New EU cybersecurity regulations will soon be mandatory for all connected devices.

RED EN 18031 → mandatory 1 August 2025

CRA — Cyber Resilience Act → full enforcement 2027

Risk: Loss of CE mark, EU sales blockage, costly redesigns, recalls, legal liability


New EU regulations are changing how connected products are designed, built, and maintained. The Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for all products with digital elements placed on the EU market, impacting manufacturers, integrators, importers, and distributors. ​The RED Directive dictates new rules for all radio-connected devices, requiring compliance at the level of the final product, not just individual components.

​Compliance is no longer optional. It directly impacts the ability to sell, scale, and compete in the European market.

If a product is not compliant:

  • No CE marking
  • No access to the European market
  • Risk of fines, product withdrawal, and liability
  • Exclusion from tenders and partnerships

Check if your device is CRA-ready


  • Designed for OEMs building connecting devices across industries, including industrial equipment, medical and laboratory devices, vending and payment systems, smart building and HVAC systems, and HMI and edge computing solutions.
  • Aligned with CRA, RED (EN 18031), IEC 62443 requirements.
  • Built to reduce the effort and cost of compliance, allowing teams to focus on the unique value of their products rather than managing complex security requirements.
  • Delivered with a transparent pricing model based on device volume.

SECO helps OEMs achieve compliance fast, with a single, integrated cybersecurity package that protects devices for the next 5 years.

Enabled by Clea OS

Industrial OS-Level Security Foundation

The Cyber Security Package operates on Clea OS, SECO’s industrial Yocto-based operating system for embedded and edge platforms. Clea OS delivers a hardened, production-ready architecture with support for secure boot chains, controlled OTA update mechanisms, system integrity enforcement, and long-term maintainability.

It runs across x86 and ARM architectures and integrates with any cloud environment, ensuring full hardware and infrastructure flexibility.


SECO Cyber Security Package

Security by Design

Secure build pipeline

Secure update with rollback protection

Encrypted and Signed A/B OS updates

Automated certificate rotation (mTLS, X.509)

Secure Boot

Encrypted/immutable partitions

SBOM & Documentation

SPDX and CycloneDX Automated SBOM management

Security-relevant changelog maintained for 5 years

Documentation aligned to CRA, RED EN18031-1 and IEC 62443 principles

Vulnerability Monitoring

CVE monitoring on SECO baseline

CVE patching on SECO baseline

Risk assessment and prioritization

Codeless scanning

Monitoring on customized parts (Available starting from Large Plan)

Patching on customized parts (Available starting from Large Plan)

Runtime Security

Real-time threat detection and notification

Real-time detection of firmware anomalies

Syscall-level intrusion monitoring

In-memory threat prevention

Security logs designed for audit purposes

Optional Add-ons: CVE patching on custom software for Small and Medium - OTA updates via Clea Device Management - Extended SBOM, full documentation pack for certification, certification support

Cyber Security features are activated on devices running Clea OS. Compatible with x86, ARM and any cloud infrastructure.


On SECO hardware, Clea OS is fully integrated, providing a secure, production-ready foundation from day one. The cybersecurity package can be activated natively, with aligned security architecture and faster time-to-secure deployment.

If existing hardware is already in place, it’s not necessarily required to start from scratch. SECO can extend the cybersecurity package to third-party platforms, provided the device can be managed through Clea OS. Our team assesses feasibility and defines a clear qualification path, including support for OS porting when required.

Check if your device is CRA-ready


Get a compliance assessment and discover which package best fits your requirements.

All fields marked with an asterisk (*) are mandatory

Please check our privacy policy below.


Ideal for manufacturers in:

  • Industrial equipment & machinery
  • Medical and laboratory devices
  • Smart vending & payment systems
  • Professional appliances
  • HMI and edge computing solutions
  • Smart building & HVAC systems 


  • A structured approach to cybersecurity and compliance, combining a secure hardware baseline, the cybersecurity package for ongoing coverage, and additional add-ons for advanced requirements and certification support.
  • Faster time-to-market through reduced complexity and accelerated compliance.
  • Regulatory support for CRA-related certifications.
  • Industrial-grade security designed for long lifecycle products.
  • Pre-certified solutions aligned with standards such as ISO 27001, IEC 62443, EN 18031.

With Clea, transform security into recurring revenue: predictive maintenance, pay-per-use billing and real-time analytics. The platform handles billing and data pipelines with no extra development.

Ready to secure your IoT fleet?

Contact us