Blog

Navigating the Cyber Resilience Act: Critical Deadlines and Security Imperatives for Cellular IoT


September 2026 and December 2027:  Two Milestones That Will Redefine IoT Security in Europe

The European Union’s Cyber Resilience Act (CRA) is reshaping cybersecurity requirements for connected devices, especially cellular IoT products such as smart meters, industrial gateways, trackers, telematics systems, and connected medical devices.

Two dates are critical for manufacturers:

These milestones will significantly impact product design, software maintenance, and lifecycle security management.

Why Cellular IoT Is Impacted

Cellular IoT devices are considered high-risk because they:

As a result, the CRA forces a fundamental shift from a traditional “ship-and-forget” model to one of continuous cybersecurity accountability.

September 2026: Start of Mandatory Reporting

From September 2026 onward, manufacturers must implement processes to:

This marks the transition toward formalized cybersecurity operations, requiring dedicated vulnerability management and incident response capabilities. 

The Role of the SBOM

A Software Bill of Materials (SBOM) becomes essential, providing full visibility into:

Non-compliant products risk exclusion from the EU market.

December 2027: Full CRA Compliance

By December 2027, cybersecurity will be a prerequisite for CE marking digital products in the EU. Manufacturers must demonstrate secure‑by‑design principles, including:

Failure to comply may result in loss of access to the EU market.

Alignment with RED EN 18031

Cellular IoT devices are also subject to the Radio Equipment Directive (RED) cybersecurity standard EN 18031, which addresses:

While RED focuses on device-level security requirements, the CRA extends these obligations across the entire product lifecycle, emphasizing continuous updates, monitoring, and incident response.

Conclusion

The CRA introduces a two-phase transformation:

Together, these milestones redefine cybersecurity as a continuous responsibility rather than a one-time feature.

Sequans is proactively preparing for this evolution with a fully controlled Western value chain—from chipset to module, firmware, and software—enabling customers to meet emerging CRA requirements while strengthening supply chain security and trust.

 

Recent Blog Posts

Building Europe’s 6G Future: Sequans’ Role in the Hexa‑X‑II Flagship Program

Building Europe’s 6G Future: Sequans’ Role in the Hexa‑X‑II Flagship Program


We are excited to highlight our role in Hexa‑X‑II, Europe’s flagship 6G research program,…
Read more
Navigating the Cyber Resilience Act: Critical Deadlines and Security Imperatives for Cellular IoT

Navigating the Cyber Resilience Act: Critical Deadlines and Security Imperatives for Cellular IoT


September 2026 and December 2027:  Two Milestones That Will Redefine IoT Security in Europe

The…
Read more
From Cat M to Cat 1 bis: How Sequans and MIKROE Empower Flexible IoT Deployments

From Cat M to Cat 1 bis: How Sequans and MIKROE Empower Flexible IoT Deployments


As IoT projects move from proof of concept to large‑scale deployment, one question keeps…
Read more