Date : 11. September 2026
Our Road to the CRA · Reporting Obligations Apply from September 11
As of today, the reporting obligations under the Cyber Resilience Act (CRA) apply. Manufacturers must report actively exploited vulnerabilities in their products. This covers not only products placed on the market from today onwards, but also devices already in the field. Today is the moment when the CRA becomes tangible for many for the first time. For us, it is the right moment to begin this series.
What this series is about
For the next twelve months, an installment will appear here each month on how we at DH electronics are dealing with the Cyber Resilience Act. Not another explainer on the regulation, there are plenty of those by now, and some are already out of date, because the interpretation of the regulation is still in motion. What we show instead is our own path: what we have long been doing, what we are working on right now, and what we have set out to do. That includes the topics we are still debating internally. To begin with, the story is told from three perspectives: hardware development, software development and management. Further aspects will be added wherever they complete the picture. Because the CRA thinks in supply chains, and that is exactly where it gets demanding: within our own company a common reading is quickly found, whereas between suppliers and customers very different interpretations meet. We deliberately put our own thinking and our decisions out in the open, because many of us are asking the same questions. Are we affected at all? What applies from when? And above all: how is this text to be interpreted correctly? We are far from having a final answer to every one of these questions. But we do have a position, and we want to communicate it openly. Only then can our customers and partners understand our path and take it with us. We welcome your feedback and your questions.
What is already standard practice for us
Much of what the CRA demands of manufacturers has been part of our product for years, long before the CRA regulation existed. We maintain our System on Module (SOM) and the associated reference designs across the product lifetime. Our update cycles follow a fixed rhythm: a Linux kernel update every year, a new Yocto LTS version every two years. Within the running LTS cycle we supply minor updates and patches on the respective kernel and Yocto version. Since 2019 we have relied consistently on mainline Linux; the major update leaps of earlier days, and the effort that came with them, are history. Our customers receive full access to the Board Support Package source code so they can trace everything and, if they wish, carry on with it themselves. None of this was CRA preparation. It was the answer to the question: how do you keep an industrial product up to date for at least ten years without it becoming a risk at the customer's site?
What changes for us with the CRA
Internal practice becomes an obligation with deadlines and evidence. That is the essential difference. On top of that comes a classification that often causes surprise in our SOM market: in the sense of the CRA we are a manufacturer, not a component supplier. The regulation draws no distinction between product and component, nor between B2B and B2C. A manufacturer is whoever makes a product available on the EU market. What is meant is making available, not manufacturing in the sense of production. Anyone concluding from this that they are not affected as a supplier is mistaken. The same applies to our customers who place a device of their own on the market based on our SOMs: for that device they are manufacturers themselves, with obligations of their own. What this means for the way we work with our customers will likewise be a topic of its own in this series.
What we are working on right now
The standard we set ourselves on all these topics, and which path is the best one for us, is something we are still working out. Even so, we want to carry "our road to the CRA" transparently to the outside and take along everyone facing the same questions.
What we have set out to do
Our ambition is not to take a minimal approach to the CRA. We want to set up the processes behind it so that they hold across the entire product lifecycle. Automated CVE and SBOM workflows, and documentation that keeps our decisions traceable, from the risk assessment through the measures taken to the determination of the support period. The CRA calls not only for appropriate measures to be implemented, but also for evidence of them to the competent authority. We want to put our customers in a position to fill their own role, rather than leaving them alone with a stack of documents.
How we fare step by step on our CRA journey is what you will read here every month from now on.
All parts of the series appear in our news section and in the monthly newsletter.