CYBER RESILENCE ACT (CRA)
Digital products, connected devices, and software-defined systems are now a central component of modern industrial and business processes. At the same time, security requirements for such products are increasing significantly. With the Cyber Resilience Act (CRA), the European Union is establishing, for the first time, a uniform legal framework for the cybersecurity of products with digital elements. The objective is to ensure that cybersecurity is not considered only after deployment, but is integrated from the very beginning into development, manufacturing, operation, and maintenance.
WHAT IS THE CYBER RESILIENCE ACT?
The Cyber Resilience Act is an EU regulation that establishes mandatory minimum requirements for the cybersecurity of hardware and software products. It applies to so-called « products with digital elements »- products that can be directly or indirectly connected to a device, network, or digital service. This includes simple connected devices as well as complex industrial systems, control units, software components, and applications.
WHY IS IT IMPORTANT FOR USERS?
For users, the CRA provides greater transparency and a higher level of security when using digital products. Manufacturers will be required to demonstrate that their products meet fundamental cybersecurity requirements, that risks have been assessed, and that vulnerabilities are managed throughout the product lifecycle. This is intended to ensure that products are delivered more securely, updated more effectively, and documented in a more traceable manner.
WHAT DOES THIS MEAN FOR MANUFACTURERS AND PRODUCT DEVELOPERS?
The CRA requires manufacturers to systematically integrate cybersecurity into their processes. This includes, among other things, risk-based product development, secure default settings, appropriate update and patch mechanisms, vulnerability management, and comprehensive technical documentation.
The approach follows the principles of « secure by design » and « secure by default ». In other words, security must be considered from the product concept phase onward and must be effective in the standard product configuration.
Outlook: Security as a Quality Attribute
The Cyber Resilience Act clearly demonstrates that cybersecurity is becoming an integral part of product quality. This creates an opportunity for companies to build trust, reduce risks, and future-proof their product development. Organizations that address cybersecurity early can meet regulatory requirements more efficiently while delivering genuine added value to their customers.
CRA at Middex
As a development partner for electronic assemblies, systems, and technical solutions, Middex supports companies in integrating regulatory and technical requirements into product concepts at an early stage. Our goal is to combine functionality, security, and practical usability from the initial idea through development to documented implementation. The Cyber Resilience Act is not merely a regulatory obligation, but a key building block for robust, trustworthy, and long-lasting products.
GUIDELINES & LEGAL INFORMATION
European Union Cyber Resilience Regulation
The Cyber Resilience Act establishes harmonized cybersecurity requirements across Europe for products with digital elements. Further information on the regulation and its scope of application can be found in the official publications of the European Union.
BSI / Technical Guideline
The « Bundesamt für Sicherheit in der Informationstechnik (BSI) » promotes information security in the digital age through prevention, detection, and response measures for government, industry, and society. As Germany’s national cybersecurity authority, the BSI plays a key role in shaping and supporting secure digital transformation.
As part of its approach to Cyber Resilience Act (CRA) compliance, Middex has taken relevant BSI recommendations and technical guidelines into consideration when designing and implementing cybersecurity-related processes and measures.
Coordinated Vulnerability Disclosure (CVD) Policy
At Middex, we take cybersecurity and the responsible handling of reported vulnerabilities very seriously. Every submitted report is carefully reviewed and processed within an appropriate and timely framework. Where possible, reporters will be kept informed about the progress of the investigation and remediation activities. To enable efficient assessment and accurate classification of reported issues, we ask that this reporting channel be used responsibly and only for relevant, verifiable, and well-substantiated information.
Scope: This policy applies to products, software components, systems, and technical solutions developed and maintained by Middex.
Contact Language: Please submit security-related reports and inquiries in English. This helps us ensure clear, consistent, and timely communication and review.
Contact: For vulnerability reports, questions, or suggestions regarding product security, please contact us at:
or submit an anonymous report using the form below:
Guidelines for Responsible Disclosure
When reporting a vulnerability, we ask that you:
- Notify us promptly upon discovering an actual or suspected security vulnerability.
- Conduct testing or proof-of-concept activities only to the extent necessary to verify the existence of the vulnerability.
- Allow us a reasonable period to investigate and remediate the issue before disclosing information publicly.
- Refrain from submitting large numbers of incomplete, unclear, duplicate, or low-quality reports.
Reporting a Vulnerability
Information submitted under this policy will be used solely for defensive purposes, including the assessment, mitigation, and remediation of vulnerabilities. Reports may be submitted anonymously. If contact details are provided, we will acknowledge receipt of your report where possible.
To help us efficiently analyze and reproduce the reported issue, please include the following information where applicable:
- The affected product, including relevant hardware and software version information.
- A detailed description of the vulnerability and the testing methodology used to identify and verify it, preferably in a reproducible manner.
- Details regarding the potential impact and any known mitigation measures.
- Additional information that may support analysis and reproduction of the issue, such as infrastructure descriptions, system environments, interface diagrams, screenshots, log files, or similar technical documentation.
