The new EU regulation that mandates cybersecurity for digital products from December 2027.
The Cyber Resilience Act (CRA) is a European regulation that entered into force on December 10, 2024. This legislation requires manufacturers, importers and distributors of products with digital elements to comply with strict cybersecurity requirements. The goal is to protect consumers and businesses in the EU against cyber threats.
CRA officially entered into force. Preparations are underway.
Reporting obligation for actively exploited vulnerabilities and incidents takes effect.
All requirements take effect. Products with digital elements must be fully compliant.
The CRA applies to all economic operators in the supply chain of digital products.
The CRA classifies products with digital elements into different categories based on their risk profile.
The majority of digital products: software, apps, connected devices. Self-assessment is sufficient for conformity assessment.
Higher risk products such as password managers, VPNs and network equipment. Harmonized standards or third-party assessment required.
High risk products such as firewalls, intrusion detection systems and industrial controllers. Mandatory third-party assessment.
The highest risk class: smart cards, hardware security modules and smart meter gateways. European cybersecurity certification required.
Maximum fine
Full compliance deadline
Mandatory support period
Vulnerability reporting deadline
Our experts analyze your product portfolio and determine which CRA obligations apply to your organization.