggestion is a phased approach:

  1. Cryptographic audit. Map every instance of public-key cryptography (RSA, ECC) currently deployed across the ecosystem.
  2. Secure lifecycles. Transition development processes to align with mature standards, and enforce secure-by-design methodologies across hardware and software teams.
  3. Ascertain supply chain transparency. Track all dependencies and provide an auditable PQC inventory.
  4. Long-Term Support. Commit to active vulnerability monitoring, remediation, and patching for a minimum 5-year post-delivery window.

CRA mandates

Essentially, the CRA mandates the following, each of which can be fulfilled by PQShield.

  • Implementation of state-of-the-art cryptography – Drop-in hybrid SDKs in PQCryptoLib help satisfy BSI/ANSSI hybridization rules
  • Guarantee of a secure supply chain – Delivery of turnkey SBOMs and compliance paperwork
  • Enforcing vulnerability and handling updates – Secure development practices with a minimum 5-year post-delivery support and vulnerability monitoring, reporting and remediation

Our ultra-small, ultra-fast and ultra secure IP is designed for specific constraints including resource-constrained electronics (PQMicroLib), high-performance, scalable PQC (PQPerform) and heavy industrial and CNI security (PQPlatform). With regulations tightening, we’re particularly focused on ensuring that compliance is high on the priority list, and the impact of the CRA cannot be understated over the course of the next few years.