inepro Solutions
Logo inepro Metering
Electricity Meters
logo inepro Pay and ID
RFID Readers
logo inepro Pay and ID
inepro Group
Company news

Cyber resilience strengthens the integrity behind every measurement

Designed to make digital products safer to use, the CRA sets mandatory requirements on a wide range of products from IoT devices and industrial controllers to operating systems. These regulations also mark a major change in electricity metering.

11/9/2026
Cyber Resiliance Act (CRA) for electricity metering

The European Union is raising the cybersecurity bar for all connected devices with the Cyber Resilience Act (CRA). This landmark regulation will be fully enforceable from 11 December 2027, while reporting obligations for actively exploited vulnerabilities and severe security incidents apply from 11 September 2026. Designed to make digital products safer to use, the CRA sets mandatory requirements on a wide range of products from IoT devices and industrial controllers to operating systems. These regulations also mark a major change in electricity metering.

For inepro Metering, this is a natural extension of established practices in product conformity. An electricity meter is expected to measure accurately and reliably, and that trust is built through how the product is designed, assessed, and maintained throughout its entire life cycle. As meters become increasingly connected and interact with wider energy management systems, that trust also extends to the security of their software and communication interfaces.

Building on established product compliance

The Cyber Resilience Act will transform how technology is designed, implemented, and maintained in Europe, as the legislation applies to all digital products, including sub-meters, gateways, EMS/BMS platforms, and IoT infrastructure.

Before an inepro meter is brought to market, its metrological performance, electrical safety, software, and communication capabilities are evaluated against the applicable requirements. Design changes are reviewed, verified and assessed for their impact on the product’s conformity throughout its entire life cycle.

The CRA is extending this tried-and-tested approach to cyber security. Connected products will no longer be assessed solely on performance and functionality, but also on how securely they protect data, manage vulnerabilities and receive security updates throughout their entire defined support period. This means stronger firmware security, more reliable communication protocols and more dependable update systems. The regulations can also extend beyond the device itself to cloud platforms, backend services, and third-party software components, if they are necessary for the product to function correctly.

Reporting readiness for the first CRA milestone

This broader lifecycle responsibility is reflected in the first major CRA milestone for manufacturers. From 11 September 2026, the reporting obligations for actively exploited vulnerabilities and severe security incidents start to apply. In preparation, inepro has established processes to receive, assess, escalate, and, where required, report product-security issues within the applicable timelines.

Our public Coordinated Vulnerability Disclosure Policy gives customers, partners and security researchers a clear route for reporting potential vulnerabilities. Behind it is a structured Product Security Incident Response Team process covering technical assessment, containment, remediation, communication and closure.

Applying the CRA at product level

Reporting is only one aspect of cyber resilience. inepro Metering also translates the CRA’s essential cybersecurity requirements into product-specific applicability and gap analyses for our relevant, connected metering platforms. These reviews examine the intended use, firmware, communication interfaces, third-party components, update capabilities and existing security measures.

The detailed harmonised standards supporting the CRA conformity assessment are still under development. inepro’s product assessments will therefore continue to evolve as these standards become available and product designs and technical guidelines develop further. They should not be construed as definitive statements of CRA conformity.

inepro’s vulnerability monitoring process incorporates a lifecycle perspective. When an advisory is published for a component used in one of our products, inepro investigates the relevant release, configuration and functionality before determining whether action is required.

The CRA’s key product requirements will apply from 11 December 2027. inepro’s current focus is therefore on building on the reporting capabilities already established and gradually integrating the product requirements into development, compliance and lifecycle management activities.

For inepro Metering, cyber resilience is the next step in maintaining the trust that underpins every measurement.

Jasper Bosgraaf inepro Metering
Ronald inepro Metering

Our team is here to assist you

Would you like advice, detailed information about our electricity meters or a personalised quote for our metering solutions?