EU Cyber Resilience Act Forces IoT Buyers to Demand Firmware SBOMs by September 2026
The EU Cyber Resilience Act mandates machine-readable firmware SBOMs for 24-hour vulnerability reporting starting September 11, 2026. Vendors without secure boot, OTA updates, and component-level visibility will fail procurement.
Compliance Pressure Redefines IoT Vendor Selection
The EU Cyber Resilience Act is forcing enterprise IoT buyers to treat firmware transparency as a mandatory procurement criterion, not a nice-to-have security claim. Starting September 11, 2026, manufacturers must deliver machine-readable software bills of materials (SBOMs) to meet the Act's 24-hour vulnerability reporting obligation, with full enforcement arriving later in the rollout. Vendors that cannot prove secure boot, unique device credentials, over-the-air update support, and component-level visibility will fail compliance audits before they reach production floors.
This shifts buying decisions from abstract "secure by design" marketing to concrete documentation requirements. If a supplier cannot expose firmware composition, document lifecycle patching, or orchestrate automatic updates across deployed fleets, they create direct regulatory and audit risk. Enterprise buyers with EU manufacturing, critical infrastructure, or cross-border device deployments must now filter vendors by their ability to maintain vulnerability documentation and component inventories across the entire device lifecycle—not just at the point of sale.
The competitive advantage moves to vendors with mature device observability and patch orchestration. Palo Alto Networks is consolidating its IoT security capabilities into Strata Cloud Manager, with June 2026 documentation updates showing new Process Zones for network visualization and updated SNMP network discovery. Customers who onboarded to IoT Security after June 2025 can only manage devices through Strata Cloud Manager, which bundles IoT visibility into a broader network-security operating model. This reduces tool sprawl for large buyers but increases platform lock-in and pushes renewals toward vendors already standardizing on cloud-managed workflows.
Risk Metrics and Router Vulnerabilities Drive Segmentation Spending
IoT risk is worsening, and the failure points are not where most buyers focus their budgets. Routers and network equipment account for more than 50% of devices with the most dangerous vulnerabilities, according to Forescout and Vedere Labs data, and average device risk rose 15% year over year. This means the riskiest assets in most enterprise networks are infrastructure devices that traditional endpoint security tools miss entirely.
Buyers should expect spending to shift from isolated IoT point controls toward network-wide device visibility, risk scoring, and segmentation. Platforms that combine asset discovery, vulnerability prioritization, and segmentation for unmanaged devices will outcompete endpoint-only security tools because the threat surface has moved to devices that lack agents, exist outside IT asset inventories, and operate on operational technology (OT) networks.
eSIM Standards Cut Deployment Friction and Logistics Costs
The GSMA SGP.32 standard is moving from standards work into deployment decisions, enabling a zero-touch "build-once, ship-anywhere" model for constrained IoT devices. ABI Research expects eSIM-enabled IoT device shipments to reach 140 million in 2025, with acceleration in 2026. This shifts competition toward providers that deliver remote provisioning, fleet-level lifecycle management, and carrier interoperability, challenging older proprietary SIM management workflows.
For enterprise buyers, this cuts logistics costs and speeds international rollouts, especially for utilities, automotive, and distributed industrial assets. The operational benefit is not theoretical: eSIM eliminates the need to physically swap SIM cards when devices cross borders, change carriers, or require network failover. This matters most for buyers managing devices across multiple regions or operating in industries where device uptime and remote management are critical.
Regulatory Labels Become Procurement Signals
The U.S. Cyber Trust Mark is now a voluntary cybersecurity label for consumer wireless IoT categories including smart cameras, smart appliances, fitness trackers, garage door openers, and baby monitors. While aimed at consumer devices, the label influences enterprise procurement in facilities, healthcare, retail, and smart-building contexts where buyers increasingly mix consumer and enterprise-connected devices.
Certification-ready vendors gain marketing and channel advantage over lower-maturity rivals that lack documented security baselines. Even in enterprise procurement, these labels and adjacent standards influence vendor due diligence because they provide a shortcut to assessing whether a vendor meets minimum security hygiene. Buyers should ask whether vendors have pursued certification, not because the label guarantees security, but because it signals a vendor's willingness to document and maintain security practices across product lifecycles.
What to Watch
Three immediate actions for enterprise buyers: First, audit current IoT vendors for CRA compliance readiness—specifically, whether they can deliver machine-readable firmware SBOMs and document vulnerability response processes. Second, prioritize vendors that support eSIM and remote provisioning if your deployments span multiple regions or carriers. Third, evaluate whether your network segmentation and asset discovery tools cover routers and network infrastructure, not just endpoints, because that is where the vulnerability concentration has shifted. Vendors that cannot meet the first requirement will fail compliance audits in EU markets; vendors that cannot meet the second will force higher deployment and operational costs; and buyers that ignore the third will continue to miss the riskiest devices in their networks.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
