Skip to main content

Qt 6.12 and CRA Compliance: Qt Group’s First Declared Release

Read Time

10 mins

MauriceKalinowski-round-500x500 Maurice Kalinowski
Director, Product Management,
Qt Framework

 

GabrielByman-round-500x500Gabriel Byman
Senior Manager, Product Security and Compliance, Qt Group

TL;DR

  • The EU Cyber Resilience Act (CRA) will come into full effect on December 11th, 2027, by which time, if it impacts you, you will need to ensure compliance for your applicable products.
  • The latest Qt Framework release, Qt 6.12 LTS, is the first Qt release with a signed EU Declaration of Conformity, covering Commercial Qt licenses.
  • Qt 6.12 complying with the CRA requirements now can help you to prepare and get your products ready on time using it.
  • Using this Qt release doesn't automatically make your finished product CRA-compliant (you’ll always have to do your own CRA work) but it gives you a documented, ready-made evidence binder designed to help significantly lower your risk for Qt's part of your product.

The freshly released Qt 6.12, the latest Qt LTS (Long-Term Support) release, makes Qt Framework the first product for which Qt Group has issued an EU Declaration of Conformity under the EU Cyber Resilience Act (CRA).

Qt 6.12 CRA compliance with the known requirements is a result of the ongoing work that Qt Group has been putting in since the regulation first entered into force in December 2024. With the full CRA deadline approaching in just a little over a year from now, timing matters more than ever. The CRA obligations come with quite a lot of work, which we hope all our customers have started by now. With the Qt Framework release conforming to the requirements already now, our goal is to give you enough time to update to the new release and enable your own preparatory work for your products’ CRA compliance.

We also receive more and more questions from our customers around what role Qt Framework plays in CRA compliance. With this article, we aim to answer that, along with this question: will Qt help you meet the CRA requirements, or is that on you?

Qt 6.12 Is Compliant with the EU Cyber Resilience Act

The commercial Qt 6.12 LTS release has been formally declared by Qt Group for CRA compliance.

Qt Group carried out a Conformity Assessment for the commercial Qt 6.12 against the CRA's Annex I essential cybersecurity requirements. Classifying the commercial Qt Framework into CRA’s default category, this was done via self-assessment and accompanying EU Declaration of Conformity for Qt 6.12.

In practice, that means the 6.12 release is built to meet the known requirements set by the CRA as we today know will take full effect in December 2027. The Commercial Qt release has already been through the same conformity exercise that the CRA requires manufacturers to run for their own products. Once regulatory standards for applying the CE marking are clearer, the CE mark for Qt 6.12 will be affixed. In the meantime, the signed Declaration of Conformity demonstrates Qt 6.12 CRA compliance, and we continue to ensure the conformity in the coming maintenance releases throughout the 5-year LTS support period.

 

What Qt 6.12 CRA Compliance Means for You

If you place products with digital elements on the EU market, you're the manufacturer under the CRA, and the compliance obligation for your finished product stays with you. Using a CRA-declared Qt release doesn't change that. However, we hope it does help change how much of the underlying work and evidence gathering you have to do yourself.

Qt's conformity work can help significantly ease your own supply-chain due diligence, but it doesn’t replace it. That is to say, instead of assessing Qt Framework's cybersecurity stance on your own and from scratch, you get a wealth of the work ready-made and officially assessed for Qt’s part of your product, which can be used for your own product assessment. In addition, Qt 6.12 will be properly maintained also from the cybersecurity standpoint throughout the five-year LTS period, with the potential for longer with additional services. In case you’re wondering, we’ve summarized why security maintenance matters for long product lifecycles.

 

What Does Qt 6.12 Do for CRA compliance?

Here are some of the compliance assets to highlight:

    • Security by design: Backed up by Qt Group's Quality Management System and the ISO certifications, Qt libraries make developing CRA-compliant features easier, and they come with any security critical items proactively marked.
    • Risk management: Threat Analysis & Risk Assessment is carried out whenever there’s a new module, major feature, or architecture change, with each identified risk scored and tracked with a clear owner.
    • Security by default: The high-quality Qt API helps add required functionality such as verifications and authentications, with clearly defined security responsibilities between Qt Group and your development team.
    • Vulnerability management: Building on our own vulnerability handling process and exacting 3rd party management, Qt Group’s CNA status, security advisories, Early Warning List, and guaranteed response times (SLAs) for commercial customers lower your risks further.
    • Security maintenance: The 5-year LTS support period, along with the option to extend and expand that with additional services, can significantly help in ensuring your products are updateable and patchable throughout their lifecycle.
    • SBOM, Documentation & Assessments: Auto-generating your Software Bill of Materials (SBOM) and making use of the ready-made technical documentation can help with your CRA-related efforts, and you can use the Qt 6.12 Declaration of Conformity as supporting evidence for your own Conformity Assessment.

For the full picture of how the 6.12 release of the Qt Framework maps to each CRA requirement, see Easier Cyber Resilience Act compliance.

 

What about Open Source?

Qt 6.12's EU Declaration of Conformity and the future CE Marking cover Commercial Qt licenses only. It does not cover Qt’s open source offering (Qt Community Edition).

If your product is a proprietary one and falls under the CRA, we encourage you to consider moving to the commercial Qt 6.12 release. With the open source Qt Community Edition, the compliance burden rests on you. While all that work is doable if you have enough resources, we’ve gathered some thoughts on why staying on open source under the CRA is risky.

 

How Qt Group Carried Out the CRA Conformity Assessment

The Conformity Assessment to evaluate how the CRA requirements are met is not a simple tick-in-the box exercise or a single form to fill in. The Conformity Assessment is a repeatable process, and since a lot of our customers are building the same kind of process for their own products right now, we hope sharing some insights to ours will give you some food for thought.

