Cette page est disponible uniquement en anglais

Blog
20.07.2026
Understanding the EU's approach to product cybersecurity

The Cyber Resilience Act (CRA) marks a significant shift in EU cybersecurity regulation. Until now, EU cybersecurity law focused primarily on the operators and providers of digital services and infrastructure. In contrast, the CRA focuses on the products themselves: software, hardware, and any connected device placed on the EU market must now meet binding cybersecurity requirements throughout their lifecycle. This guide sets out the CRA's key obligations and outlines practical steps towards compliance.

What is the CRA?

Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024, also known as the "Cyber Resilience Act", establishes horizontal cybersecurity requirements (i) for the making available on the market of products with digital elements, (ii) for the design, development and production of those products, (iii) for vulnerability handling processes, and (iv) on market surveillance and enforcement.

In practical terms, the CRA introduces a product safety regime for cybersecurity. Just as a physical product must meet health and safety standards before it can be sold in the EU, a connected product (whether a router, a password manager, industrial control software, or a smart home device) must now meet essential cybersecurity requirements before it can carry the CE marking and be placed on the EU market.

Who must comply with the CRA?

The Regulation applies to products with digital elements which includes a direct or indirect logical or physical data connection to a device or network and that made available on the EU market.

A "product with digital elements" means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately. This is a broad definition that captures connected consumer electronics, industrial software, cybersecurity tools, cloud-connected devices, and components sold individually.

The CRA creates three tiers of products, each with different conformity assessment requirements:

1. Default products → most products with digital elements, subject to a self-assessment process (internal control, module A).

2. Important products → products with digital elements which have the core functionality of a category set out in Annex III, divided into Class I and Class II, where the product primarily performs functions critical to cybersecurity or performs a function carrying a significant risk of disruption to a large number of systems or users. Class I examples from Annex III include:

  • Identity management systems, standalone and embedded browsers, password managers, anti-malware software, VPN products, and network management systems.
  • Operating systems, routers and modems intended for internet connection, smart home general-purpose virtual assistants, and smart home products with security functionalities including smart door locks and security cameras.

Class II examples include:

  • Hypervisors and container runtime systems, firewalls, intrusion detection and prevention systems, and tamper-resistant microprocessors and microcontrollers.

3. Critical products → listed in Annex IV and including hardware devices with security boxes, smart meter gateways within smart metering systems, and smartcards or similar devices, including secure elements. Critical products face the highest level of scrutiny, potentially requiring a European cybersecurity certificate.

As regards open-source software, the CRA only applies where free open-source software is made available in the course of a commercial activity. Open-source software stewards are subject to lighter, tailored obligations, while manufacturers integrating open-source components must exercise due diligence to ensure those components do not compromise product cybersecurity.

What is excluded?

Several product categories are excluded from the CRA's scope:

  • Products already covered by specific EU sectoral legislation, namely medical devices under Regulation (EU) 2017/745, diagnostic medical devices under Regulation (EU) 2017/746, and vehicles under Regulation (EU) 2019/2144.
  • Products with digital elements that have been certified in accordance with Regulation (EU) 2018/1139 (civil aviation).
  • Equipment that falls within the scope of Directive 2014/90/EU on marine equipment.
  • Products with digital elements developed or modified exclusively for national security or defence purposes or specifically designed to process classified information.
  • Spare parts made available to replace identical components in products with digital elements and manufactured according to the same specifications as those they replace.

Where other EU rules address all or some of the same cybersecurity risks, the application of the CRA may be limited or excluded, provided that such limitation is consistent with the overall regulatory framework and the sectoral rules achieve the same or a higher level of protection.

How and when will the CRA apply?

The CRA is a Regulation and therefore directly applicable in all EU Member States without requiring national transposition. The key dates are:

  • 10 December 2024 → entry into force (twenty days after publication in the Official Journal on 20 November 2024).
  • 11 June 2026 → Chapter IV (Articles 35 to 51, concerning notification of conformity assessment bodies) applies from this date.
  • 11 September 2026 → Article 14 (reporting obligations for manufacturers regarding actively exploited vulnerabilities and severe incidents) applies from this date.
  • 11 December 2027 → The Regulation applies in full from this date.

Certain products with digital elements enjoy transition exemptions, such as those that have been placed on the market before 11 December 2027. These will only be subject to the CRA's requirements if, from that date, those products are subject to a substantial modification. However, they are not exempted from all obligations: reporting obligations, for instance, are still to be complied with.

Key obligations

The following key obligations apply under the CRA:

