The new EU regulation that mandates cybersecurity for digital products from December 2027.
The Cyber Resilience Act (CRA) is a European regulation that entered into force on December 10, 2024. This legislation requires manufacturers, importers and distributors of products with digital elements to comply with strict cybersecurity requirements. The goal is to protect consumers and businesses in the EU against cyber threats.
CRA officially entered into force. Preparations are underway.
Reporting obligation for actively exploited vulnerabilities and incidents takes effect.
All requirements take effect. Products with digital elements must be fully compliant.
The CRA applies to all economic operators in the supply chain of digital products.
The CRA classifies products with digital elements into different categories based on their risk profile.
The majority of digital products: software, apps, connected devices. Self-assessment is sufficient for conformity assessment.
Higher risk products such as password managers, VPNs and network equipment. Harmonized standards or third-party assessment required.
High risk products such as firewalls, intrusion detection systems and industrial controllers. Mandatory third-party assessment.
The highest risk class: smart cards, hardware security modules and smart meter gateways. European cybersecurity certification required.
Build security into the product from the design stage rather than bolting it on. Ship with a secure default configuration and without known exploitable vulnerabilities.
Carry out a documented cybersecurity risk assessment for every product with digital elements, and keep it current throughout the product's lifetime.
Complete the applicable conformity assessment, draw up the EU declaration of conformity and affix the CE marking before placing the product on the market.
Provide free security updates for at least five years, issued separately from functional updates so users can install them without other changes.
Report an actively exploited vulnerability as an early warning within 24 hours and in full within 72 hours to your CSIRT and ENISA. This obligation applies from 11 September 2026.
Maintain the technical documentation, including a software bill of materials of your components, and keep it for ten years or the length of the support period.
Maximum fine
Full compliance deadline
Mandatory support period
Vulnerability reporting deadline
Our experts analyze your product portfolio and determine which CRA obligations apply to your organization.