2026产品网络安全进入采购清单:欧盟CRA将如何影响智能硬件供应商?

2026产品网络安全进入采购清单:欧盟CRA将如何影响智能硬件供应商?
**智能硬件采购正在从“功能+价格+认证”升级为“功能+安全+更新能力”。供应商能否发现、报告和修复漏洞,将逐渐成为制造能力的一部分。**

欧盟Cyber Resilience Act(CRA)已于2024年生效,其漏洞和事件报告义务将从2026年9月11日起适用,主要义务则从2027年12月起全面适用。

CRA为什么和采购部门有关?

风险不只发生在IT部门

受影响的“products with digital elements”可能包括:

  • IoT设备;
  • 智能家居;
  • 工业控制设备;
  • 联网仪器;
  • 带软件的电子产品;
  • 部分嵌入式硬件。

如果采购只验证功能,不验证软件更新和漏洞流程,产品上市后的风险可能转移给品牌方和进口商。

买家应该增加哪些供应商问题?

产品安全设计

  • 默认密码如何管理?
  • 是否存在安全启动或签名机制?
  • 第三方软件组件如何管理?
  • 软件版本是否可追踪?

漏洞管理

  • 是否有漏洞响应责任人?
  • 如何接收外部漏洞报告?
  • 补丁发布周期是多少?
  • 哪些版本仍在支持?

CRA采购证据矩阵

维度不够充分的回答更有价值的证据
Cyber Policy“We take security seriously”安全开发流程
Vulnerability“No known issues”漏洞处理SOP
Update“OTA supported”更新策略与版本记录
Components“Standard software”组件/SBOM管理方法
Lifecycle“Long-term support”明确支持年限

对中国智能硬件制造商意味着什么?

出口竞争力不再只是“我们能开发APP和固件”,而是:

**“我们能持续维护产品安全。”**

制造企业应该把研发、质量、售后和信息安全协同起来,建立产品级安全文件,而不是等客户审核时临时拼材料。

适用边界

CRA对不同产品类别、角色和合格评定路径有差异。特别是高网络安全相关产品可能涉及更严格的评估。具体产品应结合欧盟官方分类与法律意见确认。

FAQ

CRA是不是只针对软件公司?

不是,包含数字元素的硬件同样可能受到影响。

有CE就等于满足CRA吗?

不能这样推导。CE是合规标志,具体法规适用和技术证据仍需逐项判断。

买家现在最应该做什么?

在供应商准入中增加漏洞、更新和软件生命周期问题。

未来“供应商工程能力”将包含一个新的维度:

**产品上市以后,谁负责持续保持它安全。**

参考来源

**Procurement of smart hardware is shifting from a focus on "features, price, and certification" to "features, security, and update capabilities." A supplier's ability to discover, report, and remediate vulnerabilities will increasingly be viewed as a core component of their manufacturing capability.**

The EU Cyber ​​Resilience Act (CRA) has entered into force; obligations regarding vulnerability and incident reporting will apply starting September 11, 2026, with the main obligations becoming fully applicable from December 2027.

Why does the CRA matter to procurement departments?

Risks extend beyond the IT department

Affected "products with digital elements" may include:

  • IoT devices;
  • Smart home products;
  • Industrial control equipment;
  • Connected instruments;
  • Electronic products containing software;
  • Certain embedded hardware.

If procurement focuses solely on functionality without verifying software update and vulnerability management processes, post-market risks could shift onto the brand owner and importer.

What questions should buyers ask suppliers?

Secure Product Design

  • How are default passwords managed?
  • Are there secure boot or code-signing mechanisms in place?
  • How are third-party software components managed?
  • Is software versioning traceable?

Vulnerability Management

  • Is there a designated person responsible for vulnerability response?
  • How are external vulnerability reports received?
  • What is the patch release cycle?
  • Which versions are currently supported?

CRA Procurement Evidence Matrix

DimensionInsufficient AnswerValuable Evidence
Cyber ​​Policy"We take security seriously"Secure development process
Vulnerability"No known issues"Vulnerability handling SOP
Update"OTA supported"Update policy and version records
Components"Standard software"Component/SBOM management method
Lifecycle"Long-term support"Clearly defined support duration

What does this mean for Chinese smart hardware manufacturers?

Export competitiveness is no longer defined merely by "our ability to develop apps and firmware," but by:

**"Our ability to continuously maintain product security."**

Manufacturing enterprises should coordinate R&D, quality assurance, after-sales service, and information security to establish product-level security documentation, rather than scrambling to compile materials only when a customer audit arises. ## Scope of Application

The CRA applies differently depending on product categories, roles, and conformity assessment pathways. In particular, products with high cybersecurity relevance may be subject to more rigorous assessment. Specific products should be evaluated based on official EU classifications and legal advice.

FAQ

Does the CRA apply only to software companies?

No; hardware products containing digital elements may also be affected.

Does CE marking automatically mean CRA compliance?

Not necessarily. While CE is a mark of conformity, the applicability of specific regulations and the required technical evidence must be assessed on a case-by-case basis.

What is the most important step for buyers right now?

Incorporate requirements regarding vulnerabilities, updates, and the software lifecycle into the supplier onboarding process.

In the future, "supplier engineering capability" will include a new dimension:

**Who is responsible for maintaining the product's security after it has been placed on the market?**

References