Skip to content

Compliance

2027 is a firmware problem, not a paperwork problem

The EU Cyber Resilience Act and the US Cyber Trust Mark both require the ability to securely update and maintain IoT devices over their lifetime. That is a product capability, not a PDF.

2026-08-12

Two clocks are now public. The EU Cyber Resilience Act (Regulation (EU) 2024/2847) brings full obligations from 11 December 2027, with vulnerability reporting from 11 September 2026. Administrative fines can reach €15 million or 2.5% of worldwide annual turnover, whichever is higher. In the United States, federal buyers of consumer IoT will require the Cyber Trust Mark from 4 January 2027.

Neither rule is satisfied by a security whitepaper. Both assume a device can be securely updated and maintained for as long as it is in the field. That is OTA, identity, signing, rollback, and an organisation that will still answer the phone in year seven.

Infuse is built around that lifetime. Secure provisioning, signed updates, fleet configuration, and long-term enterprise support are part of the same stack that gets a product to market — not a retrofit when the auditor arrives.

On this site we keep 2027 language matter-of-fact on general pages. If you are an existing IoT provider or an enterprise buyer, the urgency is real: the work has to be in the firmware and the operating model now, not in December 2027. See IoT security / CRA for the readiness check and the 22-requirement map.