EU Legislation

What is the Cyber Resilience Act?

The new EU regulation that mandates cybersecurity for digital products from December 2027.

The most important EU legislation for digital products

The Cyber Resilience Act (CRA) is a European regulation that entered into force on December 10, 2024. This legislation requires manufacturers, importers and distributors of products with digital elements to comply with strict cybersecurity requirements. The goal is to protect consumers and businesses in the EU against cyber threats.

Important Dates

December 10, 2024

CRA officially entered into force. Preparations are underway.

September 11, 2026

Reporting obligation for actively exploited vulnerabilities and incidents takes effect.

December 11, 2027

All requirements take effect. Products with digital elements must be fully compliant.

Who does the CRA apply to?

The CRA applies to all economic operators in the supply chain of digital products.

Business compliance

Which products fall under the CRA?

The CRA classifies products with digital elements into different categories based on their risk profile.

Default products

The majority of digital products: software, apps, connected devices. Self-assessment is sufficient for conformity assessment.

Important products - Class I

Higher risk products such as password managers, VPNs and network equipment. Harmonized standards or third-party assessment required.

Important products - Class II

High risk products such as firewalls, intrusion detection systems and industrial controllers. Mandatory third-party assessment.

Critical products

The highest risk class: smart cards, hardware security modules and smart meter gateways. European cybersecurity certification required.

What do you need to do?

Security by design

Build security into the product from the design stage rather than bolting it on. Ship with a secure default configuration and without known exploitable vulnerabilities.

Risk assessment

Carry out a documented cybersecurity risk assessment for every product with digital elements, and keep it current throughout the product's lifetime.

CE marking and conformity

Complete the applicable conformity assessment, draw up the EU declaration of conformity and affix the CE marking before placing the product on the market.

Security updates

Provide free security updates for at least five years, issued separately from functional updates so users can install them without other changes.

Reporting within 24 hours

Report an actively exploited vulnerability as an early warning within 24 hours and in full within 72 hours to your CSIRT and ENISA. This obligation applies from 11 September 2026.

Technical documentation and SBOM

Maintain the technical documentation, including a software bill of materials of your components, and keep it for ten years or the length of the support period.

€15M

Maximum fine

2027

Full compliance deadline

5 years

Mandatory support period

24h

Vulnerability reporting deadline

Want to know if the CRA applies to your products?

Our experts analyze your product portfolio and determine which CRA obligations apply to your organization.

CRA Assistent