Computer/Embedded Technology


Nordic expands nRF Cloud with firmware vulnerability scanning

29 June 2026 Computer/Embedded Technology

Nordic Semiconductor announced that firmware vulnerability scanning is coming to nRF Cloud, further bolstering its capabilities for empowering device makers to prepare for the EU Cyber Resilience Act (CRA).

With firmware vulnerability scanning in nRF Cloud, developers will be able to upload their software bill of materials (SBOM) to nRF Cloud and automatically identify common vulnerabilities and exposures (CVEs) present in the SBOM and analyse their exposure across their nRF Cloud-connected production fleet.

nRF Cloud’s new capability is designed to help device manufacturers meet the CRAs vulnerability monitoring requirement, without taking on the burden of building and maintaining their own CVE identification systems. This new capability works in tandem with nRF Cloud’s firmware over-the-air (FOTA) service, which allows updates to be deployed at scale to devices in the field.

Shortening CRA compliance to-do lists

The CRA requires the security of connected devices to be maintained across the full device lifespan, which can extend many years into the future, meaning compliance work does not stop once devices are deployed.

With nRF Cloud’s features including vulnerability detection and FOTA, developers can more effectively manage their compliance burden and stay focused on building innovative products. This means a faster path to market, and once products ship, meeting ongoing compliance obligation with less strain on stretched resources.

Continuous vulnerability detection with real-world exposure analysis

With nRF Cloud’s new firmware vulnerability scanning, developers upload their SBOMs for each software version, and nRF Cloud will automatically and continuously scan that SBOM.

The service also highlights exactly how many deployed devices are exposed to each identified vulnerability. This exposure data enables more confident prioritisation decisions, and allows real-time monitoring of remediation via security patches, as those updates roll out.

Detection and remediation in one system

Alongside nRF Cloud’s existing FOTA update capability, firmware vulnerability scanning lets device makers move from an identified security issue, to a deployed patch, to a confirmed fix, all in one system backed by a complete audit trail.

Remediation can be monitored in real time as security patches roll out across the fleet. With the help of nRF Cloud, developers will be able to check several important requirements around vulnerability monitoring and security update delivery off their CRA to-do list.


Credit(s)



Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Compact switch for 5G applications
RF Design Telecoms, Datacoms, Wireless, IoT
The Qorvo QPC6188 is a high-performance absorptive SP4T RF switch designed to meet the demanding requirements of modern wireless infrastructure and high-frequency communication systems.

Read more...
What happens when trust can no longer live only in software?
Computer/Embedded Technology Electronics Technology
[Sponsored] For years, many enterprise security architectures treated hardware primarily as the execution layer, while software handled authentication, access control and trust decisions.

Read more...
Plug-in timing module
Comtest Computer/Embedded Technology
Microchip’s MD-990-0011-B timing module redefines the role of timing, making it possible for customers to seamlessly integrate advanced synchronisation at any stage of development.

Read more...
Seeing through the noise
RF Design Editor's Choice Telecoms, Datacoms, Wireless, IoT
How Adaptive Long Coherent Integration (ALCI) delivers superior measurement and positioning performance where conventional receivers fall short.

Read more...
Bluetooth Classic and LE Audio module
RF Design Telecoms, Datacoms, Wireless, IoT
Refresh legacy Bluetooth designs and unlock Bluetooth Core 6.0 LE Audio in one rugged, ready to implement module.

Read more...
Centimetre-level navigation without RTK infrastructure
RF Design Telecoms, Datacoms, Wireless, IoT
From precision agriculture and infrastructure inspection to beyond visual line of sight missions, modern UAVs demand far greater positional reliability than standard GNSS systems can typically provide.

Read more...
Advanced Layer 2 industrial switches
Vepac Electronics Computer/Embedded Technology
The Raptor EP4200 and EP5200 series switches provide advanced Layer 2 switching capabilities with high performance and availability tailored for demanding critical infrastructure and energy applications.

Read more...
Reliable isolation for modern networks
ASIC Design Services Computer/Embedded Technology
The Pro-Tek5 PTI Series delivers reinforced 5 kV Ethernet isolation for applications that demand robust protection, reliable signal integrity, and full IEEE802.3 performance.

Read more...
Axon NPU powers smarter edge
RF Design AI & ML
The nRF54LM20B from Nordic Semiconductor is an ultra-low-power wireless SoC that combines advanced edge AI capabilities with robust radio connectivity and rich peripheral support.

Read more...
Compact Ka-band GaN PA
RF Design Telecoms, Datacoms, Wireless, IoT
The CMX90A705 from CML Microcircuits is a high-performance two-stage GaN power amplifier operating across 27,5 to 31 GHz and targeting Ka-band applications.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved