EU Cyber Resilience Act (CRA)
If you make or sell digital products in Europe (software, IoT devices, smart appliances, apps), the CRA requires you to build in cybersecurity from day one. Products without proper security can't enter the EU market after December 2027.
The CRA in Plain English
The Cyber Resilience Act is the EU's new law that says any product with software sold in Europe must be secure by design. Think of it as a safety requirement for digital products - just like cars need seatbelts, digital products need cybersecurity.
This isn't just about big tech companies. If you make or sell anything with software - from a simple mobile app to a smart thermostat - the CRA applies to you. The law recognizes that cyberattacks are getting worse, and consumers deserve products that are secure from day one.
What makes this different? Unlike voluntary security guidelines, the CRA has legal teeth. You can't just add security as an afterthought. You must build it into your product from the very beginning, document what you've done, and keep your products secure for years after you sell them. It's a fundamental shift from 'security is optional' to 'security is mandatory'.
Standards can help: While the CRA does not mandate specific standards, established frameworks like ENISA Guidelines, IEC 62443, and ISO/IEC 27001 can help demonstrate conformity with Annex I requirements. However, no harmonised standards have been formally cited in the Official Journal yet — the Commission's standardisation request to CEN/CENELEC/ETSI is ongoing with first deliverables expected Q3 2026. Until then, using these standards is good practice but does not give a legal presumption of conformity.
Start Here - Pick What Fits You Best
Choose your path based on your situation and timeline
Compliance Standards
Explore 8 international standards mapped to CRA requirements
Quick Assessment
Find out if CRA applies to your products in 5 minutes
Browse CRA Articles
Read all 71 CRA articles with highlights and notes
Product Check
Check specific products against CRA requirements
Download Checklist
Get a complete CRA compliance checklist to work offline
RACI Matrix
See who is responsible for each CRA obligation by supply chain role
Step-by-Step Guide
Follow our detailed implementation roadmap
Get Expert Help
Work with our compliance specialists
Learn the Timeline
Understand key dates and deadlines
Why CRA Compliance Matters for Your Business
Beyond avoiding penalties, CRA compliance represents a strategic advantage. Companies that implement security by design reduce their risk of costly breaches, build customer trust, and gain competitive differentiation in an increasingly security-conscious market.
What CRA Actually Requires You to Do
The CRA establishes essential cybersecurity requirements that apply throughout your product's lifecycle. These aren't just theoretical guidelines—they're practical obligations with legal consequences.
Think of it this way: Just as you need safety standards for physical products (crash tests for cars, fire safety for electronics), the CRA creates mandatory security standards for digital products. Every requirement serves a specific purpose in protecting end users and the broader digital ecosystem.
Security by Design
Build security into products from the start per Annex I Part I
This means integrating security considerations from the very first design sketches. No more 'we'll add security later'—it must be part of your core product development process from day one.
Specific Requirements:
💡 Practical Tip:
Start by conducting threat modeling sessions during your product planning phase. Many teams find Microsoft's STRIDE methodology helpful for systematic threat identification.
Vulnerability Handling
Handle security issues per Annex I Part II requirements
You must establish a coordinated vulnerability disclosure process, maintain security throughout the product lifecycle, and respond quickly to security issues. This isn't just about fixing bugs—it's about professional incident response.
Specific Requirements:
💡 Practical Tip:
Set up a [email protected] email address and establish SLAs for response times. Consider partnering with vulnerability disclosure platforms like HackerOne or Bugcrowd.
Documentation
Provide clear security information to users
Clear, accessible documentation helps users understand security features and configure products safely. This reduces support calls and prevents security misconfigurations that could lead to breaches.
Specific Requirements:
💡 Practical Tip:
Create user-friendly security guides alongside your regular documentation. Include clear setup instructions, common security mistakes to avoid, and troubleshooting guidance.
