What is CRA?
The CRA (Cyber Resilience Act — EU Regulation 2024/2847) is a European law imposing minimum cybersecurity requirements on any product with digital elements sold in the EU. In short: if your product connects to a network or runs software, it must be secure by design and remain secure throughout its lifetime.
The logic is simple. Until now, machinery or equipment went through physical safety checks (the classic CE marking). The digital side — software, connectivity, updates — was practically unregulated. CRA shifts responsibility for security from the user to the manufacturer: the product must be secure before you sell it, not after someone gets hacked.
Who is affected
Manufacturers, importers and distributors placing products with digital elements on the EU market: machinery with connected control panels, IoT devices, installable applications, software delivered as a standalone product, equipment with online updates. The law applies regardless of where the manufacturer is based — if an EU customer can buy the product, you are affected.
What does NOT fall under CRA
Pure SaaS (all processing on the provider's servers, accessed via browser/API). Note: NIS2 and GDPR remain applicable.
Open-source software developed without a commercial purpose.
Categories covered by other laws (medical devices, automotive, aviation).
Key dates
11 June 2026 — conformity assessment bodies begin accreditation.
11 September 2026 — mandatory reporting of actively exploited vulnerabilities and serious incidents: 24 hours (initial notification), 72 hours (detailed report), 14 days (final report).
11 December 2027 — full application: CE marking and declaration of conformity required for all new products.
Products must also receive security updates for at least 5 years (or the product's lifetime, if shorter).
What you risk
Fines of up to €15 million or 2.5% of global turnover. Note: micro-enterprises and small companies are exempt from the fine for delayed 24h reporting (Art. 64(10)), but the obligation to report remains.
What you need to do, in brief
Determine which products fall under CRA.
Integrate security by design from the start.
Maintain a software component list (SBOM) and a vulnerability management process.
Prepare the technical documentation and declaration of conformity.
Establish the 24h / 72h / 14-day reporting procedure.