PREPARING MANUFACTURERS FOR THE CRA AMIDST RISING CYBER THREATS
20/08/2026 Wireless Logic Group Ltd
On 11th September, the next phase of the Cyber Resilience Act (CRA) comes into force. From this date, manufacturers must report actively exploited vulnerabilities and severe incidents that impact the security of products with digital elements.This is particularly relevant for IoT manufacturers, as connected devices are now the most frequently targeted in the UK. Under the CRA, cybersecurity must be considered throughout the product lifecycle, making secure-by-design IoT crucial for both compliance and operational continuity.
Despite the commencement of this regulation, many manufacturers still appear to be underprepared in the instance of an attack. According to recent findings from Make UK, while nearly a third (30%) of British manufacturers have experienced a cyberattack either directly or through a company in their supply chain, only 51% report having a plan in place. With reporting obligations fast approaching, closing this gap is now critical for manufacturers to remain both compliant and resilient.
Iain Davidson, Head of Product Marketing at Wireless Logic, offers insights into what the CRA means for IoT manufacturers, and how organisations can prepare in advance of the regulation:
“As the IoT grows in the manufacturing industry, and studies like Make UK’s remind us of the growing threats, regulators and businesses must remember that the IoT is not fully resilient if it is not secure. The huge quantities of valuable data IoT devices collect and transport – combined with the fact that many devices sit outside traditional IT perimeters – can make them a vulnerable target worth going after.
“Resilience has always been vital to the IoT, but under the CRA it becomes a strategic imperative, as security will become a legal condition for selling a connected product in Europe. The CRA will officially move cyber security from an afterthought to a design requirement, from the drawing board through to end of support. Manufacturers must now build in secure-by-default configuration, vulnerability handling processes and a software bill of materials before a product ever reaches CE marking – and they must keep supporting it, not just ship and move on. This is particularly crucial as the CRA's essential requirements cover the full product lifecycle: secure development, vulnerability handling, and mandatory security updates for the expected product lifetime.
“To prepare for this new regulation, the way the industry thinks about IoT security must shift to prioritising built-in resilience from the outset. This means secure-by-design connectivity, supported by strong authentication, anomaly detection and continuous visibility, to ensure every device on a network is identifiable, protected from compromise and compliant.”
For more information, please contact:
Wireless Logic Group Ltd
Wireless Logic Group Ltd Horizon
Honey Lane, Hurley
Berkshire SL6 6RJ
UK
Tel: +44 (0)330 056 3300
Email: feedback@wirelesslogic.com
Web: https://wirelesslogic.com
Share article:
Process and Control Today are not responsible for the content of submitted or externally produced articles and images. Click here to email us about any errors or omissions contained within this article.

