Pioneering Secure-by-Design in the Age of the European CRA

The global regulatory landscape for cybersecurity is undergoing a fundamental transformation. We are shifting away from a patchwork of voluntary standards toward a mandatory framework for “Products with Digital Elements” (PDE). For many in the technology sector, the European Union’s Cyber Resilience Act (CRA) is viewed as a daunting compliance hurdle. At lowRISC®, we see it differently: the CRA is a validation of our core mission to provide transparent, commercial-quality and secure open-silicon designs.

Rather than creating administrative friction, the European Commission’s guidance confirms that open stewardship serves as a structural advantage for the entire hardware ecosystem. lowRISC prepared for some time for the start of the CRA’s mandatory reporting of exploited vulnerabilities (which came into force on September 11, 2026), and we invite the industry to view compliance not as a tax, but as a collective commitment to a safer digital future.

The New Paradigm of Hardware Trust & Combined Silicon Compliance

The CRA mandates that embedded systems and connected hardware can, generally, no longer be shipped with known exploitable vulnerabilities; they must incorporate secure update mechanisms and “Secure-by-Design” principles. This framework effectively implies solutions like hardware roots of trust and secure enclaves – the exact technologies lowRISC has championed through projects like OpenTitan® (with its Ibex® core) and our CHERI-based Sunburst and COSMIC projects.

Crucially, the Commission’s guidance clarifies two key implementation principles for hardware providers:

  • Combined Hardware-Software Units: Silicon IP, boot ROM, microcode, and foundational firmware supplied to operate hardware are evaluated together as a single unified Product with Digital Elements (PDE). Compliance is established across the combined hardware/software boundary rather than in isolation.
  • Protection for Pre-Existing Silicon Designs: Silicon architectures designed prior to the CRA’s full enforcement date of December 11, 2027, do not require automatic redesigns to be placed on the market. Provided a documented cybersecurity risk assessment (created by the product’s manufacturer) confirms that existing security measures achieve an appropriate level of protection against practical threat vectors, existing chip designs can continue to be produced and distributed without unnecessary hardware re-spins.

Navigating the Open Source “Steward” Role & The Upstream Advantage

A vital distinction within the CRA is the evaluation of commercial activity. As a Community Interest Company (C.I.C.) whose profits are reinvested into our mission, lowRISC is classified under Article 24 as an Open Source Software Steward rather than a commercial manufacturer.

This classification establishes a lighter-touch regulatory model – exempting lowRISC repositories from CE markings, mandatory self-declarations, or third-party conformity assessments – while establishing clear expectations around governance, vulnerability handling, and interoperability.

More importantly, the guidance establishes a major upstream feedback loop that directly benefits lowRISC projects:

  • Commercial Integrators as Manufacturers: Commercial vendors who integrate lowRISC designs into monetised products are classified as “Manufacturers” and bear the primary compliance burden.
  • Mandatory Upstream Fix-Sharing: Under Article 13(6), downstream manufacturers are legally required to report vulnerabilities found in integrated components back to the maintainer (lowRISC) and share developed security fixes. This turns commercial adoption into a continuous, legally enforced security feedback engine that actively hardens our open-source silicon repositories at scale.

Operationalising Incident Reporting

Transitioning into the CRA era requires moving beyond ad-hoc security fixes to a formalised, cybersecurity policy. Central to lowRISC’s approach is our pre-existing Coordinated Vulnerability Disclosure (CVD) policy, which gives researchers and commercial partners clear channels to report potential or actual flaws and has been updated to take into account the requirements of the CRA.

 

The Commission’s guidance provides vital operational clarity on mandatory reporting obligations to the European Union Agency for Cybersecurity (ENISA) and national Computer Security Incident Response Teams (CSIRTs) via the Single Reporting Platform (SRP):

  • Defining “Becoming Aware”: The strict 24-hour early warning window and subsequent 72-hour detailed notification do not begin at the first unverified bug report. The clock starts only after an initial assessment yields a reasonable degree of certainty that an actively exploited vulnerability or severe incident exists.
  • Targeted Steward Scope: As a steward providing engineering support, lowRISC’s reporting duties focus on actively exploited code vulnerabilities within our published designs, rather than general internal IT infrastructure (unless an infrastructure breach directly compromises the security of the distributed silicon IP).

De-Risking Downstream Integration: Core Functionality & Spare Parts

Commercial chipmakers integrating open-source silicon IP often worry about regulatory scope creep. The Commission’s guidance introduces two safeguards that de-risk the use of lowRISC IP:

  • The Core Functionality Rule: Integrating a high-security Root of Trust (such as OpenTitan) into a complex System-on-Chip (SoC) does not automatically escalate the final chip into a “Class II” or “Critical” product category. A product’s regulatory classification is determined strictly by its overall core functionality, not by the high-security capabilities of its integrated sub-components.
  • Spare Parts & Maintenance Exemption: Identical replacement components specifically supplied to repair or maintain existing systems are exempt from full CRA reassessment. This ensures long-term maintenance lifecycles for hardware built on lowRISC maintained repositories.

Turn-Key Due Diligence: GitHub Security Advisories

To streamline compliance for downstream adopters, lowRISC is expanding its security infrastructure by leveraging GitHub Security Advisories. In addition to the existing CVD process you can now also report vulnerabilities by visiting https://github.com/lowRISC/OpenTitan/security and clicking on “Report a vulnerability”.

To meet the CRA’s full enforcement milestone by December 11, 2027, lowRISC is actively building the infrastructure to generate machine-readable Bills of Materials (SBOMs/HBOMs). Once deployed in 2027, these supply chain artifacts will provide commercial integrators with pre-packaged compliance evidence, drastically reducing their regulatory burden.

Conclusion: Open Stewardship as a Competitive Advantage

The Cyber Resilience Act mandates the exact secure-by-design architectures, transparent supply chains, and root-of-trust foundations that lowRISC was created to deliver. Far from restricting open-source hardware, the official guidance confirms that open stewardship creates a mutually beneficial ecosystem: commercial adopters receive high-assurance, audit-ready silicon IP, while lowRISC receives structured security feedback from commercial deployments.

As we move toward full enforcement in 2027, lowRISC remains committed to providing the global semiconductor industry with open, secure, and fully compliant silicon foundations.

For more information contact us: info@lowrisc.org

Key CRA Implementation Milestones

Milestone Date Significance
CRA Entry into Force 2024-12-10         Official legal framework established across the EU.
Mandatory Reporting 2026-09-11 Active exploitation & severe incident reporting obligations begin.
Full Enforcement 2027-12-11 Mandatory CE marks, full risk assessments, and SBOM/HBOM requirements.
Cert Certificate Transition   2028-06-11 End of transitional validity for pre-existing EU type-examination certificates.
×
Semiconductor IP