CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Policy & Compliance

How the EU Cyber Resilience Act Reshapes Compliance for Software Defined Vehicles

CarThreat Staff
Last updated: June 19, 2026 2:54 am
By
ctadmin
2 Min Read
SHARE

CRA Scope and Automotive Overlap

The EU Cyber Resilience Act (CRA), effective December 2024 with main obligations starting December 2027, introduces horizontal cybersecurity requirements for any hardware or software with digital elements sold in the EU. For the automotive sector, this regulation targets components that fall outside existing vehicle specific frameworks like UN R155 and ISO/SAE 21434. Key areas of impact include telematics units, infotainment systems, aftermarket diagnostic dongles, cloud connected APIs, V2X components, and EV charging infrastructure. Products already covered by equivalent sector specific EU rules may be excluded, but the burden rests on manufacturers to prove that equivalence.

Contents
CRA Scope and Automotive OverlapWhat OEMs and Suppliers Must AddressClosing the SBOM and OTA Gaps

What OEMs and Suppliers Must Address

The CRA shifts cybersecurity from a vehicle approval issue to a broader product compliance matter. OEMs and suppliers must now demonstrate risk assessment, vulnerability handling, software update capability, and technical documentation for each digital component. This creates a significant supplier management challenge because many connected vehicle risks originate outside the core vehicle platform. The regulation requires manufacturers to exercise due diligence over third party components and to maintain support periods for products with digital elements, with clear end dates communicated at purchase.

Closing the SBOM and OTA Gaps

A Software Bill of Materials (SBOM) becomes critical under the CRA, because connected vehicles contain a complex mix of proprietary code, open source libraries, supplier firmware, and cloud services. Without accurate software composition data, OEMs cannot quickly answer which vehicles contain a vulnerable component or whether a patch can be deployed OTA. Secure over the air updates move from a UN R156 best practice to compliance evidence, as the CRA expects manufacturers to identify vulnerabilities, map affected components, and deploy patches rapidly. Automotive businesses should map CRA scope across their connected vehicle ecosystem, build SBOM maturity, align vulnerability management with CRA reporting timelines, and connect evidence across UN R155, R156, and ISO/SAE 21434 to create a single cybersecurity assurance model.

Source: Automotive IQ

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesEU Cyber Resilience ActOTA UpdatesSBOMsoftware defined vehiclessupplier complianceUN R155
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Researchers find 36 million GPS trackers open to vehicle theft

By
ctadmin
August 6, 2026
India drafts vehicle cybersecurity rules after e-rickshaw hacks
Policy & Compliance

India drafts vehicle cybersecurity rules after e-rickshaw hacks

By
ctadmin
August 1, 2026
Research & Innovation

Fake brake alerts in V2X networks can trigger phantom stops

By
ctadmin
August 9, 2026
Cybersecurity

Car networking tool spills stack memory onto CAN from one packet

By
ctadmin
August 19, 2026
Policy & Compliance

Gipuzkoa’s Automotive Sector Gears Up for Cyber Resilience Act Compliance

By
ctadmin
June 19, 2026
CybersecurityPolicy & Compliance

EU issues 2026 mandate for connected vehicle cybersecurity requirements

By
ctadmin
July 18, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?