To assess the CRA conformity, Qt 6.12 went through Qt Group’s five-phase process:

  1. Define the product and assessment route. Qt Framework was classified into the CRA's default category, making it eligible for self-assessment.

  2. Assess cybersecurity requirements. Qt 6.12 LTS was reviewed against the CRA's essential cybersecurity requirements, with every finding assigned an owner and tracked to closure.

  3. Compile evidence. Documentation was assembled on the architecture, secure-development and vulnerability-handling practices, test results, SBOM, technical user documentation, and build provenance.

  4. Declare conformity and affix the CE mark. A legal review was carried out, and the EU Declaration of Conformity for Qt 6.12 was officially signed and published. The CE mark for Qt 6.12 will be affixed as soon as it is practicable in conformance with applicable legislation. In the meantime, the signed Declaration of Conformity demonstrates Qt 6.12 CRA compliance.

  5. Maintain compliance throughout the product lifecycle. The final, post-release phase: ensuring conformity throughout the support period, including ongoing vulnerability handling and incident reporting, as well as re-assessment if significant changes occur.

The same lifecycle applies across every upcoming commercial Qt Framework release. It's a cross-functional effort spanning Product Management, IT, RnD, and Legal, run the same way every time. If you're building your own CRA practices right now, we hope sharing our outline is helpful. Ensuring compliance requires quite a bit of engineering discipline, however, please keep in mind that you’re not alone. For instance, we can help you identify where you stand by organizing a CRA Readiness Check with our experts.

 

How to Check Qt’s CRA Compliance?

Qt 6.12 is the first release in what Qt Group sets out as an ongoing program: further releases and products are being sequenced for Conformity Assessment and affixing the CE Mark over time. See the CE Marking page for the latest status.

A summary of the EU Declaration of Conformity for Qt Framework Commercial 6.12 is available online. 

 

Frequently Asked Questions

Is Qt 6.12 compliant with the EU Cyber Resilience Act?

  • CRA

The commercial Qt 6.12 LTS is compliant with the EU Cyber Resilience Act (CRA) to the extent that we today know will take effect in December 2027. The release has already been through the CRA-required Conformity Assessment, allowing customers building their software products with Qt to take the release to use as part of their own CRA compliance timing. Since regulatory standards are still evolving, affixing the CE mark for Qt 6.12 will take place once legally practicable. In the meantime, the signed Declaration of Conformity demonstrates Qt 6.12 CRA compliance, and Qt Group commits to ensuring the conformity throughout the 5-year LTS support period.

Does using Qt 6.12 LTS make my product CRA-compliant?

  • CRA
 Using the CRA-compliant Qt release, that is, the commercial Qt 6.12 LTS, does not automatically make products built with it CRA-compliant. Any Qt Framework’s compliance covers Qt's part of your product only, and as the manufacturer of your own finished product, you will always need to do your own CRA-related work, set up your internal processes, gather your evidence, and ensure the cybersecurity of your product, no matter which framework or vendors you use in your product. However, using Qt 6.12 LTS can help make that work significantly easier for you. 

Can I use open source Qt under the CRA?

  • CRA

You can use the Qt Community Edition (the open source version of Qt) under the EU Cyber Resilience Act (CRA). However, it’s important to note that Qt 6.12's CRA compliance only covers Commercial Qt licenses. If your product falls under the CRA, moving to Qt 6.12 commercial is a serious consideration as the Qt Community Edition can carry a significant compliance burden and effort, especially with long product lifecycles.

Learn more about why staying on open source under the CRA is risky.

What does Qt 6.12 do for CRA compliance?

  • CRA

The Qt 6.12 LTS release comes with a signed EU Declaration of Conformity and a wealth of other assets, such as the SBOM and technical documentation, that you can use as evidence to support your own CRA due diligence for Qt's part of your product. These are further strengthened by other compliance artifacts and practices by the Qt Group, such as the five-year Qt LTS support period, CNA-issued CVEs, and the Early Warning List.

Read more about how Qt 6.12 makes your CRA-compliance easier.

What is the EU Cyber Resilience Act and who does it affect?

  • CRA

The EU Cyber Resilience Act (CRA) is a new, comprehensive piece of EU legislation that aims to ensure lifetime security and resilience against cyber threats for all products with digital elements (PDEs), ranging from industrial systems to consumer electronics and embedded user interfaces. Some already regulated industries, such as medical and automotive, are out of scope.

The CRA impacts manufacturers and suppliers who sell their products in the EU market. The reporting requirements, effective from September 11th, 2026, apply also to products that are already out in the market, not just the new ones.

Learn more at https://www.qt.io/cyber-resilience-act/will-cra-impact-me

Where can I find more information about the EU Cyber Resilience Act?

  • CRA

Qt Group has put together a dedicated CRA web space to summarize some of the requirements, provide food for thought, and share where Qt Group products are today with the CRA compliance.

Key highlights include a flow chart to explain who the CRA impacts, highlights on the Software Bill of Materials (SBOM), considerations around 3rd party management, product lifecycle practices, and vulnerability management, as well as key takeaways on the CE marking.

Go to the CRA web space >>

The information contained in this article and this website does not constitute legal advice. It is provided for informational purposes and discussion of the subject matter only. Content is subject to change, and Qt Group does not guarantee the accuracy or currentness of the contents of this article, nor is Qt Group responsible for the content or operation of any external website that these pages link to. The information contained here is not, and should not be used as, a substitute for legal advice.

    Try Qt for Free

    Download now