Glossary · simply explained

Cyber Resilience Act (CRA)

The Cyber Resilience Act (CRA) is the EU regulation for the cybersecurity of products with digital elements — from connected hardware to pure software. It obliges manufacturers to ensure security across the entire product lifecycle: security by design, vulnerability management and free security updates throughout the support period.

New is the lever: without CRA conformity no CE marking — and thus no EU market access. Cybersecurity turns from a quality feature into a market admission condition; the duties phase in until the end of 2027.

What the CRA requires of manufacturers

Products must ship with secure defaults and reach the market without known exploitable vulnerabilities; a risk assessment and technical documentation are part of conformity. Throughout the support period, vulnerabilities must be actively handled and updates provided — including a coordinated disclosure channel for security researchers.

On top come sharp reporting duties: actively exploited vulnerabilities and severe incidents must be pre-notified within 24 hours to ENISA and national bodies respectively. For important and critical product classes, stricter conformity procedures up to third-party assessment apply.

Who the CRA affects — and how to prepare

  • Manufacturers of connected products and software for the EU market — including those based outside the EU.
  • Importers and distributors with their own verification duties in the chain.
  • Preparation: build SBOM and vulnerability processes, secure update capability over years.
  • Buyers benefit: CRA conformity becomes a selection criterion for secure products.

Frequently asked questions about Cyber Resilience Act (CRA)

Which products fall under the CRA?

In principle all products with digital elements that can have a data connection — hardware and software, from routers to applications. Areas with their own regimes are exempt, such as medical devices or vehicles; pure SaaS services fall under it only in special cases.

When do the CRA duties apply?

Phased: the reporting duties for actively exploited vulnerabilities apply from 2026, the full product requirements from late 2027. Anyone building products with long development cycles effectively has to plan the requirements into current developments now.

What does security by design mean concretely in the CRA?

Security as a design requirement: secure defaults, minimised attack surfaces, protection of confidentiality and integrity, hardening against known attack classes — documented via a risk assessment that belongs to the technical documentation of CE conformity.

What role does an SBOM play in the CRA?

The software bill of materials — the machine-readable inventory of all components — is part of the documentation duties and the basis of working vulnerability management: only those who know their components can react to CVEs in dependencies.

What does the CRA mean for companies as buyers?

Tailwind: CE-conformant products will come with assured update periods, vulnerability processes and security documentation. CRA conformity can be anchored as a criterion in tenders — and supply chain risk drops structurally.

Want to put this into practice in your own network? Talk to KAEMI, aligned to your requirements and with a managed service from a single source.