Regulatory Framework
EU AI
Act
Artificial Intelligence Regulation
The EU AI Act is the world’s first comprehensive legal framework for artificial intelligence. It classifies AI systems by risk level and imposes mandatory conformity obligations on high-risk systems. AI used in critical infrastructure is classified as high-risk by default. Obligations are active and escalating through 2026 and 2027.
Regulation Overview
Type
EU Mandatory Regulation – Direct Application
In Force
1 August 2024
Full Compliance Deadline
August 2026
Market Access
CE marking via Declaration of Conformity
Certificate
No – Declaration of Conformity by manufacturer
Max Penalty
30 million EUR or 6% global turnover
August 2026 Deadline
Products placed on the EU market after August 2026 without CRA conformity will face market withdrawal by national surveillance authorities. Manufacturers of products with long development cycles need to start now.
What It Is
Understanding
the EU AI Act
The EU AI Act (EU 2024/2847) entered into force on 1 August 2024. It requires manufacturers of products with digital elements hardware and software to meet essential cybersecurity requirements before placing those products on the EU market. The full compliance deadline is August 2026.
The CRA covers any product with digital elements that can connect to another device or network. This includes embedded software in industrial equipment, connected sensors, routers, industrial control system components, and consumer IoT devices. The requirements apply to the product and to the manufacturer’s processes for vulnerability handling and security updates.
More About
EU AI Act
Unlike ISO 27001 or IEC 62443, the CRA does not result in a certificate from an accredited body. Compliance is demonstrated through a conformity assessment process, after which the manufacturer issues a Declaration of Conformity and affixes CE marking to the product. The CE mark is the market access mechanism. Without it, the product cannot be placed on the EU market.
The CRA introduces two categories of critical products like Class I and Class II with stricter conformity assessment requirements. Most connected products fall outside these classes and can self-certify. Class I products require third-party review of their technical documentation. Class II products require notified body involvement.
SUMMARY
Type
EU Mandatory Regulation – Direct Application
In Force
1 August 2024
Full Compliance Deadline
August 2026
Market Access Mechanism
CE marking via Declaration of Conformity
Certificate Issued
No – Declaration of Conformity by manufacturer
Max Penalty
30 million EUR or 6% global turnover
What the EU AI Act Covers
The CRA covers any product with digital elements that can connect to another device or network. This includes embedded software in industrial equipment, connected sensors, routers, industrial control system components, and consumer IoT devices. The requirements apply to the product and to the manufacturer’s processes for vulnerability handling and security updates.
Unlike ISO 27001 or IEC 62443, the CRA does not result in a certificate from an accredited body. Compliance is demonstrated through a conformity assessment process, after which the manufacturer issues a Declaration of Conformity and affixes CE marking to the product. The CE mark is the market access mechanism. Without it, the product cannot be placed on the EU market.
Oct 2027
Full compliance deadline for all manufacturers placing products with digital elements on the EU market.
Class I & II
Two categories of critical products with stricter conformity assessment requirements than standard self-certification.
CE Mark
The market access mechanism. Without CE marking your product cannot be legally placed on the EU market.
Who is affected
The CRA applies across the supply chain. Manufacturers bear primary obligations, but importers and distributors also have specific duties to verify conformity before making products available on the EU market.
Manufacturer
Connected Product Manufacturers
Any manufacturer placing a product with digital elements on the EU market bears primary CRA obligations. This includes industrial equipment makers, sensor manufacturers, control system component suppliers, and software developers.
Importer
EU Importers of Connected Products
Importers placing non-EU manufactured products on the EU market must verify that the manufacturer has fulfilled CRA obligations and must act when they know a product is not compliant.
Distributor
EU Distributors and Resellers
Distributors must verify CE marking before making products available on the market and must not make available products they know are non-compliant.
Critical product classes
Standard Products
Self-Certification
Most connected products fall outside Class I and Class II categories and can follow a self-certification path. The manufacturer conducts their own conformity assessment against Annex I requirements.
Class I Products
Third-Party Documentation Review
Class I products require third-party review of their technical documentation. This applies to products considered to pose higher cybersecurity risks under the regulation’s classification criteria.
