STDA050 October   2026 AM2431 , AM2432 , AM2434 , AM623 , AM625 , AM625-Q1 , AM625SIP , AM62A1-Q1 , AM62A3 , AM62A3-Q1 , AM62A7 , AM62A7-Q1 , AM62L , AM62P , AM62P-Q1 , AM6411 , AM6412 , AM6421 , AM6422 , AM6441 , AM6442 , AM67 , AM67A , AM68 , AM68A , AM69 , AM69A , DRA821U , DRA829J , DRA829V , TDA4AEN-Q1 , TDA4AH-Q1 , TDA4AL-Q1 , TDA4AP-Q1 , TDA4APE-Q1 , TDA4VE-Q1 , TDA4VEN-Q1 , TDA4VH-Q1 , TDA4VL-Q1 , TDA4VM , TDA4VM-Q1 , TDA4VP-Q1 , TDA4VPE-Q1 , TDA54-Q1

 

  1.   1
  2.   Abstract
  3. 1Introduction
  4. 2CRA Scope and the Component Supplier Question
    1. 2.1 What the Regulation Covers
    2. 2.2 How the CRA Classifies TI Products
    3. 2.3 The Integration Boundary
  5. 3Shared Responsibility Model
    1. 3.1 The Supply Chain Stack
    2. 3.2 Responsibility Allocation by CRA Requirement
    3. 3.3 The Tier 1 and SoM Vendor Layer
  6. 4TI's Security Capabilities Relevant to CRA
    1. 4.1 Hardware Security Capabilities
    2. 4.2 SDK and Software Security
    3. 4.3 Documentation and Lifecycle Artifacts
  7. 5Conclusion
  8. 6References

Abstract

The EU Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, imposes cybersecurity requirements on products with digital elements placed on the EU market - including hardware components such as microprocessors sold to product manufacturers for integration. The CRA distributes compliance requirements across the supply chain: component suppliers and product manufacturers each carry a defined set of requirements based on the role they play. This paper explains what TI addresses at the silicon and software development kit (SDK) level as a component manufacturer, and what product manufacturers - including Tier 1 board vendors, system-on-module (SoM) suppliers, and original equipment manufacturer (OEM) system integrators - remain responsible for under the CRA. This paper is not legal advice; readers need to engage their legal and compliance teams for product-specific guidance.