Behind the Tech
The EU Cyber Resilience Act (CRA) turns cybersecurity from a nice-to-have into a legal requirement for every connected device sold in Europe, and asset trackers sit squarely in its path. Here's what the CRA actually requires, why it lands hardest on long-lived, low-visibility IoT hardware, and how secure-by-design practices already used in asset tracking map onto its obligations.
- The rules are changing fast. Every connected device sold in the EU, trackers included, must be secure by design, maintain a vulnerability-handling process, and report serious incidents within 24 hours of discovery. Reporting starts 11 September 2026, full enforcement by 11 December 2027, with fines up to €15 million or 2.5% of global turnover. - Asset trackers are a textbook target. Deployed for years, easy to forget, permanently connected: exactly the profile the CRA is built to catch. Manufacturers and operators both need to prove their hardware holds up. - "Secure by design" means specifics, not slogans. Encryption, unique device identities, EU hosting and hardware, strict access controls, and annual pen testing, the same things that make audits faster when they come.
Cybersecurity in connected hardware used to be a slide near the back of the deck: a feature to mention if a prospect asked, rarely the reason a deal was won. The EU Cyber Resilience Act (CRA) changes that. It’s the first horizontal EU law to mandate cybersecurity requirements across the entire lifecycle of “products with digital elements,” and it applies to essentially anything with a chip, a connection, and a customer in Europe, from industrial sensors and smart meters to asset trackers riding on returnable containers.
As Talking IoT put it, the CRA marks a new era for device manufacturers: security stops being optional and becomes something you have to prove. At Sensolus, we build trackers that sit in the field for years and stay connected to the cloud the whole time, so that shift is one we recognize well. Our VP Engineering, Steven Van Hoof, laid out our approach in his whitepaper “Sleep Like a Baby Thanks to IoT: Security at Every Level,” and line by line, the regulation asks for things we already treat as standard practice at Sensolus.
Strip away the legal language and the CRA rests on a simple idea: manufacturers must keep a connected product secure for its entire time in service, from the day it ships until it’s decommissioned. Concretely, that means:
The regulation entered into force on 10 December 2024, and the rest phases in over three years:
Non-compliance carries fines of up to €15 million or 2.5% of global annual turnover, whichever is higher, just under GDPR’s own top-tier cap of €20 million or 4%.
Products in the CRA’s “important” category face tighter scrutiny: Class I (password managers, VPNs, general-purpose operating systems) allows self-assessment if harmonised standards are applied, Class II (firewalls, intrusion detection systems) always requires third-party assessment, and “critical” products (smart meter gateways, secure elements) need certification outright. Most connected devices, trackers included, sit outside these categories under the default self-assessment route, but the core obligations around secure design, vulnerability management, and incident reporting apply no matter which bucket a product lands in. There is no tier where “we’ll patch it eventually” is an acceptable answer.
Asset trackers are a clear example of what the CRA is worried about: built to sit unattended in the field for years, easy to forget once installed, and permanently connected to a cloud platform holding real operational data. That combination of long deployment, low visibility, and constant connectivity is exactly the profile the CRA is trying to cover.
It reaches two audiences at once. Device manufacturers, whose trackers and firmware are exactly the “products with digital elements” the regulation describes, and the operators who buy and deploy those trackers (logistics, industrial, aerospace), who will increasingly be asked by their own auditors to prove their connected hardware meets the standard. Procurement teams that once asked “does it work?” are starting to ask “can you show me your vulnerability-handling process?” A vendor who can’t answer that becomes a liability the moment it’s plugged in.
This is where Steven’s whitepaper is worth reading end to end: its three guidelines map closely onto what the CRA is trying to standardize.
The CRA requires manufacturers to keep a product secure for as long as it’s reasonably expected to stay in use, so new capabilities added years later have to meet the same standard as what shipped on day one. That’s the test AI features are starting to pose across IoT. Sensolus already uses AI to flag anomalies, such as an asset stationary far longer than normal or one that’s drifted outside its zone, and to sharpen location accuracy, always within a user’s existing access rights: every action is logged and enforceable through the same SSO, MFA, and RBAC controls that govern a human user. As Steven puts it, “first data quality and privacy, then AI. Otherwise, you only make mistakes faster,” a fair summary of what the CRA is trying to legislate into every connected product by default.
It’s tempting to treat the CRA as a compliance tax: one more audit, one more document before a deal closes. The more useful read, and the one Steven lands on in the whitepaper’s conclusion, is that security done properly is invisible day to day and obvious in the result: peace of mind, predictability, and due diligence that goes faster because the answers were already true before anyone asked.
That’s the real opportunity for operators managing connected assets across Europe. Vendors who’ve already built end-to-end encryption, EU hosting, strict access governance, and a genuine vulnerability-handling routine won’t need to scramble once reporting obligations begin; they’ll simply hand over documentation their customers’ auditors are already asking for. For everyone else in the supply chain, that’s exactly the kind of vendor question worth asking now, well before the reporting clock starts running.
Steven titled his whitepaper “Sleep Like a Baby Thanks to IoT” for a reason: when secure design, EU hosting, and a real incident-response routine are already in place, the CRA stops being something to lose sleep over.
We are experts: ask us anything, from the battery in the tracker to inventory reports and asset journeys.
Request demo
Dead-On-Arrival spare parts cost 4% of revenue. Learn how supply chain visibility reduces DOA rates by 30-50% and protects your margins.
Read article →
Learn how Sensolus guarantees the protection of your tracked assets through secure-by-design architecture and continuous monitoring.
Download whitepaper →
Europe’s new Packaging and Packaging Waste Regulation demands full traceability for reusable transport packaging. Here’s why active IoT tracking is the most efficient path to compliance.
Read article →
© 2026 Sensolus - All rights reserved