Robanchor

The Cyber Resilience Act deadline is 11 December 2027: spare parts are in scope

2025-09-20

Spare parts carry firmware, and firmware carries risk

A replacement sensor board for a collaborative robot arm looks like a commodity: a PCB, a connector, a housing. But if that board contains a microcontroller with embedded software, it is a ‘product with digital elements’ under Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA). The regulation applies from 11 December 2027, and it does not exempt spare parts that are placed on the market separately. For a service network assembling after-sales support for Chinese robotics manufacturers entering Europe, this changes how spare parts must be documented, updated, and traced.

The CRA defines a ‘product with digital elements’ as any software or hardware product and its remote data processing solutions, including software or hardware components that are placed on the market separately. A motor controller that ships with firmware is such a product. A sensor board that runs calibration routines is such a product. Even a simple I/O module with a bootloader qualifies. The only parts that fall outside are those that contain no programmable logic and no software that can be updated or exploited.

Why a replacement board is not just a component

In the after-sales context, a spare part is often treated as a repair item, not a new product. But the CRA looks at the moment of placing on the market, not at the end use. When a distributor or a service network stocks a replacement motor controller and sells it to a maintenance provider, that controller is placed on the market as a standalone product. It must meet the same essential cybersecurity requirements as the original equipment.

That means the spare part must be designed, developed, and produced so that it is free from known exploitable vulnerabilities, comes with a secure default configuration, and is supported with security updates for the expected product lifetime. The manufacturer must also provide a Software Bill of Materials (SBOM) and report actively exploited vulnerabilities to the EU Agency for Cybersecurity (ENISA). These obligations are not optional for spare parts.

Hardware-only vs. firmware-bearing parts

The distinction is practical. A metal bracket, a cable, a passive filter, or a mechanical seal has no digital elements. It cannot be updated, cannot be exploited, and does not need a security update policy. But a replacement sensor board with a microcontroller, a motor controller with a CAN stack, or a vision module with embedded image processing is a different category. The table below summarises the key differences.

Aspect Hardware-only part Firmware-bearing part
Definition under CRA Not a product with digital elements Product with digital elements
Examples Bracket, cable, heatsink, screw Sensor board, motor controller, I/O module
Cybersecurity requirements None Secure design, vulnerability handling, update support
Documentation Basic datasheet SBOM, conformity assessment, EU declaration of conformity
Update obligation Not applicable Security updates for expected lifetime
Market surveillance risk Low High if non-compliant

What this means for service networks and manufacturers

For a service network being set up to support Chinese robotics manufacturers, the practical consequence is that spare parts logistics must be treated as product compliance logistics. Every firmware-bearing part must be traceable to a CE marking that includes the CRA requirements. The manufacturer must have a single point of contact for security issues, and the service network must be able to identify which software version is installed on each part.

This is not just a paperwork burden. The CRA requires that vulnerabilities are handled according to the regulation’s Annex I, which includes obligations to inform users and ENISA. A service network that replaces a motor controller must know whether the new part has the latest firmware and whether any known vulnerabilities are patched. If the network installs an outdated part, it could be held liable for introducing a vulnerability into the robot system.

Practical steps for spare parts compliance

  1. Classify every spare part: determine whether it contains any programmable logic or firmware.
  2. For firmware-bearing parts, obtain the EU declaration of conformity and the SBOM from the manufacturer.
  3. Ensure that the part’s security update period is clearly stated and that the service network has access to update files.
  4. Keep records of which software version is installed in each part, and when it was updated.
  5. Verify that the manufacturer has a process for reporting vulnerabilities to ENISA and for notifying users.

Deadlines and transition periods

The CRA entered into force on 10 December 2024. Most obligations apply from 11 December 2027, which is the date by which products placed on the market must comply. There is a shorter transition for the reporting obligations, which apply from 11 September 2026. For spare parts, the key date is the same: from 11 December 2027, any firmware-bearing spare part placed on the market must be CRA-compliant.

It is worth noting that the regulation does not have a separate category for spare parts. They are treated like any other product with digital elements. This means that a manufacturer cannot argue that a spare part is ‘only for repair’ and therefore exempt. The European Commission’s guidance on the CRA, available on its digital strategy page, confirms that the regulation applies to products placed on the market, regardless of their intended use.

What varies by country and what to verify

While the CRA is a regulation and directly applicable in all EU member states, market surveillance and enforcement are carried out by national authorities. This means that the level of scrutiny may vary from one country to another. Some authorities may focus on high-risk products, while others may conduct random checks. Service networks should verify with the national market surveillance authority in each country where they operate to understand local enforcement priorities.

Additionally, the CRA is aligned with the harmonised standards that are still being developed. Until those standards are published, manufacturers can use other technical specifications to demonstrate compliance. Service networks should ask for the technical documentation that supports the CE marking, including the risk assessment and the security requirements that were applied.

Conclusion: spare parts are a compliance frontier

The Cyber Resilience Act is not just about new robots or smart devices. It reaches into the after-sales ecosystem, where spare parts with firmware are placed on the market every day. For a local service network being set up to support Chinese robotics manufacturers, the message is clear: treat every firmware-bearing spare part as a product that must meet the same cybersecurity standards as the original equipment. That means asking for the right documentation, keeping track of software versions, and being ready to support security updates. The deadline is 11 December 2027, and it will arrive faster than many expect.

Sources

  • EUR-Lex — Regulation (EU) 2024/2847 (CRA) — https://eur-lex.europa.eu/eli/reg/2024/2847/oj (accessed 2025-09-20)
  • European Commission — Cyber Resilience Act — https://digital-strategy.ec.europa.eu/ (accessed 2025-09-20)