Decorative page background

The Cyber Resilience Act (CRA) – who does it apply to and what new obligations does it introduce?

The Cyber Resilience Act (CRA) – who does it apply to and what new obligations does it introduce?

Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements, aka the Cyber Resilience Act (CRA)[1], entered into force in December 2024. It is a significant EU-wide regulation which sets out cybersecurity requirements for all products with digital elements placed on the EU market. What obligations does the CRA entail, who does it apply to, and how can you prepare for it?

What is the aim of the CRA?

The cybersecurity of digital products is an important issue for individual users, supply chains and critical infrastructure. Until now, however, there has been no uniform legal framework in the EU setting out comprehensive cybersecurity requirements for products containing digital elements. The current key piece of legislation in the field of cybersecurity, the NIS2 Directive[2], does not focus on products as such, but rather addresses the security of services in sectors such as IT, healthcare and energy. The CRA is intended to fill this gap.

The main objective is to ensure that both hardware and software products containing digital elements are designed, developed and manufactured with an emphasis on cybersecurity, and that manufacturers actively handle vulnerabilities throughout the product’s lifecycle. The Regulation also strengthens the position of users who, thanks to the new obligations imposed on manufacturers, will be better able to assess the cybersecurity of the products they buy and use.

To which entities and products does the CRA apply?

The CRA applies to manufacturers, importers and distributors who place products with digital elements on the EU market. The key term is “product with digital elements”, which the CRA defines as a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately. The CRA applies to products with digital elements the intended purpose or reasonably foreseeable use of which includes a direct or indirect connection to a device or network.

Therefore, to determine whether your product falls under the CRA, you will need to answer three questions:

  • Is your product software or hardware?
  • Is your product being placed on the EU market as part of a commercial activity?
  • Does its intended purpose or foreseeable use include connection to a device or network?

If you answer “yes” to all three questions, the CRA most likely applies to your product. In practice, products with digital elements include, for example, smart devices (smart TVs, smart locks, thermostats, baby monitors, smart watches), network components (routers, modems, switches), IoT devices and industrial control systems, operating systems, mobile applications and firmware, as well as server hardware and microprocessors.

Conversely, if a product does not have the necessary connection to a device or network, the CRA does not apply to it. Examples include a dishwasher, calculator, electronic toy or coffee machine that cannot connect to anything.

The following are also excluded from the scope of the CRA on a sectoral basis: medical devices, motor vehicles, products certified for civil aviation[3], products intended for national security or defence, and open-source software unless it is being provided as part of a commercial activity.[4]

Categorisation of products with digital elements according to their level of risk is also important. This classification is crucial for determining the mandatory conformity assessment procedure, which must be carried out before the product is placed on the EU market, e.g. self-assessment by the manufacturer as opposed to mandatory third-party certification. The CRA distinguishes between four product levels:

What new obligations does the CRA introduce?

The CRA introduces a whole range of new obligations, which primarily affect manufacturers. Below we summarise the most important ones:

  1. Security by design and by default: Products with digital elements must be designed and developed with built-in cybersecurity from the outset. This includes, for example, a ban on default passwords such as “password”, access control and the use of cryptography. Automatic updates must be enabled by default for consumer products, whilst users must be provided with a simple way to opt out of them.
  2. Assessment of cybersecurity risks: The manufacturer must assess the risks associated with the product, take them into account at all stages of its life cycle, and keep the assessment up to date. 
  3. Vulnerability handling and security updates: Manufacturers must handle vulnerabilities throughout the product’s support period and report actively exploited vulnerabilities and severe incidents. Security updates must be provided free of charge, if possible separately from functionality updates.
  4. As a rule, support period of no less than five years: The support period must be at least five years, or less if this corresponds to the product’s shorter expected lifetime. For products with a longer lifespan, a correspondingly longer support period is expected. The manufacturer must state the end date of support clearly and comprehensibly at the time of purchase.
  5. Software Bill of Materials (SBOM): Manufacturers must identify and document the components of a product using an SBOM, which serves as a tool for handling vulnerabilities in the supply chain. This is a non-public part of the technical documentation, which may only be requested by the supervisory authorities.
  6. Conformity assessment and CE marking: Before placing the product on the market, the manufacturer must carry out a conformity assessment based on the risk category (Module A, B+C, or H). Successful assessment is a prerequisite for CE marking. For software, the CE marking is included in the declaration of conformity or on the accompanying website.
  7. Technical documentation and user information: The manufacturer must draw up technical documentation demonstrating compliance with the CRA, which must be made available to the supervisory authorities. The product must be accompanied by instructions for safe installation, operation and use.

The first obligation applies from September 2026!

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security via ENISA’s single reporting platform (CRA Single Reporting Platform).

This applies to vulnerabilities for which there is reliable evidence of actual exploitation. Vulnerabilities discovered as part of preventative measures, such as bug bounty programmes, where there is no evidence of prior exploitation, are not subject to a reporting obligation; however, they may be reported on a voluntary basis.

The reporting process takes place in three stages:

The remainder of the CRA will become applicable as of 11 December 2027. For products placed on the market before 11 December 2027:

  • actively exploited vulnerabilities and incidents must be reported; 
  • the other obligations do not have to be complied with unless those products are subject to a substantial modification

Fines are graded based on severity as follows:

  • up to EUR 15 million or up to 2.5 per cent of worldwide turnover for non-compliance with security requirements;
  • up to EUR 10 million or up to 2 per cent of worldwide turnover for non-compliance with, for example, the registration, notification and cooperation obligations; and
  • up to EUR 5 million or up to 1 per cent of worldwide turnover for providing incorrect or misleading information to the authorities.

In view of the transition period, we recommend that you start preparing as soon as possible. The reporting obligations apply from 11 September 2026, and products falling within the scope of the CRA must be fully compliant by 11 December 2027, which requires sufficient lead time to carry out an audit of the product portfolio, adjust development and manufacturing processes, implement vulnerability handling processes, and prepare documentation.

Our dedicated team at HAVEL & PARTNERS for data protection and cybersecurity will be available to help you assess whether and to what extent the CRA applies to your products, to classify them into the relevant risk category and to establish the appropriate conformity assessment procedure. We are ready to provide you with comprehensive support to ensure compliance with the CRA, from product portfolio audits, through the establishment of vulnerability handling processes and the preparation of documentation, to assistance with fulfilling reporting obligations to supervisory authorities.

  • [1] – The CRA will be transposed into Czech law through the forthcoming Draft Bill on Cybersecurity Requirements for Products with Digital Elements
  • [2] – Implemented into Czech law by Act No. 264/2025 Sb. on cybersecurity.
  • [3] – Products certified in accordance with Regulation (EU) 2018/1139.
  • [4] – Marine equipment covered by Directive 2014/90/EU is also excluded from the scope of the CRA.
Related articles