Pioneering Secure-by-Design in the Age of the European CRA
The global regulatory landscape for cybersecurity is undergoing a fundamental transformation. We are shifting away from a patchwork of voluntary standards toward a mandatory framework for “Products with Digital Elements” (PDE). For many in the technology sector, the European Union’s Cyber Resilience Act (CRA) is viewed as a daunting compliance hurdle. At lowRISC®, we see it differently: the CRA is a validation of our core mission to provide transparent, commercial-quality and secure open-silicon designs.
Rather than creating administrative friction, the European Commission’s guidance confirms that open stewardship serves as a structural advantage for the entire hardware ecosystem. lowRISC prepared for some time for the start of the CRA’s mandatory reporting of exploited vulnerabilities (which came into force on September 11, 2026), and we invite the industry to view compliance not as a tax, but as a collective commitment to a safer digital future.
The New Paradigm of Hardware Trust & Combined Silicon Compliance
The CRA mandates that embedded systems and connected hardware can, generally, no longer be shipped with known exploitable vulnerabilities; they must incorporate secure update mechanisms and “Secure-by-Design” principles. This framework effectively implies solutions like hardware roots of trust and secure enclaves – the exact technologies lowRISC has championed through projects like OpenTitan® (with its Ibex® core) and our CHERI-based Sunburst and COSMIC projects.
Crucially, the Commission’s guidance clarifies two key implementation principles for hardware providers:
- Combined Hardware-Software Units: Silicon IP, boot ROM, microcode, and foundational firmware supplied to operate hardware are evaluated together as a single unified Product with Digital Elements (PDE). Compliance is established across the combined hardware/software boundary rather than in isolation.
- Protection for Pre-Existing Silicon Designs: Silicon architectures designed prior to the CRA’s full enforcement date of December 11, 2027, do not require automatic redesigns to be placed on the market. Provided a documented cybersecurity risk assessment (created by the product’s manufacturer) confirms that existing security measures achieve an appropriate level of protection against practical threat vectors, existing chip designs can continue to be produced and distributed without unnecessary hardware re-spins.
Navigating the Open Source “Steward” Role & The Upstream Advantage
A vital distinction within the CRA is the evaluation of commercial activity. As a Community Interest Company (C.I.C.) whose profits are reinvested into our mission, lowRISC is classified under Article 24 as an Open Source Software Steward rather than a commercial manufacturer.
This classification establishes a lighter-touch regulatory model – exempting lowRISC repositories from CE markings, mandatory self-declarations, or third-party conformity assessments – while establishing clear expectations around governance, vulnerability handling, and interoperability.
More importantly, the guidance establishes a major upstream feedback loop that directly benefits lowRISC projects:
- Commercial Integrators as Manufacturers: Commercial vendors who integrate lowRISC designs into monetised products are classified as “Manufacturers” and bear the primary compliance burden.
- Mandatory Upstream Fix-Sharing: Under Article 13(6), downstream manufacturers are legally required to report vulnerabilities found in integrated components back to the maintainer (lowRISC) and share developed security fixes. This turns commercial adoption into a continuous, legally enforced security feedback engine that actively hardens our open-source silicon repositories at scale.
Operationalising Incident Reporting
Transitioning into the CRA era requires moving beyond ad-hoc security fixes to a formalised, cybersecurity policy. Central to lowRISC’s approach is our pre-existing Coordinated Vulnerability Disclosure (CVD) policy, which gives researchers and commercial partners clear channels to report potential or actual flaws and has been updated to take into account the requirements of the CRA.

The Commission’s guidance provides vital operational clarity on mandatory reporting obligations to the European Union Agency for Cybersecurity (ENISA) and national Computer Security Incident Response Teams (CSIRTs) via the Single Reporting Platform (SRP):
- Defining “Becoming Aware”: The strict 24-hour early warning window and subsequent 72-hour detailed notification do not begin at the first unverified bug report. The clock starts only after an initial assessment yields a reasonable degree of certainty that an actively exploited vulnerability or severe incident exists.
