Blog

Navigating the Cyber Resilience Act: Critical Deadlines and Security Imperatives for Cellular IoT

September 2026 and December 2027:  Two Milestones That Will Redefine IoT Security in Europe

The European Union’s Cyber Resilience Act (CRA) is reshaping cybersecurity requirements for connected devices, especially cellular IoT products such as smart meters, industrial gateways, trackers, telematics systems, and connected medical devices.

Two dates are critical for manufacturers:

These milestones will significantly impact product design, software maintenance, and lifecycle security management.

Why Cellular IoT Is Impacted

Cellular IoT devices are considered high-risk because they:

As a result, the CRA forces a fundamental shift from a traditional “ship-and-forget” model to one of continuous cybersecurity accountability.

September 2026: Start of Mandatory Reporting

From September 2026 onward, manufacturers must implement processes to:

This marks the transition toward formalized cybersecurity operations, requiring dedicated vulnerability management and incident response capabilities. 

The Role of the SBOM

A Software Bill of Materials (SBOM) becomes essential, providing full visibility into:

Non-compliant products risk exclusion from the EU market.

December 2027: Full CRA Compliance

By December 2027, cybersecurity will be a prerequisite for CE marking digital products in the EU. Manufacturers must demonstrate secure‑by‑design principles, including:

Failure to comply may result in loss of access to the EU market.

Alignment with RED EN 18031

Cellular IoT devices are also subject to the Radio Equipment Directive (RED) cybersecurity standard EN 18031, which addresses:

While RED focuses on device-level security requirements, the CRA extends these obligations across the entire product lifecycle, emphasizing continuous updates, monitoring, and incident response.

Conclusion

The CRA introduces a two-phase transformation:

Together, these milestones redefine cybersecurity as a continuous responsibility rather than a one-time feature.

Sequans is proactively preparing for this evolution with a fully controlled Western value chain—from chipset to module, firmware, and software—enabling customers to meet emerging CRA requirements while strengthening supply chain security and trust.

 

Recent Blog Posts

Navigating the Cyber Resilience Act: Critical Deadlines and Security Imperatives for Cellular IoT

Navigating the Cyber Resilience Act: Critical Deadlines and Security Imperatives for Cellular IoT

September 2026 and December 2027:  Two Milestones That Will Redefine IoT Security in Europe

The…
Read more
From Cat M to Cat 1 bis: How Sequans and MIKROE Empower Flexible IoT Deployments

From Cat M to Cat 1 bis: How Sequans and MIKROE Empower Flexible IoT Deployments

As IoT projects move from proof of concept to large‑scale deployment, one question keeps…
Read more
First Sample of Calliope SQN4530 eRedCap FD/HD Chipset

First Sample of Calliope SQN4530 eRedCap FD/HD Chipset



We are pleased to share that we have received the first sample of the Calliope™ 3 SQN4530 chip, our new 5G NR eRedCap cellular IoT platform and the…
Read more