  • Essential cybersecurity requirements → Annex I of the CRA sets out the essential cybersecurity requirements in two parts. Part I requires that products are designed, developed and produced to ensure an appropriate level of cybersecurity based on the risks. Key requirements include making products available without known exploitable vulnerabilities, shipping with a secure by default configuration, enabling automatic security updates with a user opt-out, protecting data confidentiality and integrity, implementing access controls, and minimising attack surfaces. Part II imposes vulnerability handling obligations on manufacturers, including drawing up a software bill of materials (SBOM), remediating vulnerabilities without delay, applying regular security testing, publicly disclosing fixed vulnerabilities, and putting in place a coordinated vulnerability disclosure policy.
  • Vulnerability reporting obligations → Manufacturers must report actively exploited vulnerabilities and severe security incidents simultaneously to the CSIRT designated as coordinator and to ENISA via a single reporting platform. For both categories, an early warning must be submitted within 24 hours, followed by a more detailed notification within 72 hours. A final report is due within 14 days of a corrective measure becoming available (for vulnerabilities) or within one month of the initial notification (for incidents). Manufacturers must also inform impacted users of the vulnerability or incident and of any corrective measures they can deploy.
  • Support periods → Manufacturers must determine a support period reflecting the expected use time of the product, with a minimum of five years. The end date of the support period must be clearly communicated to purchasers at the time of sale. Each security update made available during the support period must remain available for at least 10 years or for the remainder of the support period, whichever is longer.
  • CE marking and EU declaration of conformity → Products that comply with the CRA's essential cybersecurity requirements must bear the CE marking before being placed on the market. Manufacturers must draw up an EU declaration of conformity and retain it, together with the technical documentation, for at least 10 years after the product has been placed on the market or for the support period, whichever is longer.
  • Technical documentation → Manufacturers must draw up technical documentation before placing a product on the market and keep it updated throughout the support period. The documentation must cover the product's design and development, the cybersecurity risk assessment, vulnerability handling processes (including the SBOM), and the results of conformity testing.
  • Conformity assessments procedures → The conformity assessment route depends on the product's risk classification. Default products may use a self-assessment (internal control, Module A). Important products (Class I) must use third-party assessment where harmonised standards have not been fully applied, while Class II products must always undergo third-party assessment or hold a European cybersecurity certificate. Critical products face the highest scrutiny, potentially requiring a European cybersecurity certificate under a scheme adopted pursuant to Regulation (EU) 2019/881.
  • Information and instructions to users → Manufacturers must ensure that products are accompanied by clear and accessible information for users, including the manufacturer's contact details, a single point of contact for vulnerability reporting, the end date of the support period, and instructions for secure installation, use and decommissioning of the product.

Supervision and enforcement

The CRA establishes a three-tier penalty framework, with administrative fines of up to EUR 15,000,000 or 2.5% of total worldwide annual turnover for non-compliance with the essential cybersecurity requirements and core manufacturer obligations, up to EUR 10,000,000 or 2% for breaches of other obligations (e.g. relating to importers, distributors, conformity assessment and technical documentation), and up to EUR 5,000,000 or 1% for supplying incorrect or misleading information to notified bodies or market surveillance authorities. There are certain exceptions for microenterprises or small enterprises.

Interplay with other EU legislation

The CRA expressly excludes product categories already covered by dedicated EU cybersecurity rules, such as medical devices, civil aviation products and marine equipment. The Commission may adopt delegated acts to further limit or exclude the CRA's application, meaning the CRA's scope may evolve over time.

The CRA may also overlap with other legislative pieces. For instance, financial entities that manufacture or market products with digital elements – such as payment institutions issuing card readers or banks offering mobile banking applications – may qualify as manufacturers under the CRA and face its full set of obligations alongside their existing requirements under DORA. Where both regimes apply concurrently, those entities must navigate potentially overlapping duties in areas such as vulnerability handling, incident reporting and security testing.

Another example is the interplay with the AI Act: products classified as high-risk AI systems that comply with the CRA's essential cybersecurity requirements are deemed to also meet the cybersecurity requirements of the AI Act. The CRA is also complementary to NIS2, as the CRA regulates the security of the products they use, while NIS2 regulates the cybersecurity obligations of operators and service providers, with both frameworks sharing the same CSIRT and ENISA reporting infrastructure.

Why the CRA matters for your business

The CRA's reach is broader than many organisations expect. Because CRA compliance is tied to CE marking, a failure to meet the essential cybersecurity requirements directly impacts market access. Products that cannot be lawfully CE-marked cannot be placed on the EU market, and non-compliant products may also be excluded from public procurement processes.

Additionally, the CRA reshapes how products are designed, contracted for, and maintained. Product release processes must now account for conformity assessment gates. Commercial contracts (both upstream with component suppliers and downstream with customers) will need to be updated, distribution models for non-EU manufacturers reviewed, the mandatory five-year (minimum) support period accounted for, and – if not already done – an incident response policy should be implemented.

In short, the CRA matters even for organisations that fall outside NIS2 and do not process personal data under the GDPR. It governs whether a product can legally be sold in the EU, what ongoing security commitments must be honoured, and how an organisation must respond when vulnerabilities are actively exploited across the entire supply chain.

Preparing for the CRA

The CRA applies in full from 11 December 2027, but vulnerability reporting obligations apply from September 2026. In order to ensure timely compliance, organisations should:

  1. Assess whether their products fall within scope and determine their risk classification; conduct cybersecurity risk assessments and embed security-by-design principles;
  2. Establish vulnerability management processes, including an SBOM, a coordinated vulnerability disclosure policy and a single point of contact;
  3. Build internal workflows to meet the 24-hour and 72-hour reporting deadlines via ENISA's single reporting platform;
  4. Determine and communicate support periods (minimum five years);
  5. Prepare technical documentation and the EU declaration of conformity;
  6. Identify the applicable conformity assessment route and, for important or critical products, engage with notified bodies early;
  7. Ensure importers and distributors verify manufacturer compliance before making products available on the EU market; and
  8. Monitor delegated and implementing acts, including updates to the Annex III product categories and Commission guidance.

For further guidance on how the CRA applies to your organisation, products or supply chain, or what steps should be taken to prepare for compliance, please contact our team.

Notification de cookies

Cette fonctionnalité utilise des cookies tiers. Modifiez votre cookie préférences pour visualiser ce contenu ou afficher plus d'informations.
Ces cookies assurent le bon fonctionnement du site. Ces cookies ne peuvent pas être désactivés.
Ces cookies peuvent être placés par des tiers, tels que YouTube ou Vimeo.
En désactivant certaines catégories, les fonctionnalités associées au sein du site risquent de ne plus fonctionner correctement. Vous pouvez modifier vos préférences ultérieurement. Voir plus d'informations.