Cyber Resilience Act

CRA?

The Cyber Resilience Act (CRA) is a comprehensive regulation introduced by the European Union to establish baseline cybersecurity requirements for products with digital elements. As cyber threats become more advanced and persistent, the EU has recognized the critical need to ensure that digital products are secure not only at launch but throughout their entire lifecycle.

Unlike voluntary standards or patchwork national regulations, the CRA is a binding regulation—meaning it applies uniformly across all EU Member States without the need for national legislation. This ensures a harmonized cybersecurity baseline across the entire EU market, leveling the playing field and improving trust among consumers and businesses alike.

Whether you’re a hardware manufacturer, software vendor, importer, or distributor, if you’re involved in bringing a digital product to the EU market, this law applies to you.

Who & What?

smart devices vpn

The CRA applies to an expansive category of products and economic operators. Specifically, it targets products with digital elements (PDEs)—this includes hardware and software products that connect to other devices or networks and have software embedded or interacting with them.

Some examples of covered products:

The CRA also impacts the entire supply chain, including:

Even open-source software projects may fall within the scope, especially if used or modified by companies in commercial offerings.

Product Classifications: Standard vs Critical Products

Not all digital products are created equal — and the CRA recognizes that. To ensure a risk-based approach to cybersecurity, the CRA divides products with digital elements into two main categories: Standard Products and Critical Products.

🟢 Standard Products: Lower Risk, Self-Assessable

Standard products are general-purpose digital items that present a relatively lower cybersecurity risk. These can include everyday consumer electronics, basic software tools, and connected devices that don’t perform security-sensitive functions.

For these products, manufacturers have the flexibility to self-assess their conformity with CRA requirements — as long as they maintain proper documentation, apply secure development practices, and address known vulnerabilities. This streamlined approach allows companies to reduce administrative overhead while still meeting essential cybersecurity obligations.

However, self-assessment does not mean lesser responsibility. The same baseline principles apply — secure-by-design development, clear update policies, and incident reporting mechanisms must all be in place.

🔴 Critical Products (Annex III): High Risk, Tightly Regulated

In contrast, Critical Products are identified in Annex III of the CRA and represent higher-risk technologies that, if compromised, could have a major impact on users, infrastructure, or society. These products include:

Due to their elevated risk, these products face stricter oversight. Manufacturers of Critical Products must undergo a formal conformity assessment — often involving an independent third party, or “notified body.” These assessments go beyond basic compliance and require in-depth analysis of risk management strategies, secure development lifecycles, vulnerability handling processes, and long-term maintenance plans.
This classification ensures that products central to security or network operation receive an appropriate level of scrutiny before entering the EU market.

Timeline and Key Milestones

  • 15 Sep 2022

    The Beginning of a New Cyber Standard
    The European Commission introduced the Cyber Resilience Act as a major step toward strengthening cybersecurity in the EU. This marked the beginning of a unified regulatory approach to securing digital products across the internal market.

  • 1 Dec 2023

    Reaching Political Consensus
    Following extensive negotiations, EU co-legislators reached a political agreement, aligning on the core structure and scope of the CRA. This milestone signaled broad institutional support for a harmonized cybersecurity framework.

  • 12 Mar 2024

    Parliament Approval Secured
    The European Parliament formally adopted the CRA, reinforcing the EU’s commitment to making cybersecurity a legal obligation rather than a voluntary best practice. The vote confirmed that digital product security is now a shared responsibility under law.

  • 10 Oct 2024

    Council Confirms Final Text
    With the Council’s approval, the CRA’s legal text was finalized. This closed the legislative phase and cleared the way for full adoption and publication across the EU’s legal and regulatory systems.

  • 20 Nov 2024

    The CRA Becomes Official Law
    The Cyber Resilience Act was officially published in the EU’s Official Journal as Regulation (EU) 2024/2847. This publication made the law official, setting the stage for its phased implementation.

  • 10 Dec 2024

    EU-Wide Enforcement Begins
    The CRA entered into force and became binding across all EU Member States. From this moment, the countdown began for companies to prepare for compliance, adapt internal processes, and implement the necessary security measures.

  • 1789077600

      days

      hours  minutes  seconds

    until

  • 11 Sep 2026

    Mandatory Reporting Takes Effect
    Manufacturers are required to report actively exploited vulnerabilities and significant cybersecurity incidents to relevant national authorities and ENISA. This obligation helps drive greater transparency and faster risk mitigation across the EU.

  • 11 Dec 2027

    Full Compliance Deadline
    The CRA’s main provisions become fully enforceable. From this point, all covered products must meet the complete set of cybersecurity requirements—including secure-by-design principles, documentation, CE marking, support timelines, and conformity assessments.

