DH electronics GmbH
scroll Scroll Down down

Our Road to the CRA · Reporting obligations apply from September 11

Our Road to the CRA · Reporting obligations apply from September 11

Date : 11. September 2026

Our Road to the CRA · Reporting Obligations Apply from September 11

As of today, the reporting obligations under the Cyber Resilience Act (CRA) apply. Manufacturers must report actively exploited vulnerabilities in their products. This covers not only products placed on the market from today onwards, but also devices already in the field. Today is the moment when the CRA becomes tangible for many for the first time. For us, it is the right moment to begin this series.

What this series is about

For the next twelve months, an installment will appear here each month on how we at DH electronics are dealing with the Cyber Resilience Act. Not another explainer on the regulation, there are plenty of those by now, and some are already out of date, because the interpretation of the regulation is still in motion. What we show instead is our own path: what we have long been doing, what we are working on right now, and what we have set out to do. That includes the topics we are still debating internally. To begin with, the story is told from three perspectives: hardware development, software development and management. Further aspects will be added wherever they complete the picture. Because the CRA thinks in supply chains, and that is exactly where it gets demanding: within our own company a common reading is quickly found, whereas between suppliers and customers very different interpretations meet. We deliberately put our own thinking and our decisions out in the open, because many of us are asking the same questions. Are we affected at all? What applies from when? And above all: how is this text to be interpreted correctly? We are far from having a final answer to every one of these questions. But we do have a position, and we want to communicate it openly. Only then can our customers and partners understand our path and take it with us. We welcome your feedback and your questions.

What is already standard practice for us

Much of what the CRA demands of manufacturers has been part of our product for years, long before the CRA regulation existed. We maintain our System on Module (SOM) and the associated reference designs across the product lifetime. Our update cycles follow a fixed rhythm: a Linux kernel update every year, a new Yocto LTS version every two years. Within the running LTS cycle we supply minor updates and patches on the respective kernel and Yocto version. Since 2019 we have relied consistently on mainline Linux; the major update leaps of earlier days, and the effort that came with them, are history. Our customers receive full access to the Board Support Package source code so they can trace everything and, if they wish, carry on with it themselves. None of this was CRA preparation. It was the answer to the question: how do you keep an industrial product up to date for at least ten years without it becoming a risk at the customer's site?

What changes for us with the CRA

Internal practice becomes an obligation with deadlines and evidence. That is the essential difference. On top of that comes a classification that often causes surprise in our SOM market: in the sense of the CRA we are a manufacturer, not a component supplier. The regulation draws no distinction between product and component, nor between B2B and B2C. A manufacturer is whoever makes a product available on the EU market. What is meant is making available, not manufacturing in the sense of production. Anyone concluding from this that they are not affected as a supplier is mistaken. The same applies to our customers who place a device of their own on the market based on our SOMs: for that device they are manufacturers themselves, with obligations of their own. What this means for the way we work with our customers will likewise be a topic of its own in this series.

What we are working on right now

  • Interpreting the regulation, with its articles and annexes, in relation to our products. The text runs to more than eighty pages and is ambiguous in many places for non-lawyers.
  • Determining the support period, and what the CRA means for product discontinuations. The two belong together, because both determine how long a product must be supported after you have stopped shipping it. On the support period, the CRA leaves no free choice: it must be derived from the expected product lifetime and it must be justified. Anyone falling back on the statutory minimum of five years instead will in many cases fail to meet that rule and, in case of doubt, is on thin ice.
  • The question of where and how we position ourselves on all these topics still occupies us. The CRA changes not only internal processes but also what customers may expect from a supplier.

The standard we set ourselves on all these topics, and which path is the best one for us, is something we are still working out. Even so, we want to carry "our road to the CRA" transparently to the outside and take along everyone facing the same questions.

What we have set out to do

Our ambition is not to take a minimal approach to the CRA. We want to set up the processes behind it so that they hold across the entire product lifecycle. Automated CVE and SBOM workflows, and documentation that keeps our decisions traceable, from the risk assessment through the measures taken to the determination of the support period. The CRA calls not only for appropriate measures to be implemented, but also for evidence of them to the competent authority. We want to put our customers in a position to fill their own role, rather than leaving them alone with a stack of documents.

How we fare step by step on our CRA journey is what you will read here every month from now on.

All parts of the series appear in our news section and in the monthly newsletter.

 

Back to overview
+