Cyber Resilience Act: Why Hardware Trust Matters

Cyber Resilience Act requires Hardware Trust

Strengthening Cyber Resilience Act Readiness with Hardware Trust

The European Union Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, establishes mandatory cybersecurity requirements for products with digital elements made available on the EU market.

The CRA applies to qualifying hardware and software products and introduces cybersecurity responsibilities throughout the product lifecycle, from design and development to deployment, vulnerability management, maintenance, and security updates.

The Cyber Resilience Act entered into force on December 10, 2024. Its reporting obligations apply from September 11, 2026, while the main product requirements apply from December 11, 2027.
As organizations prepare, much of the attention is understandably focused on software security, vulnerability management, secure development, SBOMs, and patching.

But there is another important question: Can an organization reliably identify and trust the hardware connected to its products and infrastructure?

This is where Sepio and Zero Trust Hardware Access can help organizations strengthen Cyber Resilience Act readiness.

Sepio does not provide Cyber Resilience Act compliance by itself. Sepio provides a hardware trust layer that can help support several Cyber Resilience Act cybersecurity objectives, including:

  • Hardware asset discovery
  • Hardware-derived device identity
  • AssetDNA™
  • Zero Trust Hardware Access
  • Hardware risk assessment
  • Unauthorized-device detection
  • Hardware attack-surface visibility
  • Continuous monitoring of hardware changes
  • Security investigation and evidence

The underlying principle is simple: Cyber resilience requires more than knowing that a device exists. It requires knowing whether that device can be trusted.

What Is the EU Cyber Resilience Act?

The Cyber Resilience Act (CRA) is European Union legislation designed to improve the cybersecurity of products with digital elements.

The European Commission describes the Cyber Resilience Act as addressing cybersecurity deficiencies in hardware and software products, including inadequate security and insufficient availability of timely security updates.

The legislation places cybersecurity responsibilities on manufacturers and other relevant economic operators throughout the lifecycle of products with digital elements.

Depending on the product and its classification, these responsibilities can include areas such as:

  • Cybersecurity risk assessment
  • Secure-by-design development
  • Protection against unauthorized access
  • Protection of confidentiality and integrity
  • Attack-surface reduction
  • Vulnerability handling
  • Security updates
  • Technical documentation
  • Vulnerability and incident reporting
  • Conformity assessment

The Cyber Resilience Act therefore represents an important transition: Cybersecurity becomes a product lifecycle responsibility.

Why Is the Cyber Resilience Act Particularly Relevant Now?

On July 27, 2026, the European Commission published new guidance designed to support manufacturers, developers, and businesses preparing for Cyber Resilience Act implementation.

The guidance provides further clarification around issues including Cyber Resilience Act scope, product obligations, substantial modification, and implementation. The timing is significant.

Cyber Resilience Act reporting requirements apply from September 11, 2026, including reporting requirements concerning actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.

The main Cyber Resilience Act obligations then apply from December 11, 2027.
For manufacturers, Cyber Resilience Act preparation therefore needs to be underway today.

The Cyber Resilience Act Is Not Just About Software

Much of the conversation around Cyber Resilience Act readiness focuses on software.
Organizations are investing in:

  • Secure SDLC
  • Application security
  • Software composition analysis
  • Vulnerability management
  • SBOM
  • Patch management
  • Penetration testing
  • Vulnerability disclosure
  • Security updates

All of these are important. But the Cyber Resilience Act explicitly concerns hardware and software products with digital elements. That creates another dimension of cyber resilience: Can you trust the hardware?

A digital product rarely operates in isolation. It may:

  • Connect to network infrastructure
  • Interact with other devices
  • Use USB devices and peripherals
  • Depend on third-party equipment
  • Connect to industrial systems
  • Be maintained through external hardware
  • Communicate through networking equipment
  • Operate in an environment that changes after deployment

Each of these interactions can potentially affect cybersecurity risk.

