EU Regulation
Cyber Resilience Act (CRA)
Background
Background
The Cyber Resilience Act (CRA), formally Regulation (EU) 2024/2847, is the EU's comprehensive cybersecurity legislation for products with digital elements. The regulation was adopted in late 2024 and introduces horizontal cybersecurity requirements for all hardware and software products that connect to networks or other devices.
The background is that increasing digitalisation has made cybersecurity vulnerabilities a systemic risk – insecure products open the door to attacks that can affect individual users, businesses, and critical infrastructure.
CRA fills a regulatory gap: while existing EU legislation (such as the NIS2 Directive) focuses on organisational cybersecurity, CRA places requirements directly on products – from design and manufacturing to updates throughout the entire lifecycle.
Scope
Who is affected?
CRA affects manufacturers, importers, and distributors of products with digital elements – a concept that covers virtually all products containing software or network connectivity. This includes:
- Connected consumer products (smart home devices, wearables, toys with network functionality)
- Industrial equipment with software
- Standalone software products
- Components and accessories with digital functions
Exceptions apply to products already regulated by sector-specific legislation with equivalent cybersecurity requirements, such as medical devices and vehicles. Open-source software that is not provided for commercial purposes is also exempt.
Requirements
Key requirements
Central requirements in CRA:
- Security by design: Products must be designed with cybersecurity as an integral part, not as an add-on
- Vulnerability management: Manufacturers must have processes to identify, document, and remediate vulnerabilities throughout the product's expected lifetime (minimum 5 years)
- Security updates: Security updates must be provided free of charge during the product's support period, with automatic installation enabled by default and the option for users to opt out
- Default settings: Products must be delivered with secure default settings, including the ability to reset to factory defaults
- Reporting: Actively exploited vulnerabilities and serious security incidents must be reported to the relevant national CSIRT (incident response organisation) and ENISA (the EU's cybersecurity agency) through a multi-step process – initial early warning within 24 hours, detailed notification within 72 hours, and final report within 14 days
- CE marking: Cybersecurity conformity must be included in the CE marking process with technical documentation and EU Declaration of Conformity
- Classification: Products are categorised into default category (self-assessment), Important Products Class I and Class II, and Critical Products – with increasing requirements for third-party review for higher classes
Timeline
Timeline and milestones
- 20 November 2024: CRA was published in the Official Journal of the EU
- 10 December 2024: The regulation entered into force
- 11 September 2026: Reporting obligations for vulnerabilities and incidents become applicable
- 11 December 2027: All requirements in the regulation become applicable
Products already on the market are not affected retroactively, but all new products after December 2027 must comply.
Compliance
Consequences of non-compliance
The sanctions framework in CRA is significant:
- Fines up to EUR 15 million or 2.5% of global annual turnover (whichever is higher) for failure to meet essential cybersecurity requirements
- Fines up to EUR 10 million or 2% of turnover for other violations
- Products that do not meet the requirements cannot be CE marked and therefore cannot be legally sold within the EU
- Market surveillance authorities can demand withdrawal or recall
- Failure to report serious vulnerabilities can trigger separate sanctions
- Products simultaneously covered by the Machinery Regulation or the Radio Equipment Directive (RED) must meet CRA's cybersecurity requirements in parallel
Action plan
What should you do now?
- Inventory products with digital elements: Map which products in your portfolio contain software, firmware, or network connectivity
- Classify according to CRA: Determine whether products fall under the default category, Class I, or Class II
- Implement security by design: Integrate cybersecurity into the product development process from the start
- Establish vulnerability management: Set up processes to detect, document, and patch security flaws
- Plan update infrastructure: Ensure you can deliver security updates throughout the product's lifetime
- Prepare reporting routines: The reporting obligation starts as early as September 2026 – implement processes for incident reporting to ENISA
- Update CE documentation: Include cybersecurity assessment in your technical documentation and EU Declaration of Conformity
Verca
How Verca helps
Verca integrates CRA's cybersecurity requirements into the overall CE workflow. The platform's classification engine identifies which of your products contain digital elements and which CRA category they fall under.
Documentation support is expanded with templates for cybersecurity assessment, vulnerability management plans, and the reporting requirements that take effect in September 2026.
Verca monitors the harmonised standards being developed under CRA and notifies you when relevant standards are published or updated, keeping your technical documentation current. By managing CRA, the Machinery Regulation, and GPSR in the same platform, you get a consolidated view of your regulatory status.