The New Cybersecurity Reality for Embedded Systems
For years, cybersecurity was treated as something that could be strengthened over time, issues patched after release, vulnerabilities handled as they emerged, compliance addressed later. That approach no longer holds. As products become more software-defined and dependent on multiple vendors and third-party components, the attack surface grows, and attacks increasingly target operational technology in vehicles, hospitals and factories, not just servers.
The result is rising demand for built-in security, Software Bills of Materials (SBOMs), CVE transparency, and growing scrutiny of the software supply chain. Security has converged into a primary concern for connected systems, and increasingly it is being written into law.
At the same time, regulators are raising expectations around secure development practices, SBOM transparency, vulnerability management, and long-term security support. Requirements introduced through regulations such as the EU Cyber Resilience Act are making cybersecurity not only a technical consideration, but also a product, compliance, and business requirement.
A Framework Mapped to Regulatory Requirements
Certifications, Compliance, and Conformance
Resources
Engineering and compliance should focus on one overarching question: If we had to demonstrate CRA compliance today, what evidence could we provide, and what capabilities or documentation are still missing? This mindset helps identify gaps before they become compliance risks.
The top 3 practical questions could be:
- Does the CRA apply to our products, and what are our obligations?
- Where are the biggest gaps between our current practices and the CRA requirements?
- Can we demonstrate compliance with evidence, or do we need to build new capabilities (e.g., SBOMs, vulnerability management, security updates, documentation)?
Start by contacting QNX Security Services or exploring our CRA-focused product resources, presentations, webinars, and blogs. We can help customers understand which CRA requirements QNX can support and which remain the product manufacturer’s responsibility.
QNX can reduce the compliance workload by providing security capabilities and supporting evidence, including SBOMs, vulnerability notifications, security documentation and lifecycle updates. For long-lifecycle products, extended and post-end-of-life support can also help maintain security through continued vulnerability monitoring and security support beyond the standard support period.