Helping OEMs deliver cyber-resilient products
- Online security must be built in, not bolted on.
- The EU’s CRA makes cyber resilience mandatory.
- Expectations for similar levels of cybersecurity are global.
- Avnet helps OEMs secure the full product lifecycle in any market.
Connectivity in embedded systems predates the internet but the Internet of Things (IoT) standardized it. The IoT’s popularity led to more technology for connecting almost any device to the world’s largest network. Adoption accelerated dramatically with wireless connectivity, making connected products easier to deploy, manage and scale.
The benefits of connectivity are undeniable but now the trend is toward placing more autonomy in intelligent and connected devices at the edge of the network. Those devices will soon embody physical AI; the agency to take direct action based on decisions made using real-world, real-time data. With this new reality on the horizon, it’s not surprising that security is once again the main topic of conversation.
Early IoT devices placed too much trust in the implied security offered by the connectivity standards. While those standards do include security features, often those features are optional and not fully implemented by manufacturers. Even when they are in place, it can be too easy to inadvertently mismanage security. That ranges from using the same, simple default password, to poor storage and sharing of private keys for authentication and encryption.
The consensus is we can no longer assume OEMs are implementing security in a robust and responsible way. There is increasing pressure coming from governments and industry alliances for OEMs to implement a level of security that is appropriate and can be independently assessed.
Software-defined comes with security risks
The second trend driving the need for more robust security standards is software-defined functionality. We’re seeing software-defined being adopted in every vertical market, and it effectively places much of the responsibility for security at the software level. The same hardware platform could be software-defined in multiple ways, entirely at the software layer. OEMs who prioritize performance over security could, for example, sacrifice data encryption for a faster display frame rate.
Vulnerabilities buried in embedded software are another major concern. Embedded systems often rely on third-party software, but even in-house software can contain vulnerabilities that go undetected until after a product ships. Once identified, those vulnerabilities need to be addressed with software patches, which may be deployed either physically or wirelessly via over-the-air (OTA) updates. OTA updates for connected devices are now commonplace in products ranging from smart lightbulbs to mass-transit vehicles.
Early in the IoT lifecycle, manufacturers felt their products were secure by obscurity. There were so many products on the market that it would be difficult for bad actors to target any one of them. That proved incorrect and the industry has (slowly, some would say) moved toward ubiquitous security through education and, more recently, legislation.
The European Union is phasing in compliance with the Cyber Resilience Act (CRA). By December 2027, it will be illegal for any OEM to put certain products into the EU market without complying with the CRA. That includes products made outside the EU but sold into the bloc.
Broadly speaking, products within scope include any device that can connect to another device or network as part of its usual operation. That extends beyond the smart lightbulb. It essentially includes any electronic device with a wired or wireless port that is used in its normal operation and is accessible.
Things that are only useful when connected to a network, like a printer or security camera, are obvious examples of where online security is needed. But there are more obscure cases to consider, too. For example, if a product includes an Ethernet or USB port, even if it is used solely and infrequently by a service engineer, it falls within the scope of the CRA.
What does the Cyber Resilience Act cover?
Other legislation to protect consumers is in force but generally applies to products as they roll off the production line. Because connected devices become nodes on an active network, the CRA puts responsibilities on the manufacturer that do not end when the products ship but continue throughout their lifecycle.
Security must be demonstrated through documented evidence to have been considered from the start of the design and throughout the product’s lifecycle. This full lifecycle responsibility will be new to manufacturers, and its implementation places great emphasis on after-sales maintenance.
In brief, the CRA requirements include:
- Documented evidence that security risks have been assessed and managed.
- A product development methodology that shows security is designed in, not added on.
- Capability for deploying software updates to the products while in service, generally over-the-air.
- A software bill of materials (SBOM) that documents the software shipped in the product and software deployed after the product has shipped.
- Robust processes that handle vulnerability monitoring and how those vulnerabilities are reported as/when they are found/fixed.
- A methodology for managing security throughout the product’s expected lifetime.
In essence, the EU is compelling OEMs to make security part of a digital product’s DNA. The need for legislation is legitimate, given the huge financial cost of cybercriminal activity, but it places the burden on manufacturers rather than end users. Products, therefore, need to be user-proofed in both their design and use, making security a matter of both design and intent.

Why the CRA isn’t just about Europe
Although the CRA is EU legislation, its impact will reach beyond Europe. Governments are increasingly treating online security as part of their responsibility to citizens, and manufacturers that sell internationally will need to monitor and meet the requirements of each market they enter.
