Back to Newsroom
Semiconductors · NexCyber Editorial

Chip Vendors Are in Scope of the CRA — Here Is Why

Semiconductor and module vendors often assume the Cyber Resilience Act reaches only finished devices. Firmware, SDKs and reference software say otherwise.

---

The short answer

A great many semiconductor vendors have concluded that the Cyber Resilience Act is their customers' problem. That conclusion does not survive contact with what they actually ship.

The CRA applies to products with digital elements — hardware and software placed on the EU market, including software placed on the market separately.

bare silicon, no software        arguable
silicon + firmware               a product with digital elements
an SDK shipped to customers      software placed on the market
a reference design with an OS    a product with digital elements

Almost nobody ships bare silicon. They ship silicon with a bootloader, a driver stack, a network stack, an SDK, and a reference application — and every one of those is software.

---

Why the position is more exposed than it looks

A device manufacturer integrating your part must meet CRA Annex I. To do that, they need to know what is in your firmware, when it was last updated, and whether known vulnerabilities affect it.

If you cannot tell them, you have not avoided the obligation — you have become the reason their obligation fails.

That is not a legal argument. It is a commercial one, and it arrives faster than enforcement: procurement questionnaires are already asking. A supplier who cannot answer is a supplier who gets designed out at the next revision.

---

The depth problem, which is specific to this industry

Semiconductor software stacks are unusually deep, and the depth is the difficulty:

customer application
  vendor SDK
    vendor RTOS or driver layer
      third-party network / crypto stack
        upstream open source components

A top-level SBOM that lists "vendor SDK 4.2" answers nothing. The vulnerability that matters is four levels down, in a crypto or TCP/IP stack the vendor licensed and may not itself have inventoried.

CRA Annex I Part II requires identification and documentation of components, in a machine-readable format, covering at the very least the top-level dependencies. That is the floor, not the target — and for this industry the floor is not where the risk lives.

---

The long-lifetime problem

Industrial and automotive parts stay in production for a decade or more, and in the field for longer.

The CRA requires a support period reflecting the expected product lifetime, and technical documentation retained for ten years after placing on the market, or the support period, whichever is longer.

For a part designed in 2026 and shipping until 2036, that is an obligation stretching into the 2040s — and it has to be decided now, because it is declared at placement.

Most semiconductor product roadmaps do not have a field for this.

---

What actually needs to exist

A per-release SBOM, generated in the build, archived. Not a document produced on request — an artefact that exists for every version you ever shipped. The question you will be asked is *which shipped versions are affected*, and only an archive answers it.

A published vulnerability contact and disclosure policy. Free, verifiable from outside, and the first thing a serious customer checks.

A stated support period per part. Your customers cannot declare theirs until you declare yours. This is the item most likely to be missing today.

A dated determination of your CRA class per product line. Annex III and Annex IV are narrower than most people fear — but "we concluded default class, here is why, dated" is worth far more than an assumption.

---

The commercial reading, which is the one that moves budgets

Every device maker using your parts now needs this evidence from you. The vendors who can produce it become easier to design in; the vendors who cannot become a documented risk in someone else's file.

This is a differentiation window, and it closes. Right now the evidence is rare enough to be a reason to choose you. In two years it will be table stakes, and its absence will simply be disqualifying.

---

Check what reaches your product line — free, no account

  • [Free readiness assessment](/assess) — your CRA class and the obligations that follow
  • [Penalty calculator](/resources/penalty-calculator) — exposure on your own turnover

---

Further reading

Products with digital elements, definedHow to build an SBOMImportant versus critical under the CRAAudit-ready evidence for the CRA

---

*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. Whether a specific part falls within scope is a determination on the facts. Verify against the current text and Commission guidance, and consult your competent authority or a qualified adviser.*

Want the regulatory deep-dive ?

Our regulatory engineering team publishes implementation guides + practical checklists for each regulatory update.

Browse Knowledge Base →