EU Legislation

What is the Cyber Resilience Act?

The new EU regulation that mandates cybersecurity for digital products from December 2027.

The most important EU legislation for digital products

The Cyber Resilience Act (CRA) is a European regulation that entered into force on December 10, 2024. This legislation requires manufacturers, importers and distributors of products with digital elements to comply with strict cybersecurity requirements. The goal is to protect consumers and businesses in the EU against cyber threats.

Important Dates

2024

December 10, 2024

CRA officially entered into force. Preparations are underway.

2026

September 11, 2026

Reporting obligation for actively exploited vulnerabilities and incidents takes effect.

2027

December 11, 2027

All requirements take effect. Products with digital elements must be fully compliant.

Who does the CRA apply to?

The CRA applies to all economic operators in the supply chain of digital products.

Business compliance

Which products fall under the CRA?

The CRA classifies products with digital elements into different categories based on their risk profile.

01

Default products

The majority of digital products: software, apps, connected devices. Self-assessment is sufficient for conformity assessment.

02

Important products - Class I

Higher risk products such as password managers, VPNs and network equipment. Harmonized standards or third-party assessment required.

03

Important products - Class II

High risk products such as firewalls, intrusion detection systems and industrial controllers. Mandatory third-party assessment.

04

Critical products

The highest risk class: smart cards, hardware security modules and smart meter gateways. European cybersecurity certification required.

What do you need to do?

01

02

03

04

05

06

€15M

Maximum fine

2027

Full compliance deadline

5 years

Mandatory support period

24h

Vulnerability reporting deadline

Want to know if the CRA applies to your products?

Our experts analyze your product portfolio and determine which CRA obligations apply to your organization.

CRA Assistent