Cybersecurity is entering a new phase in European product regulation. Under the EU Cyber Resilience Act (CRA), cybersecurity is no longer simply an information-technology consideration or a voluntary product feature. For a broad range of hardware and software products placed on the European Union market, it is becoming an essential product-conformity requirement.
Regulation (EU) 2024/2847 introduces horizontal cybersecurity requirements for products with digital elements, bringing cybersecurity risk assessment, secure product development, vulnerability management, technical documentation and conformity assessment into the regulatory lifecycle of digital products.
The result is an important development for manufacturers, software producers, importers, distributors and organizations supplying connected products into Europe.
Cybersecurity Is Becoming a Product Conformity Requirement
Product conformity in Europe has traditionally been associated with areas such as electrical safety, machinery safety, electromagnetic compatibility, pressure equipment and other regulated product characteristics.
The Cyber Resilience Act extends this regulatory thinking firmly into cybersecurity.
Manufacturers of products within the scope of the CRA will increasingly need to demonstrate that cybersecurity has been systematically considered throughout the planning, design, development, production, delivery and maintenance of the product.
Instead of being treated primarily as an internal technical function, cybersecurity increasingly becomes part of the evidence supporting product conformity and European market access.
What Is the EU Cyber Resilience Act?
The Cyber Resilience Act is Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements.
Its purpose is to establish a common cybersecurity framework for a broad range of hardware and software made available on the European Union market.
A product with digital elements can include a software or hardware product together with its remote data-processing solutions, as well as software or hardware components placed on the market separately, subject to the scope and exclusions established by the Regulation.
CRA relevance extends far beyond traditional cybersecurity products. Connected industrial equipment, network devices, software, smart devices, IoT products and many other digitally enabled products may fall within the regulatory framework.
Which Products May Be Affected?
The scope of the CRA is deliberately broad because digital functionality is now embedded throughout modern products and infrastructure.
Depending on their characteristics and intended use, affected products may include:
Applicability therefore needs to be assessed at product level rather than assumed solely from the manufacturer’s industry classification.
The Manufacturer’s Responsibilities Are Expanding
The CRA places significant responsibility on manufacturers.
When designing, developing and producing a product with digital elements, the manufacturer must ensure that the applicable essential cybersecurity requirements are addressed.
An important foundation of this process is the cybersecurity risk assessment.
That assessment informs how the applicable cybersecurity requirements are implemented throughout the product lifecycle and becomes part of the product’s technical compliance documentation.
Define the product, its digital elements, intended purpose and foreseeable use.
Identify threats, vulnerabilities and potential consequences associated with the product.
Determine which CRA cybersecurity requirements apply and how they will be addressed.
Implement appropriate cybersecurity measures across product architecture and lifecycle.
Establish testing, validation and technical evidence demonstrating implementation.
Maintain vulnerability handling, updates and regulatory reporting after market placement.
Security by Design and Security by Default
One of the central principles behind the CRA is that cybersecurity should be considered during product development rather than added only after a product reaches the market.
Products with digital elements must be designed, developed and produced to provide an appropriate level of cybersecurity based on identified risks.
Depending on the product and applicable requirements, this can involve considerations relating to secure configurations, access control, confidentiality and integrity of data, attack-surface reduction, resilience, security monitoring and vulnerability remediation.
Cybersecurity Risk Assessment Becomes Central
The CRA requires manufacturers to perform a cybersecurity risk assessment for products within its scope.
This assessment should not be treated as an isolated document prepared immediately before market launch.
It needs to inform decisions throughout the relevant stages of the product lifecycle.
- the intended purpose and reasonably foreseeable use of the product;
- the product’s architecture and digital interfaces;
- potential cybersecurity threats and attack scenarios;
- known and foreseeable vulnerabilities;
- third-party hardware and software components;
- remote services and data-processing dependencies;
- possible consequences of cybersecurity compromise; and
- controls implemented to reduce identified risks.
Cybersecurity under the CRA is not simply a feature to be tested at the end of development. It becomes a product-lifecycle conformity requirement that needs to be considered from design through post-market support.
Vulnerability Management Does Not End When the Product Is Sold
One of the most important characteristics of the Cyber Resilience Act is its lifecycle approach.
Manufacturers are expected to establish processes for identifying, documenting, addressing and communicating vulnerabilities affecting their products.
Vulnerability handling therefore becomes an ongoing product-compliance activity rather than a one-time pre-market exercise.
Establish processes for discovering and receiving information about cybersecurity weaknesses.
