CRA knowledge

The Cyber Resilience Act – explained concisely.

A primer for manufacturers of connected products: what it’s about, who it affects and why the important deadline comes sooner than many think.

What is the CRA about?

The Cyber Resilience Act (Regulation (EU) 2024/2847) is the EU’s first horizontal product cybersecurity law. It sets binding cybersecurity requirements for “products with digital elements” across their entire lifecycle – from development through security updates to technical documentation.

What are “products with digital elements”?

These are hardware and software products placed on the EU market that connect directly or indirectly to a device or network. This ranges from IoT devices and connected machines (OT) through embedded systems to software, apps and firmware components.

Who is responsible?

The CRA addresses manufacturers, importers and distributors. Many small companies are unaware that they qualify as a manufacturer under the regulation – and therefore carry the most extensive set of obligations, including the CE declaration of conformity.

No single tool makes you conformant

The CRA is mostly a process and documentation obligation. Tools can provide evidence for individual requirements but replace neither risk management nor the secure development process or the technical documentation.

Note: this page provides a general overview and does not constitute legal advice. The currently applicable text of the regulation is authoritative. Official information from the European Commission.

Deadlines

The CRA timeline – and why 2026 is the decisive year.

  1. The Cyber Resilience Act enters into force. The clock is ticking, still without immediate manufacturer obligations.
  2. Rules on the notification of conformity assessment bodies (Chapter IV) apply.
  3. relevant now
    Reporting obligations under Article 14: actively exploited vulnerabilities and severe incidents must be reported to ENISA and the national CSIRT – early warning within 24 hours, notification within 72 hours. Applies to existing products too.
  4. Full application: essential cybersecurity requirements, conformity assessment, CE marking and technical documentation.
Penalties: Infringements of the essential requirements can lead to fines of up to €15 million or 2.5% of worldwide annual turnover – whichever is higher.

Frequently asked

Briefly explained, without the jungle of paragraphs.

What is the Cyber Resilience Act?
An EU regulation (2024/2847) that sets binding cybersecurity requirements for connected products across their entire lifecycle – from development through security updates to technical documentation. It is the first horizontal product cybersecurity law of its kind.
Am I even affected as a small company?
Most likely yes, as soon as you place a product with digital elements on the EU market that connects to a network or devices. There are exceptions (e.g. certain medical devices). That’s exactly what we clarify in the applicability check.
What applies from when?
Reporting obligations for actively exploited vulnerabilities from 11 Sep 2026 – including existing products. The full requirements including CE marking apply from 11 Dec 2027. The frequently cited “2027 date” therefore hides the actually earlier first deadline.
What happens in case of non-conformity?
Market surveillance measures up to a sales ban, plus fines of up to €15 million or 2.5% of worldwide annual turnover – comparable in scale to the GDPR.
Is buying a tool enough?
No. The CRA is mostly a process and documentation obligation. Tools provide evidence for individual requirements but don’t make a product conformant on their own. This is exactly where we come in with processes, templates and a tooling concept.
We don’t have our own security team – now what?
No problem. That’s exactly why we exist: we translate the requirements into concrete, prioritised steps and support the implementation – at your team’s pace.

Unsure whether and how the CRA affects your product?

Free initial consultation Ask by email