Visibility Is Not the Same as Trust

Most organizations already have significant device visibility. Devices can be identified using information such as:

  • IP addresses
  • MAC addresses
  • Operating-system information
  • Software agents
  • Network traffic
  • SNMP
  • Device certificates
  • Vendor information
  • USB VID/PID identifiers

These are valuable sources of information. But they primarily help answer: What does this device appear to be? Cyber resilience introduces a deeper question: Is this device actually what we expect it to be, and should we trust it?

That distinction matters. Logical identifiers alone may not always provide sufficient assurance about the physical device behind them.

  • Devices can expose unexpected functionality.
  • Unauthorized hardware can be introduced.
  • An apparently familiar peripheral may behave differently from expected devices.
  • Some network devices may also be difficult to identify using conventional IP- or traffic-oriented discovery methods.

This creates what we call the: Hardware Trust Gap. The hardware trust gap exists between:

Seeing a Device

Traditional visibility identifies that a device exists.

Verifying Trust

Confirming the device is actually what it claims to be.

What Is Zero Trust Hardware Access?

Zero Trust is commonly summarized through a straightforward security principle: Never trust implicitly. Verify explicitly. Organizations increasingly apply this concept to:

  • Users
  • Identities
  • Applications
  • Workloads
  • Endpoints
  • Network sessions
  • Cloud resources

But one element can still be implicitly trusted: The hardware itself.

Zero Trust Hardware Access extends Zero Trust principles to physical devices. Instead of assuming that a device is legitimate because it presents familiar identifiers, organizations can evaluate additional hardware-derived intelligence before determining how that device should be treated.

Sepio applies this approach through: Discover ➜ Verify ➜ Assess ➜ Enforce

  1. Discover: Identify connected hardware across host and network environments.
  2. Verify: Determine whether observed hardware characteristics match the device identity the organization expects.
  3. Assess: Evaluate the device using hardware intelligence, organizational policy, AssetDNA™, and associated risk indicators.
  4. Enforce: Translate verified device intelligence into policy enforcement, remediation, or security-response decisions.
Sepio hardware visibility overview dashboard
Sepio Visibility Overview

How Does Sepio Support Cyber Resilience Act Readiness?

Cyber Resilience Act compliance requires a combination of processes, technologies, documentation, governance, and organizational responsibilities.

No single cybersecurity technology provides complete Cyber Resilience Act compliance. Sepio should therefore not be positioned as a standalone Cyber Resilience Act compliance platform.

Instead: Sepio provides a hardware trust layer that can support specific Cyber Resilience Act cybersecurity objectives. The strongest areas of applicability are:

CRA Cybersecurity AreaSepio Applicability
Cybersecurity risk assessmentHardware discovery, identity, AssetDNA™ and risk indicators
Asset visibilityContinuous hardware asset intelligence
Protection against unauthorized accessZero Trust Hardware Access
Device trustHardware-derived device identity
Attack-surface reductionDiscovery of unknown, unmanaged and unexpected hardware
Continuous risk managementIdentification of hardware and topology changes
Supply-chain riskVisibility into hardware actually present or connected
Incident investigationDevice history, identity and hardware context
Security evidenceAsset, event and risk information
Vulnerability reportingSupporting investigation evidence; not regulatory reporting
SBOMComplementary; Sepio does not replace SBOM
Secure software developmentIndirect applicability

Sepio and Cyber Resilience Act Cybersecurity Risk Assessment

Cybersecurity risk assessment is fundamental to Cyber Resilience Act. Manufacturers need to understand cybersecurity risks associated with their products and account for those risks throughout the product lifecycle.

But effective risk assessment depends upon accurate asset information. Security teams need to know:

  • What is connected?
  • What is authorized?
  • What is unmanaged?
  • What has changed?
  • What introduces risk?
  • Can the identity of the device be trusted?

