An Overview of the Cyber Resilience Act

The Cyber Resilience Act (CRA) is an EU regulation that requires companies to strengthen the cybersecurity of connected products. Since the first obligations (reporting requirements) will take effect as early as September 2026, it’s time to address this issue. We’ve summarized and organized all the relevant information, obligations and potential penalties.

A cell phone with a lock displayed on its screen. The cell phone is enclosed in a transparent dome. Various digital icons related to the Cyber Resilience Act are displayed on the dome.

What is the Cyber Resilience Act?

It is the first EU-wide legislative act with mandatory and uniform regulations for the cybersecurity of connected products. It was adopted by the EU institutions and is intended to strengthen the cybersecurity resilience of products manufactured within the EU or imported into the EU.

The CRA sets out the technical and organizational requirements for the IT security of connected products. In particular, it addresses documentation, reporting, and information obligations.

Full implementation of the CRA will be mandatory starting in December 2027.

Who is affected by the Cyber Resilience Act?

The regulation governs “products with digital elements” (PDE). This is a broad category of software and hardware that is placed on the EU market as a product. Software can thus be divided into two categories:

  • Product (installed)

  • Service (used, e.g., in a browser)

Within this broad classification, there are nuances that make the distinction more difficult. In our webinar on the Cyber Resilience Act, we used examples to show that the distinction depends on several factors. Some examples include:

  • website in a browser

  • the same application, but as a desktop app

  • smart home app with a cloud backend

  • device and software

A book with a § symbol and 12 stars arranged in a circle on its cover. Five digital icons are arranged around the book.

Who is the manufacturer?

A manufacturer is anyone who places a product on the EU market under their own name or brand. This also applies when companies have a product developed for them or provide it free of charge. Products from non-EU countries are covered in the same way as soon as they enter the EU market. In this case, the non-EU supplier is considered the manufacturer, or the party that markets the third-party product under its own name or makes significant changes to it.

What obligations apply to manufacturers of connected products?

The goal of manufacturers is to obtain the CE mark for their digital hardware or software products. This requires the issuance of a declaration of conformity confirming that the product complies with the requirements of the CRA. Manufacturers of standard products without a risk class may issue this declaration themselves. Products with a risk class require an external audit. To obtain a declaration of conformity, manufacturers must fulfill the following obligations:

  • Manufacturers must conduct a risk assessment of their product and document the results. In particular, they should analyze potential entry points and vulnerabilities.

  • Manufacturers must take appropriate measures to address security vulnerabilities in their products and document these measures in detail. Any exceptions regarding security vulnerabilities must be explicitly justified.

  • For software products, a Software Bill of Materials (SBOM) must be created and continuously updated. It lists all software components and, in particular, documents the third-party libraries used.

  • The technical documentation should, in its entirety, include an analysis of potential security vulnerabilities, the measures taken to address them, and the SBOM. It serves as the basis for obtaining a declaration of conformity and must be continuously updated throughout the entire product lifecycle.

  • Under the CRA, manufacturers of connected products are required to provide security updates for the duration of a predetermined support period (at least 5 years).

  • The CRA also requires manufacturers to report actively exploited vulnerabilities in their products or serious security incidents. Early warnings must be issued within 24 hours. Additional reports include:

    • full report on the incident within 72 hours

    • actions to correct or minimize the risk within 14 days

    • a final report on the incident within one month

A cell phone screen is the focal point of the image, held in a hand. Six icons related to digitalization and cybersecurity pop out of the screen.

Risk Assessment and Safety Classes

If software is subject to the Cyber Resilience Act, the risk assessment applies. It forms the foundation of the entire CRA process. Furthermore, it is mandatory and must be maintained and documented throughout the entire lifecycle. At the same time, it determines which requirements from CRA Annex I apply to the product and how rigorously it will be tested. However, it is estimated that 90% of products fall into the lowest security class, “Standard.” These security classes are:

  • Standard – Most apps and devices. It is permitted to conduct a self-assessment and issue an EU Declaration of Conformity on one’s own.

  • Important, Class I – smart locks / cameras, health wearables, password managers

  • Important, Class II – firewalls, tamper-resistant microprocessors

  • Critical – smart cards, smart meter gateways

The class determines whether self-assessment is possible, to what extent and whether harmonized standards must be used.

What are the potential penalties?

If market supervisory authorities (in Germany, the BSI) identify violations of the Cyber Resilience Act, this may result in substantial penalties:

  • up to €5 million or 1 % of the previous year’s revenue for providing false, incomplete, or misleading information

  • up to €10 million or 2 % of the previous year’s revenue for violations of conformity assessment, documentation, and information disclosure obligations

  • up to €15 million or 2.5 % of the previous year’s revenue for failure to comply with cybersecurity requirements or vulnerability management requirements

Penalties may vary depending on the nature and severity of the violation, the size and market share of the organization and other criteria.

The deadlines are already in effect

The Cyber Resilience Act has been in effect since December 10, 2024. These deadlines are now critical:

September 11, 2026: Reporting requirements for vulnerabilities and incidents. This also applies to products already on the market.

December 11, 2027: Full implementation of all requirements

For existing products, processes must be put in place as soon as possible to comply with the reporting requirements. However, anyone developing a product scheduled to be launched by the end of 2027 should incorporate the full requirements into the development process now.

For more information on this topic check out the free webinar with our experts

Do you have questions about the Cyber Resilience Act? Let’s talk

Consent necessary

In order to use this feature, your consent to use our Hubspot services is necessary.
On this basis, we analyze website visits to create sales-relevant information.

Insights

Project idea? Get in touch!