Back to Blog
LegalTech & IA

Your Cloud-Powered Toaster Just Got a Security Upgrade: The CRA’s New Rules

NakedPact Editorial Committee
Reviewer: Carmelo G.
Comitato Editoriale NakedPact
July 19, 2026
10 min read
Your Cloud-Powered Toaster Just Got a Security Upgrade: The CRA’s New Rules

What’s the CRA’s New Cloud Requirement?

The Cyber Resilience Act (CRA) now requires that if a digital product relies on cloud services to function, those cloud services must be included in the product’s security perimeter. This means manufacturers must secure APIs, databases, and cloud infrastructure just as they would the device itself.

Why This Matters for Your Smart Gadgets

Think of your smart thermostat. It’s useless without the cloud service that lets you adjust temperature from your phone. Under the CRA, that cloud service is now part of the product’s security obligations. If the cloud gets hacked, the manufacturer is liable.

This is a big shift. Previously, cloud security was often treated as a separate concern. Now, it’s baked into the product’s compliance.

What Manufacturers Need to Do

Manufacturers must conduct a thorough risk assessment that includes cloud dependencies. They need to ensure data in transit and at rest is encrypted, APIs are secure, and cloud providers meet the same standards as the product itself.

This might mean renegotiating contracts with cloud providers or adding security layers. It’s like making sure your house’s foundation is as strong as the roof – both are essential.

What This Means for Consumers

For consumers, this is good news. It means products you buy are less likely to be compromised through their cloud backends. But it also means manufacturers might pass on some costs. Expect slightly higher prices for smart devices, but with better security guarantees.

And yes, reading the updated terms of service might be as fun as watching paint dry, but at least now there’s real accountability.

FAQ

Does the CRA apply to all cloud services?

No, only to cloud services that are essential for the product’s core functionality. Ancillary services like analytics may not be included.

What happens if a manufacturer ignores this rule?

They face fines and potential bans from the EU market. The CRA has teeth – non-compliance can lead to penalties up to €15 million or 2.5% of global turnover.

How does this affect cloud providers like AWS or Azure?

They are not directly regulated, but manufacturers will demand stronger security guarantees. This may lead to new industry standards for cloud security in IoT.

Manufacturer’s Cloud Security Checklist

  • Identify all cloud services essential for product function
  • Conduct risk assessment including cloud dependencies
  • Ensure encryption for data in transit and at rest
  • Secure APIs with authentication and rate limiting
  • Verify cloud provider’s security certifications
  • Include cloud in incident response plan
NakedPact Logo

NakedPact Editorial Committee

Article created by the NakedPact editorial team. Our mission is to analyze, simplify, and expose unfair terms and hidden risks in everyday contracts to protect citizens and consumers.

Do you own a website?

Do you own a website?

Want to communicate your data processing transparency to your users? Dynamically use our badge and showcase your platform's compliance.

🛡️ Protect your rights with one click

Don't risk signing abusive clauses. Install the free NakedPact extension for Chrome or Firefox and instantly analyze any contract on the web.

Don't trust, verify.

Now that you know the risks, don't sign blindly. Upload your contract to NakedPact and let AI find the hidden clauses for you. It's 100% free.

Analyze Your Contract Now

Rispettiamo la tua privacy

Usiamo i cookie per migliorare la tua esperienza e personalizzare gli annunci. Scopri di più.

NakedPact Logo

Estensione Chrome

Analizza i contratti e i Termini di Servizio direttamente sul tuo browser con l'estensione NakedPact.