How Sepio Can Help? Sepio can provide hardware intelligence relating to:

  • Known hardware
  • Unknown hardware
  • Unmanaged assets
  • Network-connected devices
  • USB devices
  • Peripheral devices
  • Hardware identity anomalies
  • Unexpected device characteristics
  • Changes in hardware
  • Hardware-related risk indicators

This information can provide another input into the organization’s broader cybersecurity risk assessment process.

The key principle: An asset that cannot be confidently identified cannot be confidently assessed.

Sepio and Protection Against Unauthorized Access

Protection against unauthorized access is another important Cyber Resilience Act cybersecurity objective. At the hardware layer, unauthorized access can involve more than users and credentials. It can involve an unauthorized physical device. Examples include:

  • Unauthorized USB devices
  • Unexpected Human Interface Devices (HIDs)
  • Rogue peripherals
  • Unauthorized adapters
  • Unknown network equipment
  • Unapproved maintenance hardware

Security controls may recognize these devices according to logical identifiers presented by the devices themselves. Zero Trust Hardware Access adds another layer. Instead of relying only upon:

MAC address ➜ IP address ➜ device name ➜ USB VID/PID ➜ reported identity

organizations can incorporate hardware-derived identity and risk intelligence.

The security decision becomes: Is this device actually consistent with what we expect and should it have access?

Sepio and Hardware Attack-Surface Reduction

Attack-surface management is traditionally focused heavily on software. Security teams identify:

  • Vulnerabilities
  • Exposed ports
  • Internet-facing systems
  • Unnecessary services
  • Insecure applications
  • Misconfigurations

But organizations also have a: Hardware Attack Surface. The hardware attack surface may include:

  • Unauthorized USB devices
  • Unexpected HID devices
  • Unknown peripherals
  • Unmanaged switches
  • Unauthorized network equipment
  • Transparent network devices
  • Maintenance equipment
  • Unexpected adapters
  • Undocumented connected assets

These devices may not always appear clearly within conventional software vulnerability-management workflows. Sepio can provide additional visibility into this hardware layer.

And the principle is straightforward: You cannot reduce an attack surface you cannot identify.

Sepio and Continuous Cybersecurity Risk Management

Cybersecurity assessment cannot stop when a product leaves the factory. Real-world environments change. A product may be deployed into an environment where:

  • Network equipment is replaced
  • Peripherals are added
  • Infrastructure changes
  • Maintenance equipment is temporarily connected
  • Hardware components are replaced
  • New devices appear
  • Unauthorized equipment is introduced

A point-in-time inventory can quickly become outdated. Continuous hardware intelligence helps identify these changes. Sepio can detect changes involving:

  • Newly discovered hardware
  • Device disappearance
  • Hardware identity
  • Device characteristics
  • Network relationships
  • Infrastructure topology
  • Associated risk indicators

This enables organizations to move from:

What hardware did we have during the assessment?

What hardware do we have now, what changed, and does that change affect trust?

The Commission’s 2026 Cyber Resilience Act guidance also provides clarification regarding substantial modification, reinforcing the importance of understanding changes to products and their cybersecurity implications.

Sepio, Cyber Resilience Act and Supply-Chain Security

Software supply-chain security has become a major cybersecurity priority. Organizations increasingly use:

  • SBOM
  • Software composition analysis
  • Dependency management
  • Vulnerability databases
  • Code-signing controls

These capabilities answer important questions about software. But cyber resilience also needs to consider hardware.

SBOM and Hardware Intelligence Answer Different Questions.

An SBOM helps answer:

What software components are included in this product?

Hardware intelligence helps answer:

What hardware is actually present, connected, or being trusted?

These are different but complementary questions.

Sepio does not replace an SBOM. Instead, hardware intelligence can complement software supply-chain security by providing visibility into the physical devices operating within the environment.

A more complete trust model therefore considers: Software Composition + Hardware Identity

Sepio and Cyber Resilience Act Incident Investigation

Beginning September 11, 2026, Cyber Resilience Act manufacturers are required to report qualifying actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.

Sepio is not a Cyber Resilience Act regulatory reporting platform. However, investigation before reporting requires context.

When hardware may be relevant to an event, investigators may need to answer questions such as:

  • What device was connected?
  • When was it first observed?
  • Where was it connected?
  • Had the device been seen before?
  • Was the device expected?
  • What hardware characteristics were observed?
  • Were any characteristics anomalous?
  • Were hardware-related risk indicators triggered?
  • What other infrastructure was associated with the device?

Hardware asset intelligence can provide valuable supporting information for cybersecurity investigations.

This can shorten the distance between:

Something happened.

We understand what was present when it happened.

Sepio and Continuous Cybersecurity Evidence

Cybersecurity regulations increasingly require organizations to demonstrate not only that controls exist, but that risk is being actively managed.

Sepio can provide supporting information around:

  • Hardware inventory
  • Asset identity
  • Device characteristics
  • Asset history
  • Hardware risk indicators
  • Policy violations
  • Infrastructure relationships
  • Security events
  • Topology
  • Device changes over time

This introduces an important concept: Continuous Hardware Trust Evidence. Traditional asset inventories provide a snapshot. Continuous hardware intelligence provides evidence of how the environment changes over time.

For manufacturers preparing for Cyber Resilience Act, this additional context can complement evidence produced by secure development, vulnerability management, incident response, and other security processes.

What Is Sepio AssetDNA™?

AssetDNA™ is Sepio’s technology for building deeper intelligence about connected assets using hardware-related characteristics rather than relying exclusively on conventional logical identifiers.

Traditional asset identification can depend heavily on information such as:

  • IP address
  • MAC address
  • Operating system
  • Vendor identifiers
  • USB identifiers
  • Software agents
  • Network information

Sepio supplements these signals with hardware-derived characteristics. The objective is to determine whether the observed physical characteristics of a device are consistent with what the organization expects. This creates an additional layer of device trust.

From Device Visibility to Verified Device Identity

This distinction is central to understanding Sepio’s role in Cyber Resilience Act readiness.

Device Visibility

➜ A device exists.

Device Identification

➜ The device appears to be Device X.

Device Verification

➜ Its observed hardware characteristics are consistent with Device X.

Device Trust

➜ Based on verified identity, context, risk and policy, Device X can be trusted.

That progression represents the shift from traditional asset visibility toward: Zero Trust Hardware Access (ZTHA).

Where Sepio Does Not Replace Other Cyber Resilience Act Controls

Cyber Resilience Act implementation requires multiple complementary cybersecurity capabilities.

Sepio does not replace:

  • Secure software development
  • Application security testing
  • Software composition analysis
  • SBOM platforms
  • Vulnerability scanners
  • Patch-management systems
  • Penetration testing
  • Security update processes
  • Incident-reporting platforms
  • Regulatory compliance management
  • Product conformity assessment

Sepio addresses a different question: Can the organization identify and verify the hardware it is trusting?

That makes Sepio complementary to the broader Cyber Resilience Act security stack.

A mature Cyber Resilience Act cybersecurity architecture may therefore combine:

Secure SDLC + SBOM + Vulnerability Management + Application Security + EDR + SIEM + Incident Response + Hardware Trust

The Missing Hardware Layer in Cyber Resilience Act Readiness

Organizations preparing for Cyber Resilience Act are likely to invest heavily in software security. They should. But every Cyber Resilience Act readiness assessment should also include these questions:

  • What hardware is interacting with our products and infrastructure?
  • Is that hardware authorized?
  • Is it really what it claims to be?
  • Does it introduce new cybersecurity risk?
  • Can we detect when that hardware changes?
  • Can we enforce policy when hardware cannot be trusted?
  • Can we reconstruct the hardware environment during an investigation?

If those questions cannot be answered confidently, an important trust assumption remains. That is the gap Zero Trust Hardware Access is designed to address.

