EU tightens IoT cybersecurity requirements

The EU's new Cyber Resilience Act (CRA) increases the cybersecurity requirements for connected products. Wittra Networks AB's hybrid IoT network with intelligent gateways is well positioned to meet these demands while offering significant commercial and technical advantages. By combining multiple wireless technologies in a unified infrastructure and applying the principle of "Security by Design," it results in Wittra's solution: Reduced fragmentation in industrial IoT implementations.

Built-in security with support for secure remote updates (FOTA), reduced financial risk and lower maintenance costs, as well as decreased complexity and enhanced cybersecurity.

Wittra’s hybrid IoT solution

  • Unified Network Architecture: Wittra’s gateways seamlessly link multiple wireless standards—including LoRa, Mioty, sub-GHz mesh, and UWB—within a single infrastructure. This reduces fragmentation, eliminates isolated “silo” systems, and enables integration of both new and existing sensors, preventing vendor lock-in and making it easy to scale or adapt to new technologies.
  • Security by Design: The platform is built with security from the outset, separating operational IoT systems from broader IT networks to minimize risks. Security features include strict enforcement of access controls, built-in encryption, authentication, and segmentation, supporting “zero trust” principles. This holistic approach helps organizations meet CRA’s demand for lifecycle vulnerability management.
  • Secure Remote Updates (FOTA): With secure firmware-over-the-air (FOTA) updates, customers can remotely deploy new features and address vulnerabilities promptly—all updates are encrypted and verified, ensuring only trusted firmware is loaded onto devices. This enables ongoing compliance with CRA and rapid response to emerging threats without operational downtime.
  • Reduced cost and financial risk: By unifying sensor management and supporting remote updates, Wittra’s solution lowers capital and operational costs. Organizations save by reusing their current sensors and infrastructure, avoiding overlapping platforms, and reducing field maintenance. Secure, update-ready IoT systems minimize the risk of breaches and regulatory penalties.

Example: 1,000 legacy sensors without remote update capability

Suppose an industrial site operates 1,000 older LoRa-based sensors that cannot receive firmware updates remotely via FOTA.

  • Upgrade Costs: If a critical vulnerability emerges, each sensor would require manual intervention for patching—either by sending technicians to physically update or replace every device, or by replacing large batches of hardware with compliant alternatives. This results in significant hardware expenses, labor costs, and potential downtime while old devices are taken offline.
  • Ongoing Security Risks: Until each node is manually updated, known vulnerabilities remain exploitable by attackers, creating a significant security gap. With 1,000 sensors, full coverage could take weeks or months, during which the organization faces a constant threat of breach, operational sabotage, or data loss. Inability to update also means vulnerabilities become, in effect, permanent.
  • Regulatory Compliance Pressure: CRA mandates “security by design” and continuous vulnerability management as a baseline. An unpatchable sensor fleet could make the company non-compliant with these requirements, risking forced product recalls, sales bans, or costly fines (up to €15 million or 2.5% of global turnover).
  • Operational Impact: Manual updating disrupts production and consumes valuable resources. There is also a strategic risk if sensors must be prematurely retired simply to maintain compliance, undermining ROI on existing investments.

Wittra’s migration path

Instead of a forced, disruptive “big bang” replacement, Wittra’s hybrid architecture bridges the gap:

  • Legacy LoRa sensors can remain in use by connecting through Wittra’s versatile gateway, which supports multiple protocols simultaneously.
  • Critical updates and new security features can be deployed over the air to newly introduced, OTA-compatible devices, gradually modernizing the sensor environment at the organization’s own pace.
  • Centralized management enables secure monitoring, troubleshooting, and policy enforcement across both legacy and new sensors, defending against cyber threats and keeping up with regulatory requirements efficiently.

Future-proof and compliant IoT investment

Wittra’s platform enables organizations to comply with evolving EU cybersecurity regulations and future-proof their IoT environments. The open, standards-based infrastructure supports flexible expansion and protects investments over the long term – avoiding lock-in and supporting business growth with minimal disruption.

In summary, Wittra’s hybrid IoT solution addresses regulatory, technical, and cost-related challenges of the new EU CRA through integrated security, remote management, simplified network architecture, and strong future readiness for connected products.


To find out more, contact us at info@wittra.io