What is the Cyber Resilience Act?
The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847, which establishes cybersecurity requirements for products with digital elements placed on the European Union market. It applies to hardware and software products, including relevant remote data processing solutions, that can connect, directly or indirectly, to a device or network. Its purpose is to reduce cybersecurity vulnerabilities in digital products and to make security a requirement throughout their lifecycle.
The CRA primarily affects manufacturers, but obligations may also apply to importers and distributors. A manufacturer is not necessarily the entity that physically produces a device. It may also be an organisation that develops software, places a product on the market under its own name or trademark, or substantially modifies an existing product in a way that affects compliance.
The Regulation requires economic operators to assess cyber risks, design products securely, address known vulnerabilities, provide security updates and prepare technical documentation. Compliance with the CRA will become a condition for placing many digital products on the EU market. The Regulation entered into force on 10 December 2024. Most of its substantive obligations will apply from 11 December 2027, while certain vulnerability and incident reporting duties apply earlier, from 11 September 2026.
What does the Cyber Resilience Act cover?
The CRA covers a broad range of products with digital elements, including connected devices, operating systems, mobile and desktop applications, network equipment, industrial control components, cloud-connected consumer products and security software. The assessment should be conducted individually for each product, because the scope depends on its functionality, intended purpose and connections with other systems.
The Regulation requires products to meet essential cybersecurity requirements set out in Annex I to the CRA. These requirements concern, among other matters, secure design, protection against unauthorised access, vulnerability management, protection of the confidentiality, integrity and availability of data, secure default settings and the ability to issue security updates. Manufacturers must also identify vulnerabilities and provide security support for a period reasonably expected by users, which must generally be at least five years unless the expected period of use is shorter.
Some products may be subject to additional conformity assessment requirements. The CRA distinguishes, in particular, important products with digital elements and critical products with digital elements. Depending on the product category and risk level, a manufacturer may need to involve a notified body rather than rely solely on an internal conformity assessment procedure.
The CRA does not apply uniformly to every digital product. Certain products already covered by specific EU cybersecurity rules may be excluded in whole or in part. The legal assessment may also differ for free and open-source software, especially where it is supplied outside a commercial activity. These exclusions are limited and should not be assumed without reviewing the product’s distribution model and commercial context.
When is legal assistance with the Cyber Resilience Act advisable?
Legal support may be needed before a product is launched in the EU, when software is updated, when a company acquires a technology business, or when a manufacturer uses third-party components and open-source code. CRA compliance is also relevant for importers, distributors, online marketplace operators and businesses that sell connected products under a private-label model.
For businesses, a CRA review may involve determining whether a product falls within the Regulation, assigning the role of manufacturer, preparing contractual obligations for suppliers, reviewing vulnerability disclosure processes and documenting cybersecurity governance. It may also require coordination between legal, IT security, product development, compliance and management teams.
Individuals and organisations purchasing digital products may benefit from the CRA because it is intended to strengthen expectations regarding security updates, vulnerability remediation and product information. However, the Regulation does not automatically resolve every dispute concerning defective software, a cyber incident or a security update. Consumer law, contract law, data protection rules and sector-specific regulations may remain relevant.
An early consultation with a lawyer can help identify gaps in product documentation, security processes and supplier arrangements before the product reaches the market. It can reduce the risk of non-compliance, delayed market entry, regulatory action, contractual disputes, cybersecurity incidents and financial losses arising from inadequate vulnerability management.
Legal support concerning the Cyber Resilience Act
Support from a law firm in matters related to the Cyber Resilience Act may include in particular:
- assessing whether a product falls within the scope of the CRA;
- identifying the legal role of the manufacturer, importer or distributor;
- reviewing conformity assessment and CE marking requirements;
- analysing product documentation, user information and security update policies;
- preparing supplier, software development and vulnerability management clauses;
- advising on reporting obligations for actively exploited vulnerabilities and severe incidents;
- supporting audits, internal compliance procedures and regulatory communications;
- coordinating CRA requirements with GDPR, NIS2, DORA and sector-specific rules.
Need assistance with the Cyber Resilience Act? Contact us.