Embedded Security & Compliance
Cyber Resilience Act (CRA)
By introducing the Cyber Resilience Act (CRA) and the Radio Equipment Directive (RED), the EU is raising the requirements for cybersecurity and software integrity in connected products. While the RED requirements have been mandatory since August 1, 2025, the CRA requirements will be introduced gradually over the coming years. The aim is to ensure the security of digital products – from development and deployment to updates and maintenance.
Our role as a manufacturer of Computer-On-Modules
Since our embedded modules are integrated into a wide range of applications and industries, KA-RO electronics supplies them without pre-installed software to ensure maximum flexibility and adaptability. The Board Support Package (BSP) we provide serves as a technical reference and as development base for customer-specific systems. It is not intended as a market-ready software product. As each application has individual security and compliance requirements, the responsibility for ensuring CRA- and RED-compliance lies with the respective manufacturer or distributor of the final device.
We support our customers in the best possible way—for example, by recommending suitable testing bodies and maintaining up-to-date references for LTS versions for Linux Kernel and Yocto. We also continuously expand our development environment to facilitate secure implementations—for instance, with Secure Boot, RAUC for updates, and the creation of a Software Bill of Materials (SBOM).
Support and further information
For conformity assessment and certification of your final products, you can contact specialized testing and certification providers, such as:
In addition, the following providers offer helpful tools and services for security analysis, update strategies, and compliance verification:
- kernel concepts
Software full-service provider for embedded systems - TrustnGo
Advanced cybersecurity certification support - Exein
Exein Analyzer: Auto-check compliance and catch vulnerabilities
Exein Runtime: On-device threat detection and incident response
This ensures that you receive the necessary support to make your products fully CRA and RED compliant.