Why Nabto for CRA
Secure remote access
Encrypted, authenticated connections with no open inbound ports on the device.
Vulnerability handling
A maintained platform with coordinated disclosure and security advisories.
Lifetime updates
Patched and supported across the long lifetimes embedded products ship with.
EU data sovereignty
EU-only hosting option and GDPR-aligned infrastructure, by configuration.
Why this matters now
The CRA is law, and the first deadline is months away
The EU Cyber Resilience Act sets mandatory cybersecurity requirements for any connected product sold in the EU. It is already in force and rolls out in stages.
Penalties for breaching the essential requirements reach 15 million EUR or 2.5 percent of global annual turnover, whichever is higher. The obligations run across the whole product lifecycle, and the reporting clock starts on products you have already shipped.
An honest starting point
We cover the access and communication part. We will not pretend to do the rest.
No supplier can make your whole product CRA-compliant, and anyone who says they can is handing you a problem for later. What Nabto does is take the access and communication requirements off your plate and give you something you can put in front of an assessor.
Nabto Edge covers the parts that decide how your device is reached and how it talks:
- Secure remote access without open ports or inbound firewall rules
- Authenticated identities for both devices and users
- End-to-end encryption of data in transit
- A maintained, patched connectivity layer with security advisories
What stays with you
Your software bill of materials, your own vulnerability handling process, technical documentation and conformity assessment stay your responsibility under the CRA. We help you scope them and give you a security layer you can point to, not a certificate you can hide behind.
How it works
Built-in security, not bolted on
Nabto Edge devices and clients authenticate each other and talk over an encrypted connection set up directly between them. Your data is never sitting on an open port waiting to be probed, and it is never decrypted by something in the middle.
Because the security ships inside the SDK, your team starts from a secure default instead of assembling one. That is less to build, less to get wrong and less to explain when an assessor asks.
Read about security in Nabto Edge
In the field
Where this matters
Industrial equipment
Remote service access to machines on customer networks, without opening those networks up to inbound traffic.
Smart buildings and HVAC
Secure access to controllers and gateways across distributed sites.
Smart energy
Monitoring and control for distributed energy assets, with security you can put in front of an assessor.
Why Nabto
A security partner, not just a library
Nabto has built secure connectivity for embedded products since 2009: lightweight enough for constrained devices, scalable across fleets and trusted by industrial and IoT manufacturers. You get a maintained security layer with people behind it who work on CRA questions every day and can speak to an assessor, not a black box.
See where Nabto fits your CRA plan
The sooner you map the gaps, the cheaper they are to close. Book a short call and we will walk through it with you.

