The EU Cyber Resilience Act (CRA) is changing the expectations placed on connected products — from how security is designed in, to how vulnerabilities are managed, updates are delivered and devices are supported throughout their lifetime.
For connected device manufacturers, this makes cybersecurity increasingly important not only for compliance, but for market access, customer trust and long-term product strategy.
A new paper from Kigen and ABI Research, EU Cyber Resilience Act (CRA) for Connected Device OEMs: Compliance to Competitive Edge, explores what this means for connected device manufacturers and how secure eSIM and Remote SIM Provisioning can help provide a foundation for more resilient products and global deployments.

“Security is becoming part of market access, not simply a feature added after the product is designed.”
—
Vincent Korstanje, CEO, Kigen
Kigen has explored this shift before: manufacturers increasingly need to consider whether products can remain secure, manageable and updateable long after they leave the factory.
Existing research has highlighted the size of that readiness gap. Just 22% of organisations surveyed in the GSMA eSIM Survey Report 2026 described themselves as highly prepared for CRA, while more than half could not currently demonstrate the update capability regulators will require.
But readiness can also create opportunity. When security, remote management and lifecycle updates are built into the product architecture from the outset, manufacturers can reduce future complexity while strengthening the trust and resilience of their products.
A shift where security becoming the new market access: a move away from treating cybersecurity simply as a cost and toward viewing it as an enabler for accessing demanding global markets.
For cellular IoT manufacturers, the ABI Research paper examines how SGP.32 Remote SIM Provisioning and GSMA eUICC Security Assurance (eSA) can provide an established technical foundation for secure, long-life connected products.
SGP.32 gives manufacturers a standards-based approach for remotely managing eSIM connectivity across IoT devices, while eSA provides an established security assurance framework for the eSIM platform. Neither should be treated as a standalone guarantee of CRA compliance, but together they can form part of a wider secure-by-design architecture.
Kigen builds on this foundation through eSA-certified eSIM, SGP.32 support, IoT Profile Assistant architectures, In-Factory Profile Provisioning and remote management capabilities, helping manufacturers embed secure connectivity into products from the outset and manage them throughout their lifecycle.
That approach is now extending into some of the most demanding long-life connected products. In September 2026, Kigen Automotive eSIM became the industry’s first eSA-certified eSIM supporting SGP.32 v1.3, combining Kigen eSIM OS with Infineon’s TEGRION™ SLI22 automotive security controller. It gives connected-vehicle OEMs and Tier-1s a standards-current platform designed for fleets that may need to remain secure for more than a decade.
The automotive certification also builds on Kigen’s existing eSA-certified IoT and Consumer eSIM portfolio, extending the same security foundation across Automotive, Consumer and Industrial IoT use cases. Kigen’s automotive implementation supports features introduced with SGP.32 v1.3, including direct and indirect profile downloads, digital activation codes and emergency profile handling.
“Vehicles are becoming long-lived software platforms, so their connectivity trust anchor must remain secure and manageable long after production.” Vincent Korstanje, CEO, Kigen