Raspberry Pi and the EU Cyber Resilience Act

What is the Cyber Resilience Act (CRA)?

The EU Cyber Resilience Act (CRA) is an EU Regulation covering products with digital elements, both hardware and software, placed on the EU market. It establishes mandatory cybersecurity requirements for manufacturers, importers, and distributors throughout the product lifecycle.

Raspberry Pi’s long-standing commitment to security means that our hardware and software are already trusted solutions for embedded devices and custom software deployments.

Read our CRA whitepaper

How Raspberry Pi helps you comply

Secure updates

Raspberry Pi Connect’s remote update service, image tooling, and A/B support help ensure that updates are cryptographically secure and that any failed update does not leave the device unrecoverable.

Resilient from the start

Raspberry Pi’s secure boot provisioning software offers secure boot protection, encrypted storage, and manufacturing records for your custom Linux-based operating system.

Software Bill of Materials

Raspberry Pi generates a software bill of materials for every release of Raspberry Pi OS, and our image tooling produces one in SPDX or CycloneDX format for your own custom builds.

Comprehensive documentation

All of Raspberry Pi’s robust security features are documented in full, alongside official security vulnerability disclosures, product security policies, and guidance on user responsibilities for maintaining the security of Raspberry Pi devices.

Read security documentation

We’ve been doing this a long time

Though there are not yet any harmonised standards specifically for the CRA, Raspberry Pi already follows best practice for a range of certification standards.

EN 303 645 V2.1.1

Raspberry Pi’s fourth- and fifth-generation compute platforms were among the first to be fully compliant with the European consumer IoT cybersecurity standard (ETSI EN 303 645), ensuring enhanced security and privacy for users.

EN 18031

Raspberry Pi provides a secure platform upon which our customers are able to build compliant devices, and can demonstrate proof-of-concept compliance with the new essential requirements for secure network connection, protection of personal data and privacy, and features to protect against fraud.

Common Criteria ISO/IEC 15408

Raspberry Pi is able to guide and inform customers who use its products as components in systems that have a target Evaluation Assurance Level (EAL), and provide documentation to prove their resilience to cybersecurity vulnerabilities.