1 Shift Happens: An Introduction to the EU CRA
The Cyber Resilience Act, formally Regulation (EU) 2024/2847 of the European Parliament and the Council of the European Union, is a regulation that provides a uniform legal framework for cybersecurity and incident reporting requirements when placing products with digital elements on the EU market, as well as during the product’s life cycle.
What Products are Affected by the CRA?
The CRA defines a “product with digital elements” as “a software or hardware product and its remote data processing solutions”. This also includes individual software or hardware components sold separately. These products are within the scope of the CRA when their intended or foreseeable use includes a direct or indirect data connection to a device or network, whether the connection is logical, physical, or virtual.
Therefore, the CRA covers:
- Standalone software like applications and computer programs
- Hardware with embedded software
- Standalone hardware
- Any combination of hardware and software that are supplied separately but intended to operate together
The CRA also distinguishes between default products and those that are considered important and critical. The product category impacts the conformity assessment path required for the product. These paths range from a simple internal control-based self-assessment all the way up to a cybersecurity certification conducted by a certified third party. The following figure shows a summary of the different product categories. For a comprehensive list of important and critical products, refer to the Annex III of the CRA Specification.
Who is Required to Comply with the CRA?
Commercial entities placing their products on the European market must comply with the CRA. The term “economic operator” is used as the legal umbrella term to capture entities responsible for bringing a product to the EU market, which includes but is not limited to the following:
- Manufacturers
- Importers
- Distributors
- Authorized representatives, or legal entities who are subject to obligations in relation to making products with digital elements available on the market
What Does it Mean to Make a Product Available on the European Market?
The CRA distinguishes between placing a product on the market and making a product available.
Placing a product on the market means the first making available of a product with digital elements on the EU market.
Making a product available on the market means supplying a product for distribution or use on the EU market in the course of a commercial activity, whether for payment or free of charge.
Making this distinction is crucial for it determines exactly when an economic operator's legal obligations are triggered. It also starts the clock for the mandatory support period for the products.
The Blue Guide expressly states that placing on the market applies to each individual product, not the product type. Individual units of an existing product family / type placed after new requirements (such as EU CRA) become applicable must comply with those requirements.
As such, any individual unit first placed on the EU market on or after 11 December 2027 must be fully CRA compliant, even where:
- the same model number has been used for years;
- the hardware and firmware are unchanged;
- most of the design predates the CRA;
- identical units were previously sold in the EU.
When Does the CRA Take Effect?
The CRA is implemented in phases, with Phase 1 concerning the reporting obligations being implemented first on September 11, 2026, and full CRA compliance to follow in Phase 2 on December 11, 2027. The following figure shows an overview of the timeline for CRA implementation and compliance.
What Do These Requirements Mean for Developers, Engineers, and Decision Makers?
Product Lifetime Responsibility
The CRA mandates manufacturers to take on additional product lifetime responsibilities. They are legally bound to provide security support and patches for at least 5 years (or the expected product-related life cycle, if shorter than 5 years) after the last individual product is made available. The CRA also requires a dedicated Product Security Incident Response Team (PSIRT) to provide timely responses to vulnerabilities and issues discovered in the products. This puts more pressure on engineering resources to rapidly provide software updates and actively monitor any product issues after deployment.
Conformity Assessment and Declaration
Economic operators must perform due diligence to assess and check their products for conformity with the requirements of this legislation. A Declaration of Conformity is required for products to achieve a CE mark, which allows them to be sold on the EU Market. Conducting these assessments and checking the boxes to truthfully declare conformity is a time-consuming and resource-intensive process, especially for products in the important and critical categories.
The Price of Non-Compliance
The CRA makes cybersecurity compliance a legal condition for market entry into the EU. In addition to that, the CRA imposes monetary penalties as high as 15 million euros or up to 2.5% of the worldwide annual turnover revenue. As such, it would be no exaggeration to say that non-compliance can spell economic and financial disaster for economic operators as defined by the CRA.
What will Happen to Products that were Designed Before the CRA is Fully Implemented but have not Been Placed in the Market?
According to the July 2026 Commission Guidance on the application of the CRA, products designed before the CRA was implemented might be placed on the market under the CRA without redesign, if manufacturers can demonstrate that the products achieve an appropriate level of cybersecurity in the context of their intended or foreseeable use. This can be done through a thorough cybersecurity risk assessment and technical documentation. Similarly, manufacturers must also provide evidence of the vulnerability handling processes laid down in Part II of Annex I.
Regardless of whether products need to be redesigned or not before being placed on the market, manufacturers are still subject to the obligation of ensuring that applicable conformity assessment procedures are carried out, the EU declarations of conformity are drawn up, and the CE marking is affixed to the product.
Action Checklist
- Identify which products fall within the scope of the CRA.
- For products in scope, categorize them as Default, Important Class I/II, or Critical category.
- Create a plan to conduct a Threat Analysis and Risk Assessment (TARA).
- Check or review any existing security support or software update policy documents.
