The freshly released Qt 6.12, the latest Qt LTS (Long-Term Support) release, makes Qt Framework the first product for which Qt Group has issued an EU Declaration of Conformity under the EU Cyber Resilience Act (CRA).
Qt 6.12 CRA compliance with the known requirements is a result of the ongoing work that Qt Group has been putting in since the regulation first entered into force in December 2024. With the full CRA deadline approaching in just a little over a year from now, timing matters more than ever. The CRA obligations come with quite a lot of work, which we hope all our customers have started by now. With the Qt Framework release conforming to the requirements already now, our goal is to give you enough time to update to the new release and enable your own preparatory work for your products’ CRA compliance.
We also receive more and more questions from our customers around what role Qt Framework plays in CRA compliance. With this article, we aim to answer that, along with this question: will Qt help you meet the CRA requirements, or is that on you?
Qt 6.12 Is Compliant with the EU Cyber Resilience Act
The commercial Qt 6.12 LTS release has been formally declared by Qt Group for CRA compliance.
Qt Group carried out a Conformity Assessment for the commercial Qt 6.12 against the CRA's Annex I essential cybersecurity requirements. Classifying the commercial Qt Framework into CRA’s default category, this was done via self-assessment and accompanying EU Declaration of Conformity for Qt 6.12.
In practice, that means the 6.12 release is built to meet the known requirements set by the CRA as we today know will take full effect in December 2027. The Commercial Qt release has already been through the same conformity exercise that the CRA requires manufacturers to run for their own products. Once regulatory standards for applying the CE marking are clearer, the CE mark for Qt 6.12 will be affixed. In the meantime, the signed Declaration of Conformity demonstrates Qt 6.12 CRA compliance, and we continue to ensure the conformity in the coming maintenance releases throughout the 5-year LTS support period.
What Qt 6.12 CRA Compliance Means for You
If you place products with digital elements on the EU market, you're the manufacturer under the CRA, and the compliance obligation for your finished product stays with you. Using a CRA-declared Qt release doesn't change that. However, we hope it does help change how much of the underlying work and evidence gathering you have to do yourself.
Qt's conformity work can help significantly ease your own supply-chain due diligence, but it doesn’t replace it. That is to say, instead of assessing Qt Framework's cybersecurity stance on your own and from scratch, you get a wealth of the work ready-made and officially assessed for Qt’s part of your product, which can be used for your own product assessment. In addition, Qt 6.12 will be properly maintained also from the cybersecurity standpoint throughout the five-year LTS period, with the potential for longer with additional services. In case you’re wondering, we’ve summarized why security maintenance matters for long product lifecycles.
What Does Qt 6.12 Do for CRA compliance?
Here are some of the compliance assets to highlight:
- Security by design: Backed up by Qt Group's Quality Management System and the ISO certifications, Qt libraries make developing CRA-compliant features easier, and they come with any security critical items proactively marked.
- Risk management: Threat Analysis & Risk Assessment is carried out whenever there’s a new module, major feature, or architecture change, with each identified risk scored and tracked with a clear owner.
- Security by default: The high-quality Qt API helps add required functionality such as verifications and authentications, with clearly defined security responsibilities between Qt Group and your development team.
- Vulnerability management: Building on our own vulnerability handling process and exacting 3rd party management, Qt Group’s CNA status, security advisories, Early Warning List, and guaranteed response times (SLAs) for commercial customers lower your risks further.
- Security maintenance: The 5-year LTS support period, along with the option to extend and expand that with additional services, can significantly help in ensuring your products are updateable and patchable throughout their lifecycle.
- SBOM, Documentation & Assessments: Auto-generating your Software Bill of Materials (SBOM) and making use of the ready-made technical documentation can help with your CRA-related efforts, and you can use the Qt 6.12 Declaration of Conformity as supporting evidence for your own Conformity Assessment.
For the full picture of how the 6.12 release of the Qt Framework maps to each CRA requirement, see Easier Cyber Resilience Act compliance.
What about Open Source?
Qt 6.12's EU Declaration of Conformity and the future CE Marking cover Commercial Qt licenses only. It does not cover Qt’s open source offering (Qt Community Edition).
If your product is a proprietary one and falls under the CRA, we encourage you to consider moving to the commercial Qt 6.12 release. With the open source Qt Community Edition, the compliance burden rests on you. While all that work is doable if you have enough resources, we’ve gathered some thoughts on why staying on open source under the CRA is risky.
How Qt Group Carried Out the CRA Conformity Assessment
The Conformity Assessment to evaluate how the CRA requirements are met is not a simple tick-in-the box exercise or a single form to fill in. The Conformity Assessment is a repeatable process, and since a lot of our customers are building the same kind of process for their own products right now, we hope sharing some insights to ours will give you some food for thought.
To assess the CRA conformity, Qt 6.12 went through Qt Group’s five-phase process:
-
Define the product and assessment route. Qt Framework was classified into the CRA's default category, making it eligible for self-assessment.
-
Assess cybersecurity requirements. Qt 6.12 LTS was reviewed against the CRA's essential cybersecurity requirements, with every finding assigned an owner and tracked to closure.
-
Compile evidence. Documentation was assembled on the architecture, secure-development and vulnerability-handling practices, test results, SBOM, technical user documentation, and build provenance.
-
Declare conformity and affix the CE mark. A legal review was carried out, and the EU Declaration of Conformity for Qt 6.12 was officially signed and published. The CE mark for Qt 6.12 will be affixed as soon as it is practicable in conformance with applicable legislation. In the meantime, the signed Declaration of Conformity demonstrates Qt 6.12 CRA compliance.
-
Maintain compliance throughout the product lifecycle. The final, post-release phase: ensuring conformity throughout the support period, including ongoing vulnerability handling and incident reporting, as well as re-assessment if significant changes occur.
The same lifecycle applies across every upcoming commercial Qt Framework release. It's a cross-functional effort spanning Product Management, IT, RnD, and Legal, run the same way every time. If you're building your own CRA practices right now, we hope sharing our outline is helpful. Ensuring compliance requires quite a bit of engineering discipline, however, please keep in mind that you’re not alone. For instance, we can help you identify where you stand by organizing a CRA Readiness Check with our experts.
How to Check Qt’s CRA Compliance?
Qt 6.12 is the first release in what Qt Group sets out as an ongoing program: further releases and products are being sequenced for Conformity Assessment and affixing the CE Mark over time. See the CE Marking page for the latest status.
A summary of the EU Declaration of Conformity for Qt Framework Commercial 6.12 is available online.