Want to know more? Download the CRA factsheet

Want to know whether the CRA applies to your product, what obligations you need to meet, and how to prepare for the upcoming requirements? Download our factsheet for a clear overview of the regulation, its obligations, and the timeline.

Download CRA factsheet
Visual - CRA factsheet (ENG)

What is the Cyber Resilience Act (CRA)?

The CRA is a European regulation that sets cybersecurity requirements for products with digital elements offered on the EU market. 

The CRA applies to virtually all hardware and software that is connected, or can be connected, to the internet or a comparable digital network. This includes smart devices such as TVs, doorbells and baby monitors, as well as smartphones, smartwatches, laptops, tablets, e-readers, and all software installed or installable on them.

Four pillars of the CRA

  • Safer products: fewer vulnerabilities at market introduction.

  • Lifecycle approach: security throughout the entire support period or expected lifespan.

  • Transparency: users gain insight into cybersecurity characteristics and support period.

  • Incident response: actively exploited vulnerabilities and serious incidents are reported to supervisory authorities and (affected) users.

Vier pijlers van de CRA

What fines apply under the CRA?

The CRA imposes significant penalties:

  • Breach of essential requirements: A maximum fine of €15 million or 2.5% of global annual turnover
  • Breach of other obligations: A maximum fine of €10 million or 2% of global annual turnover
  • Incorrect or misleading information to notified bodies or market surveillance: A maximum fine of €5 million or 1% of global annual turnover

     

*Micro and small enterprises do not receive a fine for exceeding the 24-hour deadline.

When does the CRA take effect?

The CRA entered into force on 10 December 2024. New obligations will be introduced in phases. Full application of the CRA (conformity assessment, CE marking, technical documentation) takes effect on 11 December 2026.

Key  Provisions of the CRA

1. Product categories

The CRA distinguishes product categories with requirements for security and for demonstrating conformity, appropriate to the risks: default, important class I or II, and critical. The category determines the conformity route (internal control, external party or notified body, or certificate with at least "substantial" assurance level). For critical products, mandatory European cybersecurity certification may be prescribed via a delegated act.

2. Five roles under the CRA

The CRA typically distinguishes five key players (economic operators) in the digital product supply chain, each with their own legal obligations:

  • ·Manufacturer: develops (or commissions the development of) products placed on the market under its own name or trademark, or substantially modifies products.

  • Authorised representative: party representing a manufacturer established outside the EU.

  • Importer: places products from outside the EU on the market.

  • Distributor: makes products available without affecting their properties.

  • Open-source software steward: maintains open-source software without being a manufacturer.

3. Reporting obligation

Manufacturers must report actively exploited vulnerabilities and serious incidents to the competent CSIRT and to ENISA, via the Single Reporting Platform (SRP) that ENISA is establishing.

Informing users: in addition to reporting to CSIRT/ENISA, the manufacturer must inform affected users (and, where appropriate, all users) of the vulnerability or incident and of risk mitigation measures, preferably in a structured, machine-readable format such as a directly executable security update. Care must be taken to prevent the information from being misused by (other) malicious actors.

Voluntary reporting: manufacturers and other natural or legal persons may also voluntarily report vulnerabilities, cyber threats and incidents to CSIRTs. If someone other than the manufacturer reports, the CSIRT informs the manufacturer.

4. Notified bodies

Pursuant to Art. 71(2), the provisions on notification of conformity assessment bodies, referred to as "notified bodies", apply from 11 June 2026. This is particularly relevant for important and critical products: manufacturers must approach a notified body in good time for conformity assessment and CE marking.

Want to receive more information?

Leave a message using the form. One of our legal advisers will then get in touch with you.

When you submit a request, we always start with a no-obligation introductory meeting: by phone, at our office, or at your location.

Leave your details