Technical Insight

GAR INSIGHT
EU Cyber Resilience Act: A New Era of Cybersecurity Product Conformity

Cybersecurity is entering a new phase in European product regulation. Under the EU Cyber Resilience Act (CRA), cybersecurity is no longer simply an information-technology consideration or a voluntary product feature. For a broad range of hardware and software products placed on the European Union market, it is becoming an essential product-conformity requirement.

Regulation (EU) 2024/2847 introduces horizontal cybersecurity requirements for products with digital elements, bringing cybersecurity risk assessment, secure product development, vulnerability management, technical documentation and conformity assessment into the regulatory lifecycle of digital products.

The result is an important development for manufacturers, software producers, importers, distributors and organizations supplying connected products into Europe.

The shift is significant: Cybersecurity is moving from an internal technical discipline toward a demonstrable product-conformity requirement directly connected with European market access.

Cybersecurity Is Becoming a Product Conformity Requirement

Product conformity in Europe has traditionally been associated with areas such as electrical safety, machinery safety, electromagnetic compatibility, pressure equipment and other regulated product characteristics.

The Cyber Resilience Act extends this regulatory thinking firmly into cybersecurity.

Manufacturers of products within the scope of the CRA will increasingly need to demonstrate that cybersecurity has been systematically considered throughout the planning, design, development, production, delivery and maintenance of the product.

Instead of being treated primarily as an internal technical function, cybersecurity increasingly becomes part of the evidence supporting product conformity and European market access.

What Is the EU Cyber Resilience Act?

The Cyber Resilience Act is Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements.

Its purpose is to establish a common cybersecurity framework for a broad range of hardware and software made available on the European Union market.

A product with digital elements can include a software or hardware product together with its remote data-processing solutions, as well as software or hardware components placed on the market separately, subject to the scope and exclusions established by the Regulation.

Why this matters:

CRA relevance extends far beyond traditional cybersecurity products. Connected industrial equipment, network devices, software, smart devices, IoT products and many other digitally enabled products may fall within the regulatory framework.

Which Products May Be Affected?

The scope of the CRA is deliberately broad because digital functionality is now embedded throughout modern products and infrastructure.

Depending on their characteristics and intended use, affected products may include:

Applicability therefore needs to be assessed at product level rather than assumed solely from the manufacturer’s industry classification.

The Manufacturer’s Responsibilities Are Expanding

The CRA places significant responsibility on manufacturers.

When designing, developing and producing a product with digital elements, the manufacturer must ensure that the applicable essential cybersecurity requirements are addressed.

An important foundation of this process is the cybersecurity risk assessment.

That assessment informs how the applicable cybersecurity requirements are implemented throughout the product lifecycle and becomes part of the product’s technical compliance documentation.

Product & Intended Use

Define the product, its digital elements, intended purpose and foreseeable use.

Cybersecurity Risks

Identify threats, vulnerabilities and potential consequences associated with the product.

Essential Requirements

Determine which CRA cybersecurity requirements apply and how they will be addressed.

Technical Controls

Implement appropriate cybersecurity measures across product architecture and lifecycle.

Verification & Evidence

Establish testing, validation and technical evidence demonstrating implementation.

Post-Market Management

Maintain vulnerability handling, updates and regulatory reporting after market placement.

Security by Design and Security by Default

One of the central principles behind the CRA is that cybersecurity should be considered during product development rather than added only after a product reaches the market.

Products with digital elements must be designed, developed and produced to provide an appropriate level of cybersecurity based on identified risks.

Depending on the product and applicable requirements, this can involve considerations relating to secure configurations, access control, confidentiality and integrity of data, attack-surface reduction, resilience, security monitoring and vulnerability remediation.

The practical consequence for manufacturers: Cybersecurity needs to become part of the product-development and product-compliance process rather than a separate activity performed at the end.

Cybersecurity Risk Assessment Becomes Central

The CRA requires manufacturers to perform a cybersecurity risk assessment for products within its scope.

This assessment should not be treated as an isolated document prepared immediately before market launch.

It needs to inform decisions throughout the relevant stages of the product lifecycle.