Cyber Resilience Requires Hardware Trust

The Cyber Resilience Act establishes a new cybersecurity baseline for products with digital elements across the European Union. But its significance extends beyond regulatory compliance. Cyber Resilience Act reflects a broader shift toward cybersecurity that is:

  • Continuous
  • Risk-based
  • Lifecycle-oriented
  • Evidence-driven
  • Built into products rather than added afterwards

Extending those principles to hardware is a logical next step.

  • Zero Trust should apply to users.
  • It should apply to applications.
  • It should apply to workloads.
  • And it should apply to devices. Because seeing hardware is not enough. You need to know whether you can trust it.
Talk to an expert. See What You’ve Been Missing.

Frequently Asked Questions

The EU Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, establishes cybersecurity requirements for products with digital elements made available on the European Union market.
It addresses cybersecurity across the product lifecycle, including product security, vulnerability handling, security updates, documentation, and reporting.

Yes.
The Cyber Resilience Act covers qualifying hardware and software products with digital elements. The European Commission describes the Cyber Resilience Act as establishing cybersecurity requirements for hardware and software products placed on the EU market.

The Cyber Resilience Act entered into force on December 10, 2024.
Its reporting obligations apply from September 11, 2026, and most of its main product obligations apply from December 11, 2027.

The European Commission published new Cyber Resilience Act implementation guidance on July 27, 2026 to provide additional clarity for manufacturers, developers, and businesses preparing to apply the regulation.

No.
Sepio is not a standalone Cyber Resilience Act compliance solution, and no individual cybersecurity technology can make a manufacturer Cyber Resilience Act compliant.
Sepio provides hardware asset intelligence and Zero Trust Hardware Access capabilities that can support specific cybersecurity objectives within a broader Cyber Resilience Act program.

 

Sepio can support Cyber Resilience Act readiness through:

  • Hardware asset discovery
  • Hardware-derived device identity
  • AssetDNA™
  • Hardware risk assessment
  • Unauthorized-device detection
  • Hardware attack-surface visibility
  • Zero Trust Hardware Access
  • Continuous hardware monitoring
  • Incident-investigation context
  • Continuous hardware trust evidence

Sepio helps organizations identify known, unknown, unmanaged, unexpected, and potentially unauthorized hardware.
This provides security teams with additional hardware intelligence that can be incorporated into broader cybersecurity risk-assessment processes.

Zero Trust Hardware Access applies Zero Trust principles to physical devices.
A device is not automatically trusted simply because it presents familiar logical identifiers.
Instead, Sepio enables organizations to:
Discover → Verify → Assess → Enforce
This allows hardware trust decisions to incorporate hardware-derived identity, context, risk, and organizational policy.

Risk management depends on accurately identifying the assets being assessed and trusted.
If a security system identifies hardware only through logical information presented by the device, additional uncertainty may remain regarding the device’s true physical identity.
Hardware-derived intelligence provides another layer of verification.

AssetDNA™ is Sepio’s technology for creating deeper device intelligence based on hardware-related characteristics.
AssetDNA™ supplements conventional logical identifiers and helps determine whether an observed device is consistent with the hardware the organization expects.

Traditional asset-discovery approaches can rely heavily on logical information such as:

  • IP addresses
  • MAC addresses
  • Software agents
  • Network traffic
  • Operating-system information
  • Device-reported identifiers

Sepio adds hardware-derived intelligence to provide additional context about the physical identity and risk associated with the device.

The hardware trust gap is the difference between knowing that a device exists and having sufficient confidence that the physical device being trusted is actually what the organization expects it to be.
Sepio addresses this gap through hardware discovery, AssetDNA™, risk intelligence, and Zero Trust Hardware Access.

A hardware attack surface consists of physical devices, components, connections, and interfaces that could introduce cybersecurity risk.
Examples can include:

  • USB devices
  • HID devices
  • Network equipment
  • Unmanaged switches
  • Transparent network devices
  • Peripheral devices
  • Maintenance equipment
  • Unknown connected assets

Sepio provides visibility into connected hardware and helps identify assets that are unknown, unexpected, unmanaged, anomalous, or inconsistent with organizational policy.
Security teams can use this intelligence to investigate and respond to potential hardware risk.