Obligations

The CRA introduces binding cybersecurity requirements for all digital products with data or network connectivity placed on the EU market. Manufacturers and developers have key responsibilities across the entire product lifecycle — from design and production to post-market monitoring and updates.

Security by Design and by Default

Under the CRA, cybersecurity must be built into the product from the start. Manufacturers must follow “security by design and by default” principles, identifying risks early through threat modeling and risk assessments. Insecure defaults like hardcoded passwords or open ports must be avoided, while secure boot, encryption, and access controls must be integrated as standard features.

Ongoing Risk and Vulnerability Management

The CRA makes post-launch security a continuous responsibility. Manufacturers must actively monitor their products for vulnerabilities and deliver timely patches. Any actively exploited vulnerabilities must be reported to ENISA within 24 hours. A public Vulnerability Disclosure Policy and dedicated security contact must be available for researchers and users.

Technical Documentation and Compliance Files

Every product must include detailed technical documentation to prove CRA compliance. This should cover the cybersecurity risk assessment, mitigation methods, and all key software and hardware components. It must also explain how updates are managed, how security is tested, and how long the product will be supported.

CE Marking and Declaration of Conformity

To sell a product in the EU, manufacturers must apply the CE marking to show CRA compliance. This must be backed by a Declaration of Conformity that cites the applicable cybersecurity requirements and confirms full adherence. This process promotes trust and ensures regulatory oversight.

Post-Market Responsibilities

Compliance with the CRA doesn’t end once a product is launched. Manufacturers are expected to maintain the cybersecurity and resilience of their products throughout the entire operational lifecycle. Ongoing vigilance is essential.

Minimum Security Support Period

Manufacturers must guarantee security support for a minimum of five years, unless the product is clearly intended for a shorter operational period. This includes timely delivery of software updates, patches, and mitigation measures in response to emerging threats.

Lifecycle Monitoring and Response

Products must be actively monitored post-market to identify newly discovered vulnerabilities, shifts in threat landscapes, or changes in user behavior that could introduce risk. Manufacturers are responsible for establishing mechanisms that allow them to detect, analyze, and respond to these developments effectively.

Incident Reporting and Transparency

If a serious cybersecurity incident occurs — such as a breach, active exploit, or widespread vulnerability — manufacturers are required to notify both ENISA and affected users without undue delay. Transparency is a core principle of the CRA, aimed at minimizing harm and promoting rapid, coordinated response across the EU.

Penalties and Enforcement

The Cyber Resilience Act includes strong enforcement mechanisms to ensure compliance across the digital product supply chain. Failing to meet CRA obligations can lead to significant financial, legal, and reputational consequences.

Fines and Financial Sanctions

Non-compliance can result in administrative fines of up to €15 million or 2.5% of global annual turnover — whichever amount is higher. These penalties are aligned with the EU’s broader digital and data protection enforcement framework.

Market Restrictions and Product Recalls

In serious cases, authorities may take direct action, including withdrawal or recall of non-compliant products from the EU market. Sales may also be suspended until the manufacturer can demonstrate full adherence to CRA requirements.

Oversight and Regulatory Action

CRA enforcement will be coordinated by national market surveillance authorities, working alongside ENISA and the European Commission. These bodies are empowered to investigate, audit, and take corrective action as needed to ensure product security and user safety.

Legal and Reputational Risk

Beyond regulatory penalties, failure to comply can result in lawsuits, contract losses, and irreversible reputational damage — particularly if security lapses lead to data loss, system outages, or harm to users. For companies in the digital product space, CRA compliance is both a legal obligation and a strategic imperative.

Steps Toward CRA Compliance

Getting compliant with the CRA is a significant effort, especially for organizations that have not previously prioritized secure product development. The following steps are recommended:

Identify In-Scope Products

Create an inventory of products with digital elements

Perform a Gap Analysis

Compare your existing processes with CRA requirements

Build or Enhance a Secure Development Lifecycle (SDL)

Introduce security gates at all stages of development

Establish Vulnerability Disclosure and Incident Response Plans

Publicly list a security contact and VDP

Compile Required Technical Documentation

Maintain ready-to-present compliance files

Plan for Conformity Assessment

Determine whether self-assessment or third-party review is needed

Final Thoughts: Turning Compliance Into Competitive Advantage

The Cyber Resilience Act is more than a compliance hurdle—it’s a strategic opportunity. By proactively aligning with the CRA, companies can:

Reduce legal and operational risks

Improve customer trust and brand reputation

Open doors to the EU’s vast and digitally connected market

With enforcement deadlines approaching, now is the time to act. Investing in cybersecurity and compliance is no longer optional—it’s a fundamental part of doing business in a connected world.
Need support in getting CRA-ready? Our consultants can help you evaluate risks, implement controls, and navigate the compliance lifecycle.