In the United States, the Federal Communications Commission (FCC) recently added robots and power inverters to its covered list. That’s a list of products and manufacturers subject to closer scrutiny before they can be sold in the United States. Often, it means they cannot be sold.
Both robots and power inverters have been added due to the potential for malicious actors to remotely access the product and take control of it. For power inverters, the main threat is to the nation’s energy security. There is documented evidence to show such vulnerabilities exist and have already been exploited.
Security requirements vary across countries and regions. Most security requirements are not explicitly legislated, and some are implicitly imposed by other, high-level and sector-specific regulations.
In the United States, cybersecurity is mostly dealt with through sector-specific regulations, or National Institute of Standards and Technology (NIST)-based frameworks such as the (voluntary) U.S. Cyber Trust Mark, as well as Federal Trade Commission (FTC) enforcement. Enforcement is mostly sectoral, addressing healthcare, finance or energy providers.
Complying with the EU’s CRA may not be necessary in most regions, but the requirements it demands are built on best practices. Adopting those practices now could put manufacturers in a better position in the future, if demonstrating full lifecycle security measures becomes obligatory elsewhere.
How Avnet helps OEMs with cybersecurity
Instead of treating security as a burden, forward-looking manufacturers can view it as a competitive advantage. Meeting CRA requirements is challenging because they span hardware, software, system-level design and lifecycle management, including responsibilities many manufacturers may not have considered in the past.
Delivering that level of visibility takes an ecosystem. Avnet brings together the technologies, tools and services OEMs need to meet rising cybersecurity expectations from regulators, customers and markets.
Hardware is the foundation for secure connected products. The need is for integrated devices that support secure boot, encryption, authentication, secure key storage and trusted software execution. None of these features are required to get a digital device connected, but all of them are essential to do it securely.
It’s that mindset that drives online security. It’s easy to get connected, but it’s much harder to do so in a way that is scalable across thousands of devices while creating a unique identity for each one. But that’s what is needed to stay secure.
At a system level, secure connectivity depends on provisioning: the process used to authenticate a device when it joins a network. This typically involves generating, sharing and storing secure keys used to encrypt and decrypt messages over a trusted connection. That goes far beyond using standard internet protocols to establish an HTTP or FTP connection with a server.
Avnet’s linecard across all regions and businesses, including Avnet Silica and EBV Elektronik in Europe, features many of the industry’s leading integrated device manufacturers. This gives Avnet customers direct access to best-in-class secure hardware solutions, supported by expert field application engineers (FAEs).
Tria Technologies, an Avnet company, supports customers with standards-based embedded computing platforms. Many Tria-designed compute boards include secure elements from Avnet supplier partners and come with long-term software maintenance. Tria can also provide vulnerability monitoring and SBOM support, and hardware and software documentation that can help OEMs demonstrate CRA compliance.
The software aspect of online security
Secure connections can be used for OTA updates. Part of the CRA’s requirements is to produce products with no known vulnerabilities. If vulnerabilities are later discovered (and continued monitoring is also a CRA requirement), those vulnerabilities must be addressed in a short period of time. This will inevitably require a new software build to be sent to the devices.
Avnet’s /IOTCONNECT™ Software-as-a-Service (SaaS) platform is a software library that enables OEMs to connect hardware devices to cloud services using built-in secure technologies, while also providing secure device management in the field. Avnet is also a certified reseller of Canonical Ubuntu and has developed /IOTCONNECT Snap, a secure and portable runtime for connecting Ubuntu-based embedded devices to cloud services.
A software bill of materials (SBOM) is a CRA requirement, but the CRA's impact on software goes further. Software elements, including operating systems, hypervisors and virtual private network stacks, may need to be assessed by a notified body before they can be deemed compliant.
It may make sense for an OEM to treat the software stack as a standalone product that can be reused in multiple products, and have the stack assessed for CRA compliance. That decision may need the level of support and advice that is available from Witekio, an Avnet company and specialist embedded software provider.
Conclusion
Cybersecurity has always been a technical consideration; a design choice made by OEMs. But it is now becoming a requirement to access certain markets, making the choice more about implementation.
The CRA sets a clear expectation that connected products must be secure by design, supported throughout their lifecycle and backed by evidence that security risks have been assessed and managed.
As similar expectations emerge in other regions, OEMs that act now will be better prepared for future regulation and better positioned to earn customer trust. With its supplier ecosystem, secure hardware platforms, software services and embedded expertise, Avnet can help manufacturers build cyber-resilient products that are ready for the markets they serve.