EU Cyber Resilience Act

Overview. The European Union Cyber Resilience Act, Regulation (EU) 2024/2847 (the CRA), establishes essential cybersecurity requirements for hardware and software products with digital elements placed on the European Union market. The CRA entered into force on December 10, 2024. Reporting obligations for actively exploited vulnerabilities and severe incidents apply from September 11, 2026. The remaining obligations, including secure-by-design requirements, conformity assessment, CE marking, documentation, and support-period commitments apply from December 11, 2027.

Zebra's Commitment. Zebra Technologies Corporation is committed to meeting the requirements of the CRA that apply to Zebra products with digital elements offered on the EU market. Zebra has a cross-functional CRA readiness program in place. This program is focused on portfolio classification, secure development lifecycle enhancements, vulnerability handling, technical documentation, and customer communications.

September 2026 Vulnerability and Incident Reporting. Zebra is prepared to meet the CRA Article 14 reporting requirements that apply from September 11, 2026. Zebra's Product Security Incident Response Team monitors Zebra products and third-party components for security vulnerabilities and will report actively exploited vulnerabilities and severe incidents affecting Zebra products with digital elements to ENISA and the applicable national CSIRTs within the timelines set out in Article 14 through the Single Reporting Platform. Zebra will inform affected customers without undue delay of severe incidents or actively exploited vulnerabilities and provide actionable remediation or mitigation steps.

Compliance. We are actively evolving our Secure Software Development Lifecycle to meet the comprehensive secure-by-design and lifecycle support requirements of the CRA. Zebra is working to be compliant ahead of the December 11, 2027 deadline. Customers can be assured that mobile computers, RFID systems, scanning solutions and other in-scope products shipped into the European Union after December 11, 2027, will be CRA-compliant to support continued application of the CE Mark.

Additional Details:

Existing Security Foundations. Zebra's CRA readiness builds on Zebra's existing security posture. Zebra's CRA readiness effort also leverages the security controls implemented for the EU Radio Equipment Directive cybersecurity requirements (Articles 3.3(d), (e), and (f)).

Scope. The CRA applies to hardware and software products with digital elements. Standalone Zebra Software-as-a-Service (SaaS) and cloud platforms operating independently of products with digital elements fall outside the CRA scope. Remote data processing solutions developed by Zebra that are essential for an in-scope product's functionality are covered under the product's CRA compliance framework.

Support period, security updates, and Software Bill of Materials (SBOM). For Zebra products with digital elements placed on the EU market on or after December 11, 2027, Zebra will:

  1. Define and publish a product support period reflecting the product's expected time of use (which will be at least five years, unless a product's expected lifetime is shorter), in accordance with CRA Article 13(8).

  2. Provide security updates during the support period at no cost to end users, in accordance with the CRA.

  3. Maintain and make available to Regulators a Software Bill of Materials for CRA in-scope products in a form consistent with the CRA and applicable guidance.

  4. Retain CRA technical documentation for at least ten years after a product is placed on the EU market.

Product Support, SBOMs. Product specific support periods and end-of-support communications will be published in Zebra product documentation and on the applicable Zebra product support pages. Note: The CRA does not require manufacturers to provide or publish SBOMs to their customers or the general public. Instead, the CRA mandates that SBOMs are kept internally as a part of the product's mandatory technical documentation. See Annex VII, point 2(b) and Article 31, Annex I (Part II, point 1) as well as Recital 77.

EU Declaration of Conformity and CE Marking. Zebra will update the EU Declaration of Conformity for in-scope Zebra products before the December 11, 2027 deadline. The declaration and CE marking will reflect compliance with CRA's essential requirements and be integrated with Zebra's existing EU regulatory conformity statements. Declarations of Conformity are available on Zebra's Compliance page.

Contact. For CRA-related questions from customers, prospective customers, distributors, integrators, and business partners, please contact your Zebra sales representative. For security vulnerabilities and coordinated vulnerability disclosure, please see below. 

Updates and Advisories. This page will be updated as CRA implementing acts, delegated acts, and harmonized standards are published, and as Zebra's readiness progresses. Zebra also publishes information on its Security Alerts page. Customers with active Zebra service agreements can also subscribe to Zebra security notifications through support.zebra.com.

Reporting a Zebra Product Security Vulnerability

Report a Potential Security Issue. If you believe you have identified a security vulnerability, incident, exploit, breach, ransomware event, suspicious activity, or other cybersecurity concern affecting a Zebra product with digital elements, please report it to Zebra as soon as possible. Submit a report via the Zebra VDP Reporting Portal (accessible directly or through Zebra's Security & Vulnerability Alerts / LifeGuard Security page.

  • Additional Reporting Channel: InfoSecurity@zebra.com.
  • Anonymous Reporting / Safe Harbor. Zebra treats good-faith security research as a benefit to Zebra customers and the wider community. Zebra will not pursue legal action against researchers who report bugs via our Vulnerability Disclosure Program managed by HackerOne.