CRA knowledge
The Cyber Resilience Act – explained concisely.
A primer for manufacturers of connected products: what it’s about, who it affects and why the important deadline comes sooner than many think.
What is the CRA about?
The Cyber Resilience Act (Regulation (EU) 2024/2847) is the EU’s first horizontal product cybersecurity law. It sets binding cybersecurity requirements for “products with digital elements” across their entire lifecycle – from development through security updates to technical documentation.
What are “products with digital elements”?
These are hardware and software products placed on the EU market that connect directly or indirectly to a device or network. This ranges from IoT devices and connected machines (OT) through embedded systems to software, apps and firmware components.
Who is responsible?
The CRA addresses manufacturers, importers and distributors. Many small companies are unaware that they qualify as a manufacturer under the regulation – and therefore carry the most extensive set of obligations, including the CE declaration of conformity.
No single tool makes you conformant
The CRA is mostly a process and documentation obligation. Tools can provide evidence for individual requirements but replace neither risk management nor the secure development process or the technical documentation.
Note: this page provides a general overview and does not constitute legal advice. The currently applicable text of the regulation is authoritative. Official information from the European Commission.
Deadlines
The CRA timeline – and why 2026 is the decisive year.
- The Cyber Resilience Act enters into force. The clock is ticking, still without immediate manufacturer obligations.
- Rules on the notification of conformity assessment bodies (Chapter IV) apply.
- relevant nowReporting obligations under Article 14: actively exploited vulnerabilities and severe incidents must be reported to ENISA and the national CSIRT – early warning within 24 hours, notification within 72 hours. Applies to existing products too.
- Full application: essential cybersecurity requirements, conformity assessment, CE marking and technical documentation.
Frequently asked
Briefly explained, without the jungle of paragraphs.
What is the Cyber Resilience Act?
Am I even affected as a small company?
What applies from when?
What happens in case of non-conformity?
Is buying a tool enough?
We don’t have our own security team – now what?
Unsure whether and how the CRA affects your product?