An effective cybersecurity risk assessment may need to consider:
  • the intended purpose and reasonably foreseeable use of the product;
  • the product’s architecture and digital interfaces;
  • potential cybersecurity threats and attack scenarios;
  • known and foreseeable vulnerabilities;
  • third-party hardware and software components;
  • remote services and data-processing dependencies;
  • possible consequences of cybersecurity compromise; and
  • controls implemented to reduce identified risks.
Cybersecurity under the CRA is not simply a feature to be tested at the end of development. It becomes a product-lifecycle conformity requirement that needs to be considered from design through post-market support.

Vulnerability Management Does Not End When the Product Is Sold

One of the most important characteristics of the Cyber Resilience Act is its lifecycle approach.

Manufacturers are expected to establish processes for identifying, documenting, addressing and communicating vulnerabilities affecting their products.

Vulnerability handling therefore becomes an ongoing product-compliance activity rather than a one-time pre-market exercise.

Vulnerability Identification

Establish processes for discovering and receiving information about cybersecurity weaknesses.

Assessment & Prioritization

Evaluate severity, exploitability and potential impact on affected products.

Remediation

Develop and deploy appropriate corrections, patches or security updates.

Communication

Provide appropriate security information to users, customers and relevant stakeholders.

Regulatory Reporting

Maintain escalation and reporting processes for incidents and vulnerabilities subject to CRA obligations.

Lifecycle Support

Ensure vulnerability-management responsibilities continue throughout the applicable support period.

Cybersecurity Is Becoming Part of CE Marking

One of the most significant consequences of the CRA is the integration of cybersecurity into the European product-conformity framework.

Before placing an applicable product with digital elements on the EU market, the manufacturer must carry out the appropriate conformity-assessment procedure.

Where conformity with the applicable requirements has been demonstrated, the manufacturer draws up the EU Declaration of Conformity and affixes the CE marking.

TRADITIONAL VIEW Cybersecurity as a technical product feature

Security is often treated primarily as an engineering or IT consideration.

CRA CONFORMITY VIEW Cybersecurity as part of regulatory market access

Security requirements, evidence and conformity assessment become part of the formal compliance process.

Not Every Product Follows the Same Conformity Route

The CRA establishes different conformity-assessment possibilities depending on the product and its classification.

Many products may be able to use an internal-control conformity route where the applicable conditions are satisfied.

However, the Regulation also identifies categories of important and critical products with digital elements for which different or more demanding conformity procedures may apply.

Product classification matters. Depending on the product category, applicable harmonised standards, certification schemes and selected conformity route, third-party conformity assessment may become necessary.

Correct product classification therefore becomes an early and important compliance decision.

Testing and Technical Evidence Will Become Increasingly Important

Product conformity depends on objective evidence.

For CRA compliance, manufacturers may need to demonstrate how cybersecurity requirements have been implemented and verified through appropriate technical documentation, engineering analysis and testing.

The evidence framework may include:
  • cybersecurity risk-assessment records;
  • product architecture and security-design documentation;
  • software and component information;
  • vulnerability-analysis records;
  • security verification and validation;
  • penetration or other cybersecurity testing where appropriate;
  • technical specifications and applicable standards;
  • corrective-action and vulnerability-remediation records;
  • product instructions and security information; and
  • conformity-assessment evidence.

The Supply Chain Also Matters

Modern digital products rarely consist entirely of technology developed by a single manufacturer.

Software libraries, embedded components, third-party applications, cloud services and externally supplied hardware can all become part of the final product architecture.

The CRA therefore creates important implications for supply-chain cybersecurity and component management.

Third-party components can become part of the manufacturer’s compliance risk. Procurement, supplier qualification, component oversight and technical documentation may therefore become increasingly important elements of CRA compliance.

The September 2026 Reporting Milestone

Although the CRA’s main obligations apply from 11 December 2027, one particularly important requirement arrives considerably earlier.

From 11 September 2026, manufacturers are required to report certain actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.

This means organizations should not regard December 2027 as the only date that matters.

Vulnerability-management, escalation and regulatory-reporting procedures require attention now.

