Regulatory Framework

EU Cyber
Resilience Act

The EU Cyber Resilience Act mandates security-by-design for all products with digital elements sold in the EU market. Manufacturers must fulfil essential security requirements, complete a conformity assessment, issue a Declaration of Conformity, and affix CE marking. Full compliance is required by October 2027.

Regulation Overview

Type

EU Mandatory Regulation – Direct Application

In Force

10 December 2024

Full Compliance Deadline

October 2027

Market Access

CE marking via Declaration of Conformity

Certificate

No – Declaration of Conformity by manufacturer

Max Penalty

15 million EUR or 2.5% global turnover

October 2027 Deadline

Products placed on the EU market after October 2027 without CRA conformity will face market withdrawal by national surveillance authorities. Manufacturers of products with long development cycles need to start now.

What It Is

Understanding
the EU Cyber Resilience Act

The EU Cyber Resilience Act (EU 2024/2847) entered into force on 10 December 2024. It requires manufacturers of products with digital elements hardware and software to meet essential cybersecurity requirements before placing those products on the EU market. The full compliance deadline is October 2027.

The CRA covers any product with digital elements that can connect to another device or network. This includes embedded software in industrial equipment, connected sensors, routers, industrial control system components, and consumer IoT devices. The requirements apply to the product and to the manufacturer’s processes for vulnerability handling and security updates.

More About
EU Cyber Resilience Act

Unlike ISO 27001 or IEC 62443, the CRA does not result in a certificate from an accredited body. Compliance is demonstrated through a conformity assessment process, after which the manufacturer issues a Declaration of Conformity and affixes CE marking to the product. The CE mark is the market access mechanism. Without it, the product cannot be placed on the EU market.

The CRA introduces two categories of critical products like Class I and Class II with stricter conformity assessment requirements. Most connected products fall outside these classes and can self-certify. Class I products require third-party review of their technical documentation. Class II products require notified body involvement.

SUMMARY

Type

EU Mandatory Regulation – Direct Application

In Force

10 December 2024

Full Compliance Deadline

October 2027

Market Access Mechanism

CE marking via Declaration of Conformity

Certificate Issued

No – Declaration of Conformity by manufacturer

Max Penalty

15 million EUR or 2.5% global turnover

What the CRA covers

The CRA covers any product with digital elements that can connect to another device or network. This includes embedded software in industrial equipment, connected sensors, routers, industrial control system components, and consumer IoT devices. The requirements apply to the product and to the manufacturer’s processes for vulnerability handling and security updates.

Unlike ISO 27001 or IEC 62443, the CRA does not result in a certificate from an accredited body. Compliance is demonstrated through a conformity assessment process, after which the manufacturer issues a Declaration of Conformity and affixes CE marking to the product. The CE mark is the market access mechanism. Without it, the product cannot be placed on the EU market.

Oct 2027

Full compliance deadline for all manufacturers placing products with digital elements on the EU market.

Class I & II

Two categories of critical products with stricter conformity assessment requirements than standard self-certification.

CE Mark

The market access mechanism. Without CE marking your product cannot be legally placed on the EU market.

Who is affected

The CRA applies across the supply chain. Manufacturers bear primary obligations, but importers and distributors also have specific duties to verify conformity before making products available on the EU market.

Manufacturer

Connected Product Manufacturers

Any manufacturer placing a product with digital elements on the EU market bears primary CRA obligations. This includes industrial equipment makers, sensor manufacturers, control system component suppliers, and software developers.

Importer

EU Importers of Connected Products

Importers placing non-EU manufactured products on the EU market must verify that the manufacturer has fulfilled CRA obligations and must act when they know a product is not compliant.

Distributor

EU Distributors and Resellers

Distributors must verify CE marking before making products available on the market and must not make available products they know are non-compliant, and ensure required documentation and instructions are provided.

Critical product classes

Standard Products

Self-Certification

Most connected products fall outside Class I and Class II categories and can follow a self-certification path. The manufacturer conducts their own conformity assessment against Annex I requirements.

Class I Products

Third-Party Documentation

Class I products require third-party review of their technical documentation. This applies to products considered to pose higher cybersecurity risks under the regulation’s classification criteria.

Class II Products

Notified Body Involvement

Class II products require involvement of a notified body in the conformity assessment. These products are considered critical and face the most stringent assessment requirements under the regulation.