- Targeted Steward Scope: As a steward providing engineering support, lowRISC’s reporting duties focus on actively exploited code vulnerabilities within our published designs, rather than general internal IT infrastructure (unless an infrastructure breach directly compromises the security of the distributed silicon IP).
De-Risking Downstream Integration: Core Functionality & Spare Parts
Commercial chipmakers integrating open-source silicon IP often worry about regulatory scope creep. The Commission’s guidance introduces two safeguards that de-risk the use of lowRISC IP:
- The Core Functionality Rule: Integrating a high-security Root of Trust (such as OpenTitan) into a complex System-on-Chip (SoC) does not automatically escalate the final chip into a “Class II” or “Critical” product category. A product’s regulatory classification is determined strictly by its overall core functionality, not by the high-security capabilities of its integrated sub-components.
- Spare Parts & Maintenance Exemption: Identical replacement components specifically supplied to repair or maintain existing systems are exempt from full CRA reassessment. This ensures long-term maintenance lifecycles for hardware built on lowRISC maintained repositories.
Turn-Key Due Diligence: GitHub Security Advisories
To streamline compliance for downstream adopters, lowRISC is expanding its security infrastructure by leveraging GitHub Security Advisories. In addition to the existing CVD process you can now also report vulnerabilities by visiting https://github.com/lowRISC/OpenTitan/security and clicking on “Report a vulnerability”.
To meet the CRA’s full enforcement milestone by December 11, 2027, lowRISC is actively building the infrastructure to generate machine-readable Bills of Materials (SBOMs/HBOMs). Once deployed in 2027, these supply chain artifacts will provide commercial integrators with pre-packaged compliance evidence, drastically reducing their regulatory burden.
Conclusion: Open Stewardship as a Competitive Advantage
The Cyber Resilience Act mandates the exact secure-by-design architectures, transparent supply chains, and root-of-trust foundations that lowRISC was created to deliver. Far from restricting open-source hardware, the official guidance confirms that open stewardship creates a mutually beneficial ecosystem: commercial adopters receive high-assurance, audit-ready silicon IP, while lowRISC receives structured security feedback from commercial deployments.
As we move toward full enforcement in 2027, lowRISC remains committed to providing the global semiconductor industry with open, secure, and fully compliant silicon foundations.
For more information contact us: info@lowrisc.org
Key CRA Implementation Milestones
| Milestone | Date | Significance |
| CRA Entry into Force | 2024-12-10 | Official legal framework established across the EU. |
| Mandatory Reporting | 2026-09-11 | Active exploitation & severe incident reporting obligations begin. |
| Full Enforcement | 2027-12-11 | Mandatory CE marks, full risk assessments, and SBOM/HBOM requirements. |
| Cert Certificate Transition | 2028-06-11 | End of transitional validity for pre-existing EU type-examination certificates. |
Related Semiconductor IP
- Root of Trust
- Embedded Hardware Security Module (Root of Trust) - Automotive Grade ISO 26262 ASIL-B
- tRoot Fx Hardware Secure Modules: Programmable Root of Trust
- Root of Trust solutions
- CryptoManager Root of Trust for Use with the Caliptra Specification
Related Blogs
- Tape-out Risk in the Age of Edge AI: The Case for GPU IP
- Cadence at the TSMC OIP: Pioneering the Future of Semiconductor Design
- Pasteur’s Magic Quadrant in AI: The Fusion of Fundamental Research and Practical
- A Golden Source As The Single Source Of Truth In HSI
Latest Blogs
- Pioneering Secure-by-Design in the Age of the European CRA
- Overcoming power management IP challenges
- Running OpenCode with llama.cpp and Qwen 3.5 on E-Series
- Automated, Faster Specification to Sign-Off with IDS-AI
- NovaTech Automation Crius PIU: Bringing Conventional Instrument Transformers onto the IEC 61850 Process Bus