Cyber Resilience Act Implementation Timeline

10 December 2024

The Cyber Resilience Act entered into force.

11 June 2026

Provisions concerning notification of conformity-assessment bodies began to apply.

11 September 2026

Article 14 reporting obligations concerning certain vulnerabilities and severe incidents begin to apply.

11 December 2027

The main provisions of the Cyber Resilience Act become fully applicable.

What Manufacturers Should Be Doing Now

The transition period should be used to build CRA requirements into existing product-development and conformity processes rather than waiting until the final application date.

Map the Product Portfolio

Identify hardware, software and components that may qualify as products with digital elements.

Determine CRA Applicability

Review product characteristics, commercial model, intended use and applicable exclusions.

Establish Product Classification

Determine whether products fall within general, important or critical CRA categories.

Perform a Gap Assessment

Compare existing product-development and security controls with applicable CRA requirements.

Strengthen Risk Assessment

Integrate cybersecurity risk analysis into product planning, development, verification and change management.

Review Technical Documentation

Ensure cybersecurity requirements, testing, risk decisions and compliance evidence can be demonstrated.

Establish Vulnerability Management

Prepare processes for identification, remediation, updates, escalation and regulatory reporting.

Plan Conformity Assessment

Determine what testing, technical evaluation, certification or third-party assessment may be required.

From Cybersecurity Engineering to Market Access

The Cyber Resilience Act represents more than another cybersecurity regulation.

It brings cybersecurity into the established world of product conformity assessment.

Manufacturers will increasingly need to connect cybersecurity engineering with risk assessment, product testing, technical documentation, regulatory compliance, conformity assessment and CE marking.

That convergence is particularly important for organizations operating across international supply chains, where products may incorporate components, software, engineering resources and manufacturing activities from multiple countries.

The companies best prepared for the CRA will therefore be those that treat cybersecurity not as a separate technical exercise, but as an integrated element of product quality, conformity and lifecycle management.

Cybersecurity is becoming part of product conformity. Compliance evidence will increasingly become part of European market access.

Is Your Product Portfolio Ready for the Cyber Resilience Act?

CRA readiness begins with understanding which products are affected, what requirements apply and what conformity route is appropriate.

An early assessment can identify regulatory gaps, testing requirements, technical-documentation needs and vulnerability-management obligations before they become barriers to market access.

The Cyber Resilience Act marks a fundamental transition: cybersecurity is moving from a desirable product characteristic toward a demonstrable conformity requirement for access to the European market.
Regulatory status: Regulation (EU) 2024/2847 entered into force on 10 December 2024. Provisions relating to notification of conformity-assessment bodies have applied since 11 June 2026. Article 14 reporting obligations apply from 11 September 2026, while the Regulation’s main requirements apply from 11 December 2027. Organizations should verify the applicable regulatory provisions, standards, guidance and conformity-assessment requirements for their specific products when making compliance decisions.
GLOBAL ALLIANCE REGISTER

How Global Alliance Register Can Support You

Global Alliance Register supports manufacturers, suppliers and responsible economic operators with independent technical-assurance services relevant to Cyber Resilience Act within the digital and AI context. Based on the article's emphasis on regulatory review, technical-documentation review and risk assessment, GAR can coordinate competent specialists, laboratories, inspectors, auditors and accredited conformity-assessment resources as appropriate to the actual technical need. Within the context of this article, Global Alliance Register can support you in the following areas:

01

Review the applicable regulatory, technical and scope requirements for Cyber Resilience Act and define the responsibilities, classifications and assurance pathway relevant to the product or equipment.

02

Map the applicable standards, specifications, acceptance criteria and technical requirements for Cyber Resilience Act to the evidence needed to demonstrate compliance, quality or performance.

03

Review test records, inspection evidence, calculations, reports and other technical documentation relating to Cyber Resilience Act for completeness, consistency and traceability.

04

Coordinate specialist engineering review of design assumptions, calculations, specifications, risks and other technical features that materially affect Cyber Resilience Act.

05

Integrate test results, inspection reports, audit evidence and certification outcomes relating to Cyber Resilience Act into a coherent assurance process with clear responsibilities and traceability.

Scroll to Top