EU CRA – Cyber Resilience Act
In this blog series, we would like to keep you informed about the implementation of the Cyber Resilience Act (CRA) for IACBOX.
Overview
The CRA is an EU-wide regulation (EU 2024/2847) that applies to all products with digital elements. The only exceptions are products that are already subject to other or stricter regulations, such as those in the medical and automotive sectors.
Key points of the CRA:
- As an EU regulation, it applies directly and does not require implementation into national law (unlike NIS2).
- Products must be developed using a secure development process and must also be maintained accordingly.
- Security updates must be provided promptly and free of charge for the product’s lifetime, for a minimum of 5 years.
- Updates must remain available for download for 10 years.
- Pure SaaS products are also exempt, provided that no other on-premises products depend on them. This means that cloud services such as the IACBOX licensing and update servers are also covered by the CRA.
Timeline
- The CRA already entered into force in December 2024.
- However, there is a transition period until 11 December 2027. From that date onward, affected products may only be placed on the EU market if they comply with the CRA and bear the CE marking.
- Older products that are already in operation are exempt from the essential requirements and the CE marking obligation; however, the reporting obligations still apply.
- The first obligations will already apply from 11 September 2026. Actively exploited vulnerabilities or severe security incidents must be reported to ENISA, which will automatically inform the national CSIRT – in Austria, CERT.at.
Categorization
The CRA divides products into several categories, each subject to different requirements.
- Default – Products with digital elements: the majority of products offered with low security relevance. CRA conformity can be self-assessed.
- Important Products
- Class I: CRA conformity can be self-assessed when applying a harmonized standard (these are currently, as of August 2026, not yet available), or a notified body must assess CRA conformity.
- Class II: Hypervisors, intrusion detection/prevention systems, firewalls, and products whose primary features are designed for security. A notified body must assess CRA conformity.
- Critical Products: Hardware security devices, smart cards, secure elements, etc.
As a network product, IACBOX falls into the “Important Products – Class I” category. We intend to perform a self-assessment based on a harmonized standard, provided that an appropriate standard becomes available in time.
IACBOX Roadmap
- The current versions, v24 and v26, are still based on our proven proprietary Linux platform. After December 2027, these versions will only receive security updates and bug fixes that do not constitute substantial modifications.
- The first CRA-compliant version will be v27, which is planned for the end of 2027. It will be based on a new Linux platform to enable us to meet the stringent CRA requirements more efficiently.
Contact
Stay secure and up to date with IACBOX Software Maintenance! If you require any further information, please contact us.