Sepio is designed to identify and assess connected hardware and can help security teams discover devices that may be unknown, unexpected, unauthorized, or inconsistent with organizational policies.

Yes.
Sepio provides hardware intelligence for USB devices and peripherals and can identify characteristics or functionality that may require additional investigation or policy action.

Sepio is designed to provide asset intelligence across network environments, including devices that may not be readily identified through conventional agent-based or purely IP-based approaches.

No.
An SBOM, or Software Bill of Materials, identifies software components.
Sepio provides hardware asset and device identity intelligence.
These technologies solve different problems and can complement each other.

An SBOM helps answer:
What software is included in the product?
Hardware intelligence helps answer:
What physical hardware is present, connected, or being trusted?
Both can contribute to a more comprehensive cybersecurity risk picture.

Cyber Resilience ActThe Cyber Resilience Act should not be interpreted as creating a universal Hardware Bill of Materials requirement equivalent to an SBOM requirement.
However, understanding hardware assets and device identity can support broader cybersecurity risk-management objectives relevant to CRA readiness.
How does Sepio support hardware supply-chain security?
Sepio provides visibility into the hardware actually observed within an environment.
This can complement software supply-chain controls by helping organizations identify unexpected hardware and verify whether connected devices are consistent with what the organization expects.

Sepio adds hardware-derived context to device identity and risk assessment.
This intelligence can support policy decisions concerning whether connected hardware should be trusted, restricted, investigated, or otherwise remediated.

Yes.
Sepio can provide supporting context including:

  • Device identity
  • Asset history
  • Connection context
  • Hardware characteristics
  • Risk indicators
  • Infrastructure relationships
  • Changes over time

This information may help organizations investigate cybersecurity events involving hardware.

No.
Sepio does not replace official Cyber Resilience Act vulnerability or incident-reporting processes.
Sepio can provide supporting hardware intelligence and evidence that may contribute to incident investigation and reporting preparation.
Cyber Resilience Act reporting obligations concerning qualifying actively exploited vulnerabilities and severe security incidents apply from September 11, 2026.

Sepio can provide information relating to:

  • Hardware inventory
  • Asset identity
  • Device characteristics
  • Hardware risk indicators
  • Asset history
  • Device changes
  • Policy violations
  • Infrastructure relationships
  • Security events

This can complement evidence generated by other elements of an organization’s Cyber Resilience Act cybersecurity program.

Hardware environments change after initial deployment.
Devices may be added, removed, replaced, upgraded, or temporarily connected.
Continuous hardware monitoring helps organizations identify these changes and assess whether they introduce new cybersecurity risks.

Device visibility means knowing that a device exists.
Device identification means determining what that device appears to be.
Verification of the device, means establishing whether observed characteristics are consistent with the expected device.
Trust in the device, means deciding, based on identity, context, risk, and policy, whether the device should be allowed to operate.

Hardware trust may be particularly relevant to manufacturers and organizations operating:

  • IoT products
  • Industrial equipment
  • OT environments
  • Connected medical technology
  • Telecommunications equipment
  • Networking equipment
  • Financial infrastructure
  • Critical infrastructure
  • Manufacturing systems
  • Embedded systems
  • Security appliances
  • Other connected products with digital elements

Organizations should ask:
Can we continuously identify the hardware interacting with our products and infrastructure, verify that it is what we expect, understand the risk it introduces, and take action when trust cannot be established?
If the answer is no, hardware trust may represent a missing layer in the organization’s cybersecurity strategy.

Sepio’s role is to provide a hardware trust layer within a broader CRA cybersecurity strategy.
Sepio helps organizations:
Discover hardware.
Verify device identity.
Assess hardware risk.
Enforce security policy.
Maintain continuous hardware intelligence.
The relationship can be summarized simply:
The CRA raises the bar for cyber resilience. Sepio helps organizations address the hardware trust required to support that resilience.

August 20th, 2026