TechNewsReel
Live

Nordic Semiconductor Launches Lifetime FOTA Solution for EU Cyber Resilience Act

The chipmaker introduces a flat-rate firmware update service to help IoT manufacturers navigate the EU's strict new security mandates.

TechNewsReel Newsroom · August 3, 2026

Nordic Semiconductor is moving to shield its customers from the operational burdens of the European Union's Cyber Resilience Act (CRA). The company has launched a lifelong Firmware Over-the-Air (FOTA) flat-rate license via its nRF Cloud to ensure embedded devices can receive mandatory security updates throughout their operational lives.

The new offering directly addresses the CRA's requirement for manufacturers to provide security support for the duration of a product's expected lifetime. By utilizing the nRF Cloud infrastructure, Nordic allows its clients to deploy critical patches and security fixes remotely, removing the logistical hurdle of manual updates for millions of deployed IoT devices. A Nordic Semiconductor representative stated that the company is providing these solutions to "simplify and accelerate the compliance process" as the enforcement window closes.

The Regulatory Deadline

The EU Cyber Resilience Act, which entered into force on December 10, 2024, represents the first binding regulation in the European Union specifically targeting the cybersecurity of products with digital elements. The act mandates a "security by design" approach, forcing manufacturers to integrate security measures from the earliest stages of development. While the act is already in force, the grace period for full product compliance—including formal conformity assessments and the application of the CE marking—ends on December 11, 2027.

Industry Implications

For the semiconductor and IoT sectors, the CRA transforms security from a best practice into a legal necessity. For manufacturers, the act introduces significant risks, including increased liability and higher long-term compliance costs. However, for a provider like Nordic, the regulation creates a strategic opportunity to embed its services deeper into the customer lifecycle. By offering a flat-rate FOTA solution, Nordic not only ensures its hardware remains viable in the EU market but also establishes a recurring value proposition that locks customers into its cloud ecosystem.

Scaling for Compliance

As the December 2027 deadline approaches, the industry will be watching how other chipmakers respond to the CRA's lifecycle requirements. The primary focus for Nordic remains the scaling of nRF Cloud to support the massive volume of updates required to keep the European IoT landscape compliant. This infrastructure is critical for maintaining the long-term viability of devices that must now adhere to strict, legally mandated security maintenance schedules over several years of operation.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.