Key requirements

CRA Annex I defines essential cybersecurity requirements in two parts: security properties the product must have, and vulnerability handling obligations manufacturers must fulfil throughout the product lifecycle.

Art.Annex I Part 1

Security by Design Requirements

Products must be delivered without known exploitable vulnerabilities, with a secure default configuration, protection against unauthorised access, data protection, minimal attack surface, and resilience against denial of service attacks.

Mandatory

Art.Annex I Part 1(2)

Confidentiality and Integrity

Products must protect data at rest and in transit, with secure access controls, strong encryption, data minimisation, protection against unauthorised disclosure, and resilience against data compromise, while maintaining data accuracy and preventing unauthorised alteration or corruption.

Mandatory

Art.Annex I Part 2(1)

Vulnerability Identification and Documentation

Manufacturers must identify and document vulnerabilities and components contained in products, including a software bill of materials in a machine-readable format.

Mandatory

Art.Annex I Part 2(2)

Security Updates for Minimum 5 Years

Manufacturers must address vulnerabilities without delay and provide security updates separately from functionality updates for a minimum of five years or the expected product lifecycle.

Mandatory

Art.13

Technical Documentation

Manufacturers must draw up technical documentation before placing the product on the market. It must enable conformity assessment and be kept for ten years after product placement.

Mandatory

Art.14

Actively Exploited Vulnerability Reporting

Manufacturers must notify ENISA within 24 hours of becoming aware of an actively exploited vulnerability in their product, providing information to support assessment, coordination, mitigation, and timely response to the threat.

24h Reporting

15M EUR

Maximum Penalty – or 2.5% of Global Annual Turnover

The CRA sets maximum penalties of 15 million EUR or 2.5 percent of global annual turnover for violations of the essential requirements. Market surveillance authorities can also require products to be withdrawn from the market or recalled without financial penalty, which for a product-dependent business is often a more significant consequence than the fine.

Conformity assessment and CE marking

Unlike ISO 27001 or IEC 62443, the CRA does not result in a certificate from an accredited body. CE marking is the market access mechanism.

Compliance is demonstrated through a conformity assessment process, after which the manufacturer issues a Declaration of Conformity and affixes CE marking to the product. The CE mark is the market access mechanism. Without it, the product cannot be placed on the EU market. The pathway for your products depends on their classification: standard, Class I, or Class II.

  • Product portfolio scope and classification analysis
  • Annex I gap assessment against current product state
  • Technical file and Declaration of Conformity preparation
  • Support for third-party or notified body engagement

How we deliver CRA engagements

We help manufacturers assess their product portfolio against CRA Annex I requirements, define the conformity assessment pathway, and prepare the Declaration of Conformity documentation and technical file.

Step 1 – Scope

Product Scope and Classification

We identify which of your products fall within CRA scope, classify them as standard, Class I, or Class II products, and determine the applicable conformity assessment route for each.

Output: CRA product scope map with classification and conformity pathway per product

Step 2 – Gap Assessment

Annex I Readiness Assessment

We assess each in-scope product against all Annex I Part 1 and Part 2 requirements and produce a gap report with remediation priorities sequenced by enforcement risk.

Output: CRA Annex I gap report with prioritised finding register per product

Step 3 – Remediate

Technical Remediation and Process Design

We support your engineering and product teams in closing Annex I gaps including secure default configuration, vulnerability management process design, and SBOM implementation.

Output: Closed Annex I gaps with documented evidence and vulnerability handling process

Step 4 – Conform

Declaration of Conformity and CE Marking

We prepare the Article 13 technical documentation file and the Declaration of Conformity, enabling your products to carry CE marking and enter the EU market without regulatory challenge.

Output: Technical documentation file and Declaration of Conformity per product

Related

Connected frameworks
and services

Service

EU Digital Regulation Programme

Explore →

Regulation

IEC 62443

Explore →

Regulation

NIS2 Directive

Explore →

Start with a 30-minute discovery call

We scope your CRA product obligations and define the fastest path to CE marking. Book a 30-minute discovery call. We help manufacturers assess their product portfolio against CRA Annex I requirements, define the conformity assessment pathway, and prepare the Declaration of Conformity documentation and technical file.

You leave with:

  • Your product scope classification
  • Your Annex I gap summary
  • Your conformity assessment pathway
Scroll to Top