Skip to content

Securing the future of European connected devices: the Cyber Resilience Act (CRA)

Design-Reuse August 17, 2026

The EU Cyber Resilience Act (CRA ) is at the center of the transition. It mandates legally-binding obligations to manufacturers, developers and hardware vendors, ensuring the security of products with digital components, and it specifies milestones for compliance that are to come into force.

The CRA is designed to be forward-looking, rather than demanding standard cybersecurity defenses. Like a regulatory lens, it helps focus organizations towards state-of-the-art cryptography, supply-chain transparency, and naturally, quantum readiness, all in advance of the generation of threats.

The CRA specifies a very clear roadmap for compliance.

This aligns with a number of international guidelines, including the US CNSA 2.0 targeting PQC implementation by 2035, as well as BSI and ANSSI, pushing for a phasing out of classical cryptography in preference of hybrid post-quantum/classical solutions over the few years.

The headline news is that over the decade, classical cryptography will be phased out in favor of full migration to PQC by 2035.

Meeting PQC transition objectives requires a blueprint. Our suggestion is a phased approach:

Essentially, the CRA mandates the following, each of which can be fulfilled by PQShield.

Our ultra-small, ultra-fast and ultra secure IP is designed for specific constraints including resource-constrained electronics (PQMicroLib), high-performance, scalable PQC ( PQPerform ) and heavy industrial and CNI security ( PQPlatform ). With regulations tightening, we’re particularly focused on ensuring that compliance is high on the priority list, and the impact of the CRA cannot be understated over the course of the few years.