The Cyber Resilience Act is a European regulation that sets cybersecurity requirements for products with digital elements offered on the EU market. The CRA applies to virtually all hardware and software that is connected, or can be connected, to the internet or a comparable digital network.
Want to know whether the CRA applies to your product, what obligations you need to meet, and how to prepare for the upcoming requirements? Download our factsheet for a clear overview of the regulation, its obligations, and the timeline.
Download CRA factsheetThe CRA is a European regulation that sets cybersecurity requirements for products with digital elements offered on the EU market.
The CRA applies to virtually all hardware and software that is connected, or can be connected, to the internet or a comparable digital network. This includes smart devices such as TVs, doorbells and baby monitors, as well as smartphones, smartwatches, laptops, tablets, e-readers, and all software installed or installable on them.
Safer products: fewer vulnerabilities at market introduction.
Lifecycle approach: security throughout the entire support period or expected lifespan.
Transparency: users gain insight into cybersecurity characteristics and support period.
Incident response: actively exploited vulnerabilities and serious incidents are reported to supervisory authorities and (affected) users.
The CRA imposes significant penalties:
*Micro and small enterprises do not receive a fine for exceeding the 24-hour deadline.
The CRA entered into force on 10 December 2024. New obligations will be introduced in phases. Full application of the CRA (conformity assessment, CE marking, technical documentation) takes effect on 11 December 2026.
The CRA distinguishes product categories with requirements for security and for demonstrating conformity, appropriate to the risks: default, important class I or II, and critical. The category determines the conformity route (internal control, external party or notified body, or certificate with at least "substantial" assurance level). For critical products, mandatory European cybersecurity certification may be prescribed via a delegated act.
The CRA typically distinguishes five key players (economic operators) in the digital product supply chain, each with their own legal obligations:
·Manufacturer: develops (or commissions the development of) products placed on the market under its own name or trademark, or substantially modifies products.
Authorised representative: party representing a manufacturer established outside the EU.
Importer: places products from outside the EU on the market.
Distributor: makes products available without affecting their properties.
Open-source software steward: maintains open-source software without being a manufacturer.
Manufacturers must report actively exploited vulnerabilities and serious incidents to the competent CSIRT and to ENISA, via the Single Reporting Platform (SRP) that ENISA is establishing.
Informing users: in addition to reporting to CSIRT/ENISA, the manufacturer must inform affected users (and, where appropriate, all users) of the vulnerability or incident and of risk mitigation measures, preferably in a structured, machine-readable format such as a directly executable security update. Care must be taken to prevent the information from being misused by (other) malicious actors.
Voluntary reporting: manufacturers and other natural or legal persons may also voluntarily report vulnerabilities, cyber threats and incidents to CSIRTs. If someone other than the manufacturer reports, the CSIRT informs the manufacturer.
Pursuant to Art. 71(2), the provisions on notification of conformity assessment bodies, referred to as "notified bodies", apply from 11 June 2026. This is particularly relevant for important and critical products: manufacturers must approach a notified body in good time for conformity assessment and CE marking.