The Cyber Resilience Act (CRA) is the EU regulation for the cybersecurity of products with digital elements — from connected hardware to pure software. It obliges manufacturers to ensure security across the entire product lifecycle: security by design, vulnerability management and free security updates throughout the support period.
New is the lever: without CRA conformity no CE marking — and thus no EU market access. Cybersecurity turns from a quality feature into a market admission condition; the duties phase in until the end of 2027.
What the CRA requires of manufacturers
Products must ship with secure defaults and reach the market without known exploitable vulnerabilities; a risk assessment and technical documentation are part of conformity. Throughout the support period, vulnerabilities must be actively handled and updates provided — including a coordinated disclosure channel for security researchers.
On top come sharp reporting duties: actively exploited vulnerabilities and severe incidents must be pre-notified within 24 hours to ENISA and national bodies respectively. For important and critical product classes, stricter conformity procedures up to third-party assessment apply.
Who the CRA affects — and how to prepare
- Manufacturers of connected products and software for the EU market — including those based outside the EU.
- Importers and distributors with their own verification duties in the chain.
- Preparation: build SBOM and vulnerability processes, secure update capability over years.
- Buyers benefit: CRA conformity becomes a selection criterion for secure products.