Risk Assessment
Classify products by cybersecurity risk level
Products must be assessed for their potential impact if compromised. Critical infrastructure products face stricter requirements than consumer apps, reflecting their different risk profiles.
Specific Requirements:
💡 Practical Tip:
Use risk assessment frameworks like NIST Cybersecurity Framework to systematically evaluate your product's risk level. Document your reasoning for audit purposes.
Supply Chain Security
Ensure third-party components meet CRA requirements
You're responsible for the security of all components in your product, including third-party libraries and dependencies. This creates accountability throughout the entire supply chain.
Specific Requirements:
💡 Practical Tip:
Implement Software Bill of Materials (SBOM) tracking from the start. Tools like Syft, CycloneDX, or SPDX can help automate component inventory management.
CE Marking
Affix CE marking and provide conformity declarations
CE marking for cybersecurity works like CE marking for other product safety aspects. It's your declaration that the product meets EU security requirements and is safe to place on the market.
Specific Requirements:
💡 Practical Tip:
Work with a notified body early in your process to understand specific conformity assessment requirements for your product category and risk level.
The Bottom Line
CRA requirements aren't just compliance checkboxes—they represent cybersecurity best practices that protect your customers, your business, and the broader digital ecosystem. Companies that implement these requirements early often find they reduce long-term security costs while building stronger, more trustworthy products.
Free CRA Compliance Tools
Get started with our comprehensive toolkit designed to simplify your compliance journey. Each tool is built by experts and validated against official requirements.
Assessment & Planning
CRA Gap Analysis
Assess your compliance with CRA Annex I requirements
Product Checker
Check if your products are covered by CRA
Secure Development Checklist
CRA requirements checklist (with optional IEC 62443 mapping)
Implementation & Documentation
CRA Documentation Templates
Templates for CRA technical documentation (ISO 27001 compatible)
Risk Calculator
Determine your product category (default/important/critical)
CRA Timeline
View key deadlines and implementation milestones
RACI Matrix
See who is responsible for each CRA obligation by role
Harmonised Standards Guide
Type A/B/C hierarchy, base standards, amendment status and conformity routes
Common CRA Questions
Can existing standards help with CRA compliance?
Yes, but they are voluntary — CRA does not mandate specific standards. Useful frameworks include:
- IEC 62443-4-1 and 4-2 for secure product development practices
- ISO/IEC 27001 for organizational security management
- ISO/IEC 29147 and 30111 for vulnerability disclosure and handling
- Once published, harmonised standards will provide presumption of conformity
What products are covered by CRA?
CRA covers any product with digital elements sold in the EU:
- Software products (apps, operating systems, etc.)
- Hardware with embedded software (IoT devices, smart appliances)
- Connected products (anything that connects to a network)
- Digital services that are part of a physical product
What are the CRA product categories?
CRA classifies products into four categories with different conformity assessment requirements:
- Default category: Basic security requirements, self-assessment (Module A)
- Important Class I (Annex III, Part I): Self-assessment if harmonised standards applied, otherwise third-party
- Important Class II (Annex III, Part II): Always requires third-party assessment
- Critical (Annex IV): Always requires third-party assessment or EU cybersecurity certification
What if my product is already CE marked?
Existing CE marking doesn't cover CRA requirements. You'll need to:
- Add cybersecurity requirements to your conformity assessment
- Update your EU declaration of conformity
- Ensure your technical documentation covers CRA requirements
- You may be able to use existing quality management processes
What about open source components?
CRA applies to manufacturers who place products on the EU market:
- If you sell a product using open source, you're responsible for CRA compliance
- Open source developers are generally not liable unless they commercialize
- You must identify and track all open source components (SBOM)
- Consider the security posture of your open source dependencies
When do I need to start preparing?
Start now, even though CRA takes effect in December 2027:
- Product development cycles can take 1-3 years
- Security-by-design requires early planning
- Documentation and processes take time to implement
- Third-party assessments may have long lead times