Overview
Avnet's CRA and IoT Device Certification Readiness Services close the gap between a compliant platform and a compliant product.
Manufacturers already running a secure IoT platform hit the same fact in their first Cyber Resilience Act review: the platform's compliance posture is not the product's. A platform provisions X.509 certificates, terminates TLS and delivers signed OTA payloads. It cannot generate a certificate signing request inside your MCU's secure element, verify a boot chain, implement rollback on a failed firmware install, track CVEs in the libraries compiled into your firmware, or CE-mark your enclosure. Those obligations belong to the manufacturer, and the CRA enforces them there. That boundary is where this engagement works.
The clock is running. The CRA entered into force 10 December 2024; vulnerability reporting obligations applied 11 September 2026; full obligations apply 11 December 2027, with penalties to EUR 15 million or 2.5% of global turnover. The UK PSTI Act is enforceable now at GBP 10 million or 4% of revenue. Products that cannot show secure-by-default configuration, a disclosure process, an SBOM and a defined update period lose market access.
ENGAGEMENT PACKAGES
1. Product Classification and Gap Assessment (2-4 weeks). We classify each SKU against the CRA's categories - Default, Important under Annex III, or Critical under Annex IV - then assess it against Annex I essential requirements and your platform's shared-responsibility boundary, separating what infrastructure covers from open engineering work. Deliverables: per-SKU classification and conformity route, a gap register spanning CRA, UK PSTI, ETSI EN 303 645 and IEC 62443, and a costed roadmap.
2. Firmware and Hardware Security Engineering (6-16 weeks, scoped from the assessment). The device-side work no platform performs for you: secure boot bring-up and flash protection; TPM, secure element and HSM integration for hardware-rooted keys; in-device CSR generation so private keys never leave the part; TLS client review of cipher suites, chain and hostname validation; OTA hardening with download validation, anti-rollback counters and field recovery; on-device encryption and credential rotation. Where the current device design cannot support these controls, we document the gap and provide engineering recommendations your hardware team can act on.
3. SBOM and Vulnerability Operations (4-8 weeks to stand up, optional ongoing). Automated firmware SBOM generation in CycloneDX or SPDX inside your CI/CD pipeline, continuous CVE correlation with triage and remediation SLAs, coordinated disclosure meeting CRA Article 13 and ETSI Provision 2, and workflows aligned to the CRA's 24-hour ENISA early warning.
4. Conformity Documentation and Multi-Market Support (4-8 weeks). Assembly of the CRA technical file - risk assessment, essential-requirements evidence, SBOM, secure development records, support-period declaration and vulnerability handling - plus notified-body preparation. Because CRA, UK PSTI, the US Cyber Trust Mark, Japan JC-STAR and Singapore CLS all rest on ETSI EN 303 645, we map evidence once so one package serves five markets.
5. Managed Compliance (optional, 12-month minimum). Avnet operates firmware CVE monitoring, patch cadence, disclosure coordination and conformity review across your declared support period.
Scope boundary. Avnet is not a notified body and does not issue certifications. Important and Critical products require third-party assessment; we prepare you for it rather than replace it. Confirm classification with your counsel.
Built on AWS, using AWS IoT Core, IoT Device Defender, IoT Greengrass, Private CA and KMS for identity and key lifecycle, Amazon Inspector for dependency scanning, and Security Hub and Audit Manager for posture and evidence. Customers on /IOTCONNECT, available on AWS Marketplace and certified to ISO 27001 and SOC 2 Type II, inherit the platform-layer controls and shorten the engagement.
Why Avnet. Compliance failures in connected products are rarely cloud failures. They are a missing secure element, a bootloader that accepts unsigned images, or an OpenSSL version nobody tracked - fixes needing firmware engineers and hardware access, not a cloud architect. Avnet brings 2,000+ engineers with deep firmware and embedded-security expertise, so remediation reaches the device, not just the documentation.
Highlights
- **Close the Gap Your Platform Leaves Open:** Certificates, TLS termination, and OTA delivery are platform functions. Secure boot, TPM and secure-element key storage, TLS client hardening, anti-rollback logic, on-device encryption, and firmware CVE tracking are yours — and the CRA enforces them against the manufacturer. Our engineers deliver that device-side layer, then produce the evidence that proves it.
- **Device-Level Remediation, Not Just a Report:** Our firmware and embedded-security engineers work hands-on with your devices. When your current design cannot support hardware-rooted keys or a verified boot chain, we assess the gap, recommend design options, and support your engineering team through the change. Remediation reaches the device, not just the documentation.
- **One Evidence Package, Five Markets:** CRA, UK PSTI, US Cyber Trust Mark, Japan JC-STAR, and Singapore CLS all rest on the ETSI EN 303 645 baseline. We map your product once, assemble a single conformity documentation file, and reuse it across every market you sell into — with SBOM generation and coordinated vulnerability disclosure operating continuously behind it.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Resources
Vendor resources
Support
Vendor support
Talk to our Experts: https://www.avnet.com/wps/portal/us/solutions/iot/contact-us/ Call Us 866-345-7638 info@softwebsolutions.com