Editor's Choice


Could the EU’s Cyber Resilience Act affect your electronics manufacturing business?

27 November 2025 Editor's Choice

South African companies exporting IoT devices to the European Union (EU) face a significant regulatory shift. The EU’s Cyber Resilience Act (CRA) becomes mandatory in December 2027 and manufacturers with products already in the European market need to act now, according to Renaldo Fibiger, field application engineer at Altron Arrow.

“While the South African market remains largely unaffected, customers active in the EU, particularly those with products already in the field, may face significant recall obligations if compliance issues arise,” he explains.

This is why Altron Arrow is reminding manufacturers that sell products in the EU to assess the risks now and determine their exposure before the regulation takes effect. “The more critical the device is the more stringent the compliance requirements will be,” Fibiger notes. “These are EU regulations, but it remains to be seen whether similar legislation will affect South Africa more broadly.” 

What South African manufacturers need to know

The CRA requires hardware and software products sold in the EU to meet cybersecurity standards throughout their entire lifecycle. Critically, the act applies retroactively to existing products. While the act came into force in late 2024, with reporting required from 2026, full compliance becomes mandatory from December 2027.

• The act’s reach is extensive. Any product that runs code falls within its scope, including laptops, gate controllers, routers, home automation devices, medical devices, and some software applications. While full size motor vehicles are exempted from the act, automotive components in the supply chain must comply.

• Manufacturers are responsible for the entire lifespan of the product, typically ten years (or fifteen, in the case of products developed for military applications). This includes notifying the market of any vulnerabilities within 24 hours, providing security updates to address vulnerabilities and informing users about the support period for updates.

• The financial stakes are significant. Non-compliance could result in fines of up to 5% of total yearly revenue.

The three tiers of security required

The CRA assesses cybersecurity requirements based on the level of risk associated with a product, creating three classes of security:

Default classification: this is the lowest risk category and encompasses most devices, including printers and smart home automation products. Companies can typically self-assess compliance, provided they align with EU standards. 

Important products require external third-party assessments for CE certification. This classification tier is split into two classes:

1. Class I covers less sensitive products like routers, home security devices, password managers, browsers, and antivirus software.   

2. Class II encompasses higher-risk products including hypervisors, firewalls, and tamper-resistant microcontrollers and microprocessors.

Critical products already fall under the European Common Criteria-based cybersecurity certification scheme (EUCC). These include smartcards, hardware devices with security boxes, and smart meter gateways.

Cost implications of non-compliance

The cost implications for a South African manufacturer found in breach of the CRA are substantial. “While I support the regulation’s objectives, I understand manufacturers’ concerns regarding potential product recalls,” says Fibiger.  

At this stage, he does not anticipate South Africa adopting these kinds of regulations in the immediate future but notes that the landscape could change. “Should similar legislation be introduced locally, businesses will need to adapt quickly.”

Fortunately, South African exporters in the IoT space are not without support in managing this transition. “At Altron Arrow, we work across both electronic components and cybersecurity, enabling us to guide manufacturers through the compliance process,” Fibiger says. “With proper preparation, the transition should be manageable.”

For more information on CRA compliance support, visit https://eu1.hubs.ly/H0plz9p0

For South African manufacturers selling into the EU market, December 2027 will arrive sooner than expected. The question is not whether to comply, but whether you have started preparing.


Credit(s)



Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Engineering in a world that cannot assume connectivity
Technews Publishing Editor's Choice News
Across industrial automation, networking, and defence systems, engineers are rediscovering the importance of resilience and autonomy in an increasingly connected world.

Read more...
Designing IoT devices for deterministic LPWAN environments
Editor's Choice Telecoms, Datacoms, Wireless, IoT
Built on Ultra Narrow Band communication technology, the Sigfox network focuses on low power, wide area M2M connectivity rather than maximising data throughput.

Read more...
Driving excellence in electronics manufacturing
Jemstech Editor's Choice Manufacturing / Production Technology, Hardware & Services
Jemstech’s reputation for disciplined execution and client-focused service has earned it strong loyalty from companies operating in demanding industries.

Read more...
Compact 6 A automotive buck converter
Altron Arrow Power Electronics / Power Management
Delivering up to 6 A of continuous output current, the DCP0606Y from STMicroelectronics enables efficient regulation of low-voltage rails commonly used in modern vehicle electronics and industrial systems.

Read more...
In sync with the line
Testerion Editor's Choice Manufacturing / Production Technology, Hardware & Services
In modern SMT lines, stencil printing must meet two requirements at the same time: it has to ensure a reproducible solder paste volume, while adhering to the specified line cycle time.

Read more...
Next-gen modules for rugged edge AI systems
Altron Arrow Computer/Embedded Technology
Designed for real-world edge deployments where systems do not sit still, SolidRun’s P100 COMx6 series targets mobile platforms as well as harsh, mission-critical environments.

Read more...
Resilient navigation in warfare: The role of non-GNSS
Etion Create Editor's Choice
Alternative navigation methods are essential for maintaining operational capability when satellite signals are unreliable or unavailable.

Read more...
NXP has expanded its MCX A Series
Altron Arrow AI & ML
NXP has significantly expanded its MCX A Series of Arm Cortex-M33 microcontrollers, doubling the portfolio with six new families aimed at industrial and IoT edge applications.

Read more...
Quectel’s RG255C-NA and RM255C-GL accelerate 5G RedCap adoption
iCorp Technologies Editor's Choice Telecoms, Datacoms, Wireless, IoT
Quectel’s RG255C-NA and RM255C-GL modules represent a strategic move into this fast-growing segment, delivering Sub-6 GHz 5G connectivity optimised for mid-tier IoT applications.

Read more...
SDRs – Which RF architecture should you choose?
RFiber Solutions Editor's Choice Telecoms, Datacoms, Wireless, IoT
There are several common methods of implementing SDR architectures. This paper discusses which is best when meeting a specific need.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved