What Is the EU Cyber Resilience Act?
The EU Cyber Resilience Act (CRA) is a regulation that establishes cybersecurity requirements for hardware and software products placed on the European Union market that process, store, or transmit digital data. It has a definitive set of deadlines for compliance as listed below.
Key Deadlines:
- September 11, 2026 — Vulnerability and incident reporting obligations begin (24-hour reporting to ENISA required)
- December 11, 2027 — Full CRA compliance required
Scope and Purpose
The CRA applies to any hardware and software product with digital elements, including FPGAs, ASICs, microcontrollers, development tools, and IP cores. Its goal is to ensure that products are secure by design, resilient throughout their lifecycle, and that vulnerabilities are handled transparently and promptly.
Key Objectives
- Secure by design and default
- Lifecycle resilience and vulnerability handling
- Coordinated disclosure and timely updates
- Informed purchasing and supply chain transparency
- A level playing field for global manufacturers
Product Cybersecurity Requirements
- No known exploitable vulnerabilities at time of market placement
- Secure by default, proportionate to risk
- Protect confidentiality, integrity, and availability
- Secure authentication and access control
- Secure update mechanisms and minimal attack surface
Vulnerability Handling Requirements
- Identify and document vulnerabilities (SBOM where relevant)
- Prompt correction via updates or mitigations
- Coordinated vulnerability disclosure policy
- Actively exploited vulnerabilities reported to ENISA within 24 hours
- Defined support period for the product lifecycle
CRA Product Classifications
The CRA defines three product categories, each with different conformity assessment requirements.
| Category | Conformity Assessment |
|---|---|
| Default | Self-assessment (Module A). Requires risk analysis, technical documentation, and vulnerability reporting from September 2026. |
| Important Class I | Self-assessment if IEC 62443 harmonized standards are applied; otherwise, third-party assessment may be required. |
| Important Class II / Critical | Third-party Notified Body assessment or EU cybersecurity certification scheme required. |
How Lattice Technology Supports CRA Compliance
From established security standards to proven hardware features, Lattice provides the technical foundation your team needs to meet CRA requirements across the full product lifecycle. Lattice offers FPGAs, software design tools and IP, reference designs, and a solution stack that can help your organization accelerate its CRA compliance efforts with confidence.
FPGA Security Features
The Lattice MachXO5™-NX TDQ, Lattice Mach™-NX, and other security-capable FPGAs deliver built-in secure boot, Root of Trust, PQC-ready cryptography, and Platform Firmware Resiliency (PFR), helping address Important Class I cybersecurity requirements under the CRA. The Lattice MachXO5™-NX TDQ FPGAs are designed to help you protect against emerging quantum-era threats. They ship with ML-KEM and ML-DSA, meeting the encryption and digital signature requirements now mandated by both CRA and U.S. Executive Order 14412. Legacy Lattice FPGAs typically fall within the Default category and require risk assessments, technical documentation, and vulnerability reporting.
CRA-Aligned Design Tools and IP
The Lattice Radiant® and Lattice Propel™ software design tools support secure development lifecycle practices, vulnerability management, and CRA-aligned design flows. Lattice IP cores, reference designs, and the Lattice Sentry™ solution stack provide secure integration patterns to help customers build compliant systems faster.
Post-Quantum Cryptography (PQC)
Lattice FPGAs combine low power, high performance, and reconfigurability, making them well suited to accelerating PQC algorithms with the low latency and high throughput required for network security, hardware security modules, and secure communication. Because FPGAs can be reprogrammed to implement new PQC schemes as standards evolve, organizations are able to future-proof deployed hardware against quantum-era threats. Lattice provides secure FPGA platforms and products that meet advancing security standards and enable prompt PQC adoption.
Root of Trust and Secure Boot
Hardware Root of Trust helps ensure that only authenticated, unmodified firmware boots on your system. This directly satisfies CRA requirements for secure authentication, integrity protection, and resilience against unauthorized modification.
Platform Firmware Resiliency (PFR)
Lattice PFR solutions help protect, detect, and recover firmware in real time. Meeting NIST SP 800-193 and IEC 62443 standards, Lattice PFR provides the lifecycle resilience that CRA mandates for products deployed in Industrial and Operational Technology environments.
IEC 62443 and Zero Trust Alignment
Lattice's industrial security strategy is built around IEC 62443 and Zero Trust principles, both of which align with CRA harmonized standards pathways. Using these frameworks can qualify security-featured FPGAs for Important Class I self-assessment, avoiding costly third-party audits.
Vulnerability Reporting Readiness
CRA requires manufacturers to report actively exploited vulnerabilities to ENISA within 24 hours starting September 2026. Lattice is continuing to enhance the processes and customer communication channels needed to support compliance across both legacy and security-featured portfolios.
Open Security Test Consortium
Lattice participates in open test consortia, independently validating silicon, IP, and tool chain security. Transparent, publicly accessible test results give your engineering team the documented evidence needed to support CRA technical documentation requirements.
Ready to Start Your CRA Compliance Journey?
Connect with Lattice experts to assess your portfolio and develop a CRA compliance strategy.







