Editor's Choice


Could the EU’s Cyber Resilience Act affect your electronics manufacturing business?

27 November 2025 Editor's Choice

South African companies exporting IoT devices to the European Union (EU) face a significant regulatory shift. The EU’s Cyber Resilience Act (CRA) becomes mandatory in December 2027 and manufacturers with products already in the European market need to act now, according to Renaldo Fibiger, field application engineer at Altron Arrow.

“While the South African market remains largely unaffected, customers active in the EU, particularly those with products already in the field, may face significant recall obligations if compliance issues arise,” he explains.

This is why Altron Arrow is reminding manufacturers that sell products in the EU to assess the risks now and determine their exposure before the regulation takes effect. “The more critical the device is the more stringent the compliance requirements will be,” Fibiger notes. “These are EU regulations, but it remains to be seen whether similar legislation will affect South Africa more broadly.” 

What South African manufacturers need to know

The CRA requires hardware and software products sold in the EU to meet cybersecurity standards throughout their entire lifecycle. Critically, the act applies retroactively to existing products. While the act came into force in late 2024, with reporting required from 2026, full compliance becomes mandatory from December 2027.

• The act’s reach is extensive. Any product that runs code falls within its scope, including laptops, gate controllers, routers, home automation devices, medical devices, and some software applications. While full size motor vehicles are exempted from the act, automotive components in the supply chain must comply.

• Manufacturers are responsible for the entire lifespan of the product, typically ten years (or fifteen, in the case of products developed for military applications). This includes notifying the market of any vulnerabilities within 24 hours, providing security updates to address vulnerabilities and informing users about the support period for updates.

• The financial stakes are significant. Non-compliance could result in fines of up to 5% of total yearly revenue.

The three tiers of security required

The CRA assesses cybersecurity requirements based on the level of risk associated with a product, creating three classes of security:

Default classification: this is the lowest risk category and encompasses most devices, including printers and smart home automation products. Companies can typically self-assess compliance, provided they align with EU standards. 

Important products require external third-party assessments for CE certification. This classification tier is split into two classes:

1. Class I covers less sensitive products like routers, home security devices, password managers, browsers, and antivirus software.   

2. Class II encompasses higher-risk products including hypervisors, firewalls, and tamper-resistant microcontrollers and microprocessors.

Critical products already fall under the European Common Criteria-based cybersecurity certification scheme (EUCC). These include smartcards, hardware devices with security boxes, and smart meter gateways.

Cost implications of non-compliance

The cost implications for a South African manufacturer found in breach of the CRA are substantial. “While I support the regulation’s objectives, I understand manufacturers’ concerns regarding potential product recalls,” says Fibiger.  

At this stage, he does not anticipate South Africa adopting these kinds of regulations in the immediate future but notes that the landscape could change. “Should similar legislation be introduced locally, businesses will need to adapt quickly.”

Fortunately, South African exporters in the IoT space are not without support in managing this transition. “At Altron Arrow, we work across both electronic components and cybersecurity, enabling us to guide manufacturers through the compliance process,” Fibiger says. “With proper preparation, the transition should be manageable.”

For more information on CRA compliance support, visit https://eu1.hubs.ly/H0plz9p0

For South African manufacturers selling into the EU market, December 2027 will arrive sooner than expected. The question is not whether to comply, but whether you have started preparing.


Credit(s)



Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

High-performance processing for cost-aware industrial IoT
Altron Arrow DSP, Micros & Memory
STMicroelectronics has expanded its industrial processing portfolio with the new STM32MP2 series, a family of application microprocessors designed to deliver higher performance, advanced security and long-term reliability for cost-sensitive industrial IoT systems.

Read more...
Compact, durable and wideband wireless performance
Altron Arrow Telecoms, Datacoms, Wireless, IoT
The Taoglas Metal Stamped MPA Series of antennas is engineered to meet the growing demands of modern wireless devices that require high performance in increasingly compact form factors.

Read more...
High-performance processing at the edge
Altron Arrow DSP, Micros & Memory
STMicroelectronics’ STM32MP23 microprocessor is designed to meet the demands of industrial, IoT, and edge AI applications.

Read more...
RF agile transceiver
Altron Arrow Telecoms, Datacoms, Wireless, IoT
The AD9361 from Analog Devices is a high performance, highly integrated RF Agile Transceiver designed for use in 3G and 4G base station applications.

Read more...
Ultra-low-power Arm Cortex MCU with FPU
Altron Arrow DSP, Micros & Memory
STMicroelectronics expanded its STM32 ultra-low-power family with the launch of the STM32U3 for cost-sensitive applications in industrial, medical, and consumer electronics devices.

Read more...
From the editor's desk: Resilience and innovation in South Africa’s electronics sector
Technews Publishing Editor's Choice
For South Africa in particular, 2025 has been a year that highlighted the resilience and adaptability of our engineering community as we navigated shifting technologies and a fast-moving international landscape

Read more...
Powering the future of embedded control
Altron Arrow Editor's Choice DSP, Micros & Memory
As the demand for intelligent, connected, and energy-efficient systems grows, embedded engineers are under pressure to design faster, smarter, and more secure products

Read more...
Smart IMU for high/low-g acceleration
Altron Arrow Analogue, Mixed Signal, LSI
The ISM6HG256X is a 6-axis intelligent inertial measurement unit that enables smart motion sensing, edge computing, and real-time awareness.

Read more...
Is it time for Wi-Fi 7 in SA?
Technews Publishing Editor's Choice Telecoms, Datacoms, Wireless, IoT
Wi-Fi 7, the IEEE 802.11be standard also known as Extremely High Throughput, is the next-gen wireless networking standard designed to dramatically improve speed, latency, efficiency, and reliability.

Read more...
20 years of precision, progress and purpose – the Jemstech journey
Jemstech Editor's Choice Manufacturing / Production Technology, Hardware & Services
Twenty years ago, Jemstech began as a small, determined venture built on technical excellence and trust. Today, it stands among South Africa’s leading electronic manufacturing service providers.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved