Solutions · By Industry · Iot

IoT & Connected Devices

Three EU regulations cross your product : CRA (December 2027), RED cyber (live since August 2025), NIS2 if you sell to essential entities. NexCyber gives you one source of truth.

Pain

Three regulations, three audits, three Big4 quotes, three different conclusions about your SBOM.

What you want

One assessment. One SBOM. One MRCC that covers CRA + RED + NIS2.

What you get

NexCyber detects regulation overlap and maps controls without double-work. Issue one certificate, not three.

Your regulatory landscape

If you ship connected hardware to the EU market, you face three concurrent regulations :

  • CRA (Cyber Resilience Act) — full enforcement 11 Dec 2027. Mandatory cybersecurity for products with digital elements. €15M / 2.5% turnover max.
  • RED (Radio Equipment Directive) — Article 3(3)(d)(e)(f) cybersecurity live since 1 Aug 2025. Network resilience + data protection + fraud prevention. Market withdrawal + national penalties.
  • NIS2 (if your buyers are essential entities) — your IoT product becomes a piece of their supply chain. They pass you the risk through procurement clauses.

Each of these wants : an SBOM, vulnerability handling, conformity dossier, CE marking, secure-by-design proof.

How NexCyber consolidates

One SBOM, three regulations. Your SPDX or CycloneDX file is auto-mapped to CRA Art. 13 + RED Art. 3 cybersecurity + NIS2 supply chain Article 21.

One conformity dossier. Module A self-assessment OR Module B+C Notified Body workflow — ready to hand over.

One MRCC. A single signed certificate that covers all three regulations, verified cryptographically by your customers' procurement teams.

IoT-specific value

  • EN 18031 / EN 303 645 baseline — consumer IoT requirements pre-filled
  • CRA Class I / II classification — automated based on your product specs
  • Supply chain visibility — track third-tier component vendors
  • Vulnerability monitoring — known CVE mapping across your dependency tree, alerts when new CVEs hit your SBOM

Get started

Free assessment in 5 minutes — detects which regulations apply to your specific IoT product.

Versus what you do today

Big4 consulting · In-house spreadsheet · NexCyber.

DimensionBig4 / ConsultingIn-house spreadsheetNexCyber
First assessment delay
4–8 weeks
2–6 weeks
5 minutes
Cost per regulation cycle
€90k–170k
€30k+ hidden
Included
Reproducibility
Slide deck of the day
Depends on editor
Deterministic, identical re-runs
Article-level traceability
Footnote
Often missing
Live link to EUR-Lex
Update when law changes
Re-billed mission
Restart from scratch
Automatic, MRCC re-signed
Deliverable format
Static PDF
XLSX/Word
PDF + MRCC machine-verifiable
Auditor verification
Email + chase
Not verifiable
sha256 verified in seconds
Multi-regulation simultaneous
1 mission per regulation
Duplicates & conflicts
5 regulations, 1 source of truth
New product line evolution
Re-billed mission
Full re-entry
Clone + delta
Run free assessment