Class II Products
Notified Body Involvement
Class II products require involvement of a notified body in the conformity assessment. These products are considered critical and face the most stringent assessment requirements under the regulation.
Key requirements
CRA Annex I defines essential cybersecurity requirements in two parts: security properties the product must have, and vulnerability handling obligations manufacturers must fulfil throughout the product lifecycle.
Art.Annex I Part 1
Security by Design Requirements
Products must be delivered without known exploitable vulnerabilities, with a secure default configuration, protection against unauthorised access, data protection, minimal attack surface, and resilience against denial of service attacks.
Mandatory
Art.Annex I Part 1(2)
Confidentiality and Integrity
Products must protect data at rest and in transit. Collected data must be limited to what is necessary for the intended purpose.
Mandatory
Art.Annex I Part 2(1)
Vulnerability Identification and Documentation
Manufacturers must identify and document vulnerabilities and components contained in products, including a software bill of materials in a machine-readable format.
Mandatory
Art.Annex I Part 2(2)
Security Updates for Minimum 5 Years
Manufacturers must address vulnerabilities without delay and provide security updates separately from functionality updates for a minimum of five years or the expected product lifecycle.
Mandatory
Art.13
Technical Documentation
Manufacturers must draw up technical documentation before placing the product on the market. It must enable conformity assessment and be kept for ten years after product placement.
Mandatory
Art.14
Actively Exploited Vulnerability Reporting
Manufacturers must notify ENISA within 24 hours of becoming aware of an actively exploited vulnerability in their product.
24h Reporting
15M EUR
Maximum Penalty – or 2.5% of Global Annual Turnover
The CRA sets maximum penalties of 15 million EUR or 2.5 percent of global annual turnover for violations of the essential requirements. Market surveillance authorities can also require products to be withdrawn from the market or recalled without financial penalty, which for a product-dependent business is often a more significant consequence than the fine.
Conformity assessment and CE marking
Unlike ISO 27001 or IEC 62443, the CRA does not result in a certificate from an accredited body. CE marking is the market access mechanism.
Compliance is demonstrated through a conformity assessment process, after which the manufacturer issues a Declaration of Conformity and affixes CE marking to the product. The CE mark is the market access mechanism. Without it, the product cannot be placed on the EU market. The pathway for your products depends on their classification: standard, Class I, or Class II.
- Product portfolio scope and classification analysis
- Annex I gap assessment against current product state
- Technical file and Declaration of Conformity preparation
- Support for third-party or notified body engagement
How we deliver CRA engagements
We help manufacturers assess their product portfolio against CRA Annex I requirements, define the conformity assessment pathway, and prepare the Declaration of Conformity documentation and technical file.
Step 1 – Scope
Product Scope and Classification
We identify which of your products fall within CRA scope, classify them as standard, Class I, or Class II products, and determine the applicable conformity assessment route for each.
Output: CRA product scope map with classification and conformity pathway per product
Step 2 – Gap Assessment
Annex I Readiness Assessment
We assess each in-scope product against all Annex I Part 1 and Part 2 requirements and produce a gap report with remediation priorities sequenced by enforcement risk.
Output: CRA Annex I gap report with prioritised finding register per product
Step 3 – Remediate
Technical Remediation and Process Design
We support your engineering and product teams in closing Annex I gaps including secure default configuration, vulnerability management process design, and SBOM implementation.
Output: Closed Annex I gaps with documented evidence and vulnerability handling process
Step 4 – Conform
Declaration of Conformity and CE Marking
We prepare the Article 13 technical documentation file and the Declaration of Conformity, enabling your products to carry CE marking and enter the EU market without regulatory challenge.
Output: Technical documentation file and Declaration of Conformity per product
Related
Connected frameworks
and services
Service
EU Digital Regulation Programme
Explore →
Regulation
IEC 62443
Explore →
Regulation
NIS2 Directive
Explore →
Start with a 30-minute discovery call
We scope your CRA product obligations and define the fastest path to CE marking. Book a 30-minute discovery call. We help manufacturers assess their product portfolio against CRA Annex I requirements, define the conformity assessment pathway, and prepare the Declaration of Conformity documentation and technical file.
You leave with:
- Your product scope classification
- Your Annex I gap summary
- Your conformity assessment pathway