Evaluate severity, exploitability and potential impact on affected products.
Develop and deploy appropriate corrections, patches or security updates.
Provide appropriate security information to users, customers and relevant stakeholders.
Maintain escalation and reporting processes for incidents and vulnerabilities subject to CRA obligations.
Ensure vulnerability-management responsibilities continue throughout the applicable support period.
Cybersecurity Is Becoming Part of CE Marking
One of the most significant consequences of the CRA is the integration of cybersecurity into the European product-conformity framework.
Before placing an applicable product with digital elements on the EU market, the manufacturer must carry out the appropriate conformity-assessment procedure.
Where conformity with the applicable requirements has been demonstrated, the manufacturer draws up the EU Declaration of Conformity and affixes the CE marking.
Security is often treated primarily as an engineering or IT consideration.
Security requirements, evidence and conformity assessment become part of the formal compliance process.
Not Every Product Follows the Same Conformity Route
The CRA establishes different conformity-assessment possibilities depending on the product and its classification.
Many products may be able to use an internal-control conformity route where the applicable conditions are satisfied.
However, the Regulation also identifies categories of important and critical products with digital elements for which different or more demanding conformity procedures may apply.
Correct product classification therefore becomes an early and important compliance decision.
Testing and Technical Evidence Will Become Increasingly Important
Product conformity depends on objective evidence.
For CRA compliance, manufacturers may need to demonstrate how cybersecurity requirements have been implemented and verified through appropriate technical documentation, engineering analysis and testing.
- cybersecurity risk-assessment records;
- product architecture and security-design documentation;
- software and component information;
- vulnerability-analysis records;
- security verification and validation;
- penetration or other cybersecurity testing where appropriate;
- technical specifications and applicable standards;
- corrective-action and vulnerability-remediation records;
- product instructions and security information; and
- conformity-assessment evidence.
The Supply Chain Also Matters
Modern digital products rarely consist entirely of technology developed by a single manufacturer.
Software libraries, embedded components, third-party applications, cloud services and externally supplied hardware can all become part of the final product architecture.
The CRA therefore creates important implications for supply-chain cybersecurity and component management.
The September 2026 Reporting Milestone
Although the CRA’s main obligations apply from 11 December 2027, one particularly important requirement arrives considerably earlier.
From 11 September 2026, manufacturers are required to report certain actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.
This means organizations should not regard December 2027 as the only date that matters.
Vulnerability-management, escalation and regulatory-reporting procedures require attention now.
Cyber Resilience Act Implementation Timeline
The Cyber Resilience Act entered into force.
Provisions concerning notification of conformity-assessment bodies began to apply.
Article 14 reporting obligations concerning certain vulnerabilities and severe incidents begin to apply.
The main provisions of the Cyber Resilience Act become fully applicable.
What Manufacturers Should Be Doing Now
The transition period should be used to build CRA requirements into existing product-development and conformity processes rather than waiting until the final application date.
Identify hardware, software and components that may qualify as products with digital elements.
Review product characteristics, commercial model, intended use and applicable exclusions.
Determine whether products fall within general, important or critical CRA categories.
Compare existing product-development and security controls with applicable CRA requirements.
Integrate cybersecurity risk analysis into product planning, development, verification and change management.
Ensure cybersecurity requirements, testing, risk decisions and compliance evidence can be demonstrated.
Prepare processes for identification, remediation, updates, escalation and regulatory reporting.
Determine what testing, technical evaluation, certification or third-party assessment may be required.
From Cybersecurity Engineering to Market Access
The Cyber Resilience Act represents more than another cybersecurity regulation.
It brings cybersecurity into the established world of product conformity assessment.
Manufacturers will increasingly need to connect cybersecurity engineering with risk assessment, product testing, technical documentation, regulatory compliance, conformity assessment and CE marking.
That convergence is particularly important for organizations operating across international supply chains, where products may incorporate components, software, engineering resources and manufacturing activities from multiple countries.
The companies best prepared for the CRA will therefore be those that treat cybersecurity not as a separate technical exercise, but as an integrated element of product quality, conformity and lifecycle management.
Is Your Product Portfolio Ready for the Cyber Resilience Act?
CRA readiness begins with understanding which products are affected, what requirements apply and what conformity route is appropriate.
An early assessment can identify regulatory gaps, testing requirements, technical-documentation needs and vulnerability-management obligations before they become barriers to market access.
The Cyber Resilience Act marks a fundamental transition: cybersecurity is moving from a desirable product characteristic toward a demonstrable conformity requirement for access to the European market.