LinkedInInstagramXTikTok

The EU Cyber Resilience Act: what companies need to know

Why the Cyber Resilience Act matters now

The EU Cyber Resilience Act (Regulation (EU) 2024/2847), or CRA, is the first EU-wide law to set binding cybersecurity requirements for products with digital elements – from connected consumer devices to business software. It entered into force on 10 December 2024, and its obligations are now being phased in. The first major deadline is close: from 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents. The main obligations follow on 11 December 2027.

If your company develops, imports or sells hardware or software with any digital component, the CRA will affect you. This article explains what the regulation requires, who is covered, the timeline you need to plan around, and the practical steps to take now.

What is the Cyber Resilience Act?

The CRA sets essential cybersecurity requirements for “products with digital elements” placed on the EU market. In plain terms, that covers almost any product that can connect to a device or network – software applications, operating systems, connected appliances, industrial control systems, mobile apps and more. The goal is to make security a built-in feature across a product’s entire lifecycle, rather than an afterthought, and to give buyers clearer information about the products they use.

Unlike NIS2, which governs how essential and important organisations manage their own network and information security, the CRA regulates the products themselves. The two frameworks complement each other: NIS2 addresses organisational security, while the CRA addresses product security.

Who is covered?

The obligations are distributed across the supply chain, but manufacturers carry the primary responsibility. A manufacturer is anyone who develops or produces a product with digital elements, or has one developed, and places it on the market under their own name or trademark. Importers must verify that the products they bring into the EU meet the requirements and carry the CE marking, and distributors must act with due care and check that the marking and documentation are present. Even open-source software can fall within scope where it is supplied commercially.

The most important requirements

Security by design and by default

Products must be designed, developed and produced so that they deliver an appropriate level of cybersecurity based on the risks. That means shipping without known exploitable vulnerabilities, secure default settings, protection of data confidentiality and integrity, and minimising the attack surface. Security cannot be bolted on at the end – it has to be engineered in from the start.

Vulnerability handling throughout the lifecycle

Manufacturers must identify and address vulnerabilities for the expected product lifetime, or at least five years, whichever is shorter. This includes providing security updates – free of charge and, where possible, automatically – and maintaining a coordinated vulnerability-disclosure policy. Manufacturers must also draw up a software bill of materials (SBOM) documenting the components in their products.

Reporting of vulnerabilities and incidents

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents through a single reporting platform to the relevant national CSIRT and to ENISA. Reporting follows three stages: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report once the issue is resolved. Fast, structured reporting is designed to help authorities monitor emerging threats and coordinate a response.

Conformity assessment and CE marking

Products are grouped by risk into default, important (Class I and Class II) and critical categories. Most default products can be self-assessed by the manufacturer, while important and critical products generally require assessment involving an independent notified body. Compliance is demonstrated through a conformity assessment, an EU declaration of conformity and the CE marking, supported by technical documentation.

The timeline you need to plan around

The CRA entered into force on 10 December 2024. The reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026. The remaining main obligations – including the essential cybersecurity requirements, conformity assessment and CE marking – apply from 11 December 2027. In practice, 2026 and 2027 are the years to get ready, because building secure-by-design processes, vulnerability handling and documentation takes time.

Practical example

Imagine a Swedish company that makes smart home sensors with an accompanying mobile app. Under the CRA it is a manufacturer of a product with digital elements. It must ship the sensors free of known exploitable vulnerabilities, provide security updates for the expected lifetime, publish a vulnerability-disclosure policy, and prepare a software bill of materials. From September 2026, if a vulnerability in its app is being actively exploited, it must issue an early warning within 24 hours. To sell inside the EU from December 2027, the product must carry the CE marking backed by a conformity assessment and technical documentation. The company that starts building these processes in 2026 will find the 2027 deadline manageable rather than disruptive.

Common mistakes companies make

The first mistake is assuming the CRA is only about hardware; software products and even certain commercial open-source components are squarely in scope. The second is treating it as a one-off compliance project rather than an ongoing obligation – vulnerability handling and updates run for the whole product lifecycle. The third is underestimating the documentation burden: without a software bill of materials, clear technical documentation and a disclosure policy, demonstrating conformity becomes very difficult. The fourth is leaving classification too late, since important and critical products may need an independent notified body with limited capacity.

Recommended actions

Start by mapping which of your products fall within scope and how each should be classified. Review your development processes against the security-by-design requirements and close obvious gaps. Establish a vulnerability-handling process, a coordinated disclosure policy and a routine for producing a software bill of materials. Set up an internal procedure so you can meet the 24-hour, 72-hour and final-report deadlines before September 2026. Finally, plan your conformity-assessment route and technical documentation well ahead of the December 2027 deadline, and factor in lead times if a notified body is required.

Frequently asked questions

When does the Cyber Resilience Act start to apply?

The regulation entered into force on 10 December 2024. Reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, and the main obligations apply from 11 December 2027.

Does the CRA apply to software as well as hardware?

Yes. The CRA covers products with digital elements, which includes standalone software such as applications and operating systems, not only physical devices. Certain commercial open-source software can also fall within scope.

What are the penalties for non-compliance?

Breaches of the essential cybersecurity requirements or the core manufacturer obligations can lead to fines of up to €15 million or 2.5 per cent of total worldwide annual turnover, whichever is higher. Lower ceilings apply to other breaches.

Conclusion

The Cyber Resilience Act makes cybersecurity a baseline requirement for products sold in the EU, and its deadlines are approaching quickly. With reporting obligations from September 2026 and the main requirements from December 2027, the companies that map their products, build secure-by-design processes and organise their documentation now will be well placed – while those who wait risk a rushed and costly scramble.

Lawgent helps companies navigate cybersecurity regulation and compliance using law and AI. Want to understand how the Cyber Resilience Act affects your specific products and how to prepare in practice? Get in touch with Lawgent and we will help you get started.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop