Regulatory Framework

EU Cyber Resilience
Act Compliance

EU Cyber Resilience Act compliance requires manufacturers of products with digital elements to meet essential cybersecurity requirements before placing products on the EU market. The CRA introduces security-by-design obligations, vulnerability handling requirements, conformity assessment procedures, and CE marking requirements. Its main obligations apply from 11 December 2027.

Regulation Overview

Type

EU Mandatory Regulation – Direct Application

In Force

10 December 2024

Full Compliance Deadline

11 December 2027

Market Access

CE marking via Declaration of Conformity

Certificate

No – Declaration of Conformity by manufacturer

Max Penalty

EUR 15M or 2.5% global turnover

11 December 2027 Main Application Date

The main CRA obligations apply from 11 December 2027. Manufacturers with products in scope should prepare product classification, Annex I gap assessments, vulnerability handling processes, technical documentation, and conformity assessment well before the applicable date.

What It Is

What Is the EU Cyber Resilience Act?

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024. It establishes cybersecurity requirements for products with digital elements across their lifecycle, including secure design, vulnerability handling, security updates, technical documentation, and conformity assessment. The main obligations apply from 11 December 2027.

The CRA covers any product with digital elements that can connect to another device or network. This includes embedded software in industrial equipment, connected sensors, routers, industrial control system components, and consumer IoT devices. The requirements apply to the product and to the manufacturer’s processes for vulnerability handling and security updates.

More About
EU Cyber Resilience Act

Unlike ISO 27001 or IEC 62443, the CRA does not result in a certificate from an accredited body. Compliance is demonstrated through a conformity assessment process, after which the manufacturer issues a Declaration of Conformity and affixes CE marking to the product. The CE mark is the market access mechanism. Without it, the product cannot be placed on the EU market.

The CRA introduces two categories of critical products like Class I and Class II with stricter conformity assessment requirements. Most connected products fall outside these classes and can self-certify. Class I products require third-party review of their technical documentation. Class II products require notified body involvement.

SUMMARY

Type

EU Mandatory Regulation – Direct Application

In Force

10 December 2024

Full Compliance Deadline

11 December 2027

Market Access Mechanism

CE marking via Declaration of Conformity

Certificate Issued

No – Declaration of Conformity by manufacturer

Max Penalty

EUR 15M or 2.5% global turnover

What Products Does the Cyber Resilience Act Cover?

The CRA covers any product with digital elements that can connect to another device or network. This includes embedded software in industrial equipment, connected sensors, routers, industrial control system components, and consumer IoT devices. The requirements apply to the product and to the manufacturer’s processes for vulnerability handling and security updates.

Unlike ISO 27001 or IEC 62443, the CRA does not result in a certificate from an accredited body. Compliance is demonstrated through a conformity assessment process, after which the manufacturer issues a Declaration of Conformity and affixes CE marking to the product. The CE mark is the market access mechanism. Without it, the product cannot be placed on the EU market.

11 Dec 2027

Main application date for all manufacturers placing products with digital elements on the EU market.

Class I & II

Two categories of critical products with stricter conformity assessment requirements than standard self-certification.

CE Mark

The market access mechanism. Without CE marking your product cannot be legally placed on the EU market.

Who Must Comply With the Cyber Resilience Act?

The CRA applies across the supply chain. Manufacturers bear primary obligations, but importers and distributors also have specific duties to verify conformity before making products available on the EU market.

Manufacturer

Connected Product Manufacturers

Any manufacturer placing a product with digital elements on the EU market bears primary CRA obligations. This includes industrial equipment makers, sensor manufacturers, control system component suppliers, and software developers.

Importer

EU Importers of Connected Products

Importers placing non-EU manufactured products on the EU market must verify that the manufacturer has fulfilled CRA obligations and must act when they know a product is not compliant.

Distributor

EU Distributors and Resellers

Distributors must verify CE marking before making products available on the market and must not make available products they know are non-compliant, and ensure required documentation and instructions are provided.

Cyber Resilience Act Product Classes and Conformity Assessment

Standard Products

Self-Certification

Most connected products fall outside Class I and Class II categories and can follow a self-certification path. The manufacturer conducts their own conformity assessment against Annex I requirements.

Class I Products

Third-Party Documentation

Class I products require third-party review of their technical documentation. This applies to products considered to pose higher cybersecurity risks under the regulation’s classification criteria.

Class II Products

Notified Body Involvement

Class II products require involvement of a notified body in the conformity assessment. These products are considered critical and face the most stringent assessment requirements under the regulation.

Cyber Resilience Act Requirements: Annex I

CRA Annex I defines essential cybersecurity requirements in two parts: security properties the product must have, and vulnerability handling obligations manufacturers must fulfil throughout the product lifecycle.

Art.Annex I Part 1

Security by Design Requirements

Products must be delivered without known exploitable vulnerabilities, with a secure default configuration, protection against unauthorised access, data protection, minimal attack surface, and resilience against denial of service attacks.

Mandatory

Art.Annex I Part 1(2)

Confidentiality and Integrity

Products must protect data at rest and in transit, with secure access controls, strong encryption, data minimisation, protection against unauthorised disclosure, and resilience against data compromise, while maintaining data accuracy and preventing unauthorised alteration or corruption.

Mandatory

Art.Annex I Part 2(1)

Vulnerability Identification and Documentation

Manufacturers must identify and document vulnerabilities and components contained in products, including a software bill of materials in a machine-readable format.

Mandatory

Art.Annex I Part 2(2)

Security Updates for Minimum 5 Years

Manufacturers must address vulnerabilities without delay and provide security updates separately from functionality updates for a minimum of five years or the expected product lifecycle.

Mandatory

Art.13

Technical Documentation

Manufacturers must draw up technical documentation before placing the product on the market. It must enable conformity assessment and be kept for ten years after product placement.

Mandatory

Art.14

Actively Exploited Vulnerability Reporting

Manufacturers must notify ENISA within 24 hours of becoming aware of an actively exploited vulnerability in their product, providing information to support assessment, coordination, mitigation, and timely response to the threat.

24h Reporting

EUR 15M

Maximum Penalty – or 2.5% of Global Annual Turnover

The CRA provides for maximum administrative fines of EUR 15 million or 2.5 percent of the undertaking’s total worldwide annual turnover for certain infringements of the essential cybersecurity requirements, whichever is higher. Market surveillance authorities may also take corrective enforcement measures, including requiring non-compliant products to be withdrawn or recalled.

Cyber Resilience Act CE Marking and Conformity Assessment

Unlike ISO 27001 or IEC 62443, the CRA does not result in a certificate from an accredited body. CE marking is the market access mechanism.

Compliance is demonstrated through a conformity assessment process, after which the manufacturer issues a Declaration of Conformity and affixes CE marking to the product. The CE mark is the market access mechanism. Without it, the product cannot be placed on the EU market. The pathway for your products depends on their classification: standard, Class I, or Class II.

  • Product portfolio scope and classification analysis
  • Annex I gap assessment against current product state
  • Technical file and Declaration of Conformity preparation
  • Support for third-party or notified body engagement

How We Deliver Cyber Resilience Act Compliance

We help manufacturers assess their product portfolio against CRA Annex I requirements, define the conformity assessment pathway, and prepare the Declaration of Conformity documentation and technical file.

Step 1 – Scope

Product Scope and Classification

We identify which of your products fall within CRA scope, classify them as standard, Class I, or Class II products, and determine the applicable conformity assessment route for each.

Output: CRA product scope map with classification and conformity pathway per product

Step 2 – Gap Assessment

Annex I Readiness Assessment

We assess each in-scope product against all Annex I Part 1 and Part 2 requirements and produce a gap report with remediation priorities sequenced by enforcement risk.

Output: CRA Annex I gap report with prioritised finding register per product

Step 3 – Remediate

Technical Remediation and Process Design

We support your engineering and product teams in closing Annex I gaps including secure default configuration, vulnerability management process design, and SBOM implementation.

Output: Closed Annex I gaps with documented evidence and vulnerability handling process

Step 4 – Conform

Declaration of Conformity and CE Marking

We prepare the Article 13 technical documentation file and the Declaration of Conformity, enabling your products to carry CE marking and enter the EU market without regulatory challenge.

Output: Technical documentation file and Declaration of Conformity per product

EU Cyber Resilience Act FAQ

The following answers summarise the main CRA compliance questions for manufacturers, developers, importers, and distributors of products with digital elements.

What is the EU Cyber Resilience Act?

The EU Cyber Resilience Act, Regulation (EU) 2024/2847, establishes mandatory cybersecurity requirements for products with digital elements placed on the EU market. It covers cybersecurity across product design, development, maintenance, and vulnerability handling.

When does the Cyber Resilience Act apply?

The CRA entered into force on 10 December 2024. Its main provisions apply from 11 December 2027. Article 14 reporting obligations apply from 11 September 2026, and the provisions concerning notification of conformity assessment bodies apply from 11 June 2026.

Which products are covered by the Cyber Resilience Act?

The CRA applies to products with digital elements, including hardware, software, and certain remote data processing solutions. Examples include connected sensors, routers, industrial equipment, industrial control components, and consumer IoT products.

What are the main CRA Annex I requirements?

Annex I covers essential cybersecurity requirements for products and vulnerability handling. Requirements include secure-by-design development, secure default configurations, protection of data and access, vulnerability identification and handling, security updates, and related lifecycle processes.

Does the Cyber Resilience Act require CE marking?

Products subject to the CRA use CE marking to indicate conformity with the applicable EU requirements. The manufacturer must complete the applicable conformity assessment procedure and issue the required EU Declaration of Conformity before placing the product on the market.

Does CRA compliance require third-party assessment?

The applicable conformity assessment route depends on the product and its classification. Some products can follow a self-assessment route, while certain important or critical products may require involvement of a notified body.

What are the CRA vulnerability reporting requirements?

Article 14 introduces reporting obligations for actively exploited vulnerabilities and severe incidents. These reporting obligations apply from 11 September 2026, ahead of the CRA’s main application date.

What are the potential CRA penalties?

For certain infringements of the essential cybersecurity requirements, the CRA provides for maximum administrative fines of EUR 15 million or 2.5% of the undertaking’s total worldwide annual turnover, whichever is higher. Enforcement also includes corrective measures for non-compliant products.

Related

Related Cybersecurity Regulations and Services

Service

EU Digital Regulation programme

Explore →

Regulation

IEC 62443

Explore →

Regulation

NIS2 Directive

Explore →

Start with a 30-minute discovery call

We scope your CRA product obligations and define the fastest path to CE marking. Book a 30-minute discovery call. We help manufacturers assess their product portfolio against CRA Annex I requirements, define the conformity assessment pathway, and prepare the Declaration of Conformity documentation and technical file.

You leave with:

  • Your product scope classification
  • Your Annex I gap summary
  • Your conformity assessment pathway
Scroll to Top