Takes Effect December 11, 2027 - Start Preparing Now

EU Cyber Resilience Act (CRA)

If you make or sell digital products in Europe (software, IoT devices, smart appliances, apps), the CRA requires you to build in cybersecurity from day one. Products without proper security can't enter the EU market after December 2027.

Dec 2027
Full application (reporting from Sep 2026)
€15M fines
Maximum penalties
4 risk categories
Default, Important I & II, Critical

The CRA in Plain English

The Cyber Resilience Act is the EU's new law that says any product with software sold in Europe must be secure by design. Think of it as a safety requirement for digital products - just like cars need seatbelts, digital products need cybersecurity.

This isn't just about big tech companies. If you make or sell anything with software - from a simple mobile app to a smart thermostat - the CRA applies to you. The law recognizes that cyberattacks are getting worse, and consumers deserve products that are secure from day one.

What makes this different? Unlike voluntary security guidelines, the CRA has legal teeth. You can't just add security as an afterthought. You must build it into your product from the very beginning, document what you've done, and keep your products secure for years after you sell them. It's a fundamental shift from 'security is optional' to 'security is mandatory'.

Standards can help: While the CRA does not mandate specific standards, established frameworks like ENISA Guidelines, IEC 62443, and ISO/IEC 27001 can help demonstrate conformity with Annex I requirements. However, no harmonised standards have been formally cited in the Official Journal yet — the Commission's standardisation request to CEN/CENELEC/ETSI is ongoing with first deliverables expected Q3 2026. Until then, using these standards is good practice but does not give a legal presumption of conformity.

Applies to hardware with software (smart devices, IoT, connected appliances)
Applies to standalone software (apps, operating systems, firmware)
Requires security updates for the support period (proportionate to expected product lifetime, minimum 5 years unless expected lifetime is shorter)
Manufacturers responsible for ongoing security updates and vulnerability fixes
CE marking required to enter EU market (same process as other safety regulations)
Penalties up to €15 million or 2.5% global revenue for non-compliance
Covers commercial products; open source stewards have lighter obligations
Includes supply chain security - you're responsible for third-party components
ENISA Guidelines and existing standards (IEC 62443, ISO 27001) are good practice but do NOT yet give presumption of conformity
No harmonised standards have been formally cited in the Official Journal yet (expected Q3 2026)
Once published, harmonised standards under Art. 27 will provide presumption of conformity

Why CRA Compliance Matters for Your Business

Beyond avoiding penalties, CRA compliance represents a strategic advantage. Companies that implement security by design reduce their risk of costly breaches, build customer trust, and gain competitive differentiation in an increasingly security-conscious market.

Risk Reduction
Proactive compliance reduces the risk of costly breaches and enforcement actions
Market Access
Compliance is a prerequisite for placing products and services on the EU market
Customer Trust
Demonstrable compliance builds confidence with customers and partners

What CRA Actually Requires You to Do

The CRA establishes essential cybersecurity requirements that apply throughout your product's lifecycle. These aren't just theoretical guidelines—they're practical obligations with legal consequences.

Think of it this way: Just as you need safety standards for physical products (crash tests for cars, fire safety for electronics), the CRA creates mandatory security standards for digital products. Every requirement serves a specific purpose in protecting end users and the broader digital ecosystem.

Core Requirement 1

Security by Design

Build security into products from the start per Annex I Part I

This means integrating security considerations from the very first design sketches. No more 'we'll add security later'—it must be part of your core product development process from day one.

Specific Requirements:

• Secure development lifecycle
• Threat modelling
• Secure default configurations

💡 Practical Tip:

Start by conducting threat modeling sessions during your product planning phase. Many teams find Microsoft's STRIDE methodology helpful for systematic threat identification.

Core Requirement 2

Vulnerability Handling

Handle security issues per Annex I Part II requirements

You must establish a coordinated vulnerability disclosure process, maintain security throughout the product lifecycle, and respond quickly to security issues. This isn't just about fixing bugs—it's about professional incident response.

Specific Requirements:

• Vulnerability disclosure policy
• Internal handling procedures
• Incident response capability

💡 Practical Tip:

Set up a [email protected] email address and establish SLAs for response times. Consider partnering with vulnerability disclosure platforms like HackerOne or Bugcrowd.

Core Requirement 3

Documentation

Provide clear security information to users

Clear, accessible documentation helps users understand security features and configure products safely. This reduces support calls and prevents security misconfigurations that could lead to breaches.

Specific Requirements:

• Technical documentation
• EU declaration
• User guidance

💡 Practical Tip:

Create user-friendly security guides alongside your regular documentation. Include clear setup instructions, common security mistakes to avoid, and troubleshooting guidance.

Core Requirement 4

Risk Assessment

Classify products by cybersecurity risk level

Products must be assessed for their potential impact if compromised. Critical infrastructure products face stricter requirements than consumer apps, reflecting their different risk profiles.

Specific Requirements:

• Risk classification
• Impact analysis
• Mitigation measures

💡 Practical Tip:

Use risk assessment frameworks like NIST Cybersecurity Framework to systematically evaluate your product's risk level. Document your reasoning for audit purposes.

Core Requirement 5

Supply Chain Security

Ensure third-party components meet CRA requirements

You're responsible for the security of all components in your product, including third-party libraries and dependencies. This creates accountability throughout the entire supply chain.

Specific Requirements:

• Component due diligence
• Software Bill of Materials (SBOM)
• Dependency vulnerability tracking

💡 Practical Tip:

Implement Software Bill of Materials (SBOM) tracking from the start. Tools like Syft, CycloneDX, or SPDX can help automate component inventory management.

Core Requirement 6

CE Marking

Affix CE marking and provide conformity declarations

CE marking for cybersecurity works like CE marking for other product safety aspects. It's your declaration that the product meets EU security requirements and is safe to place on the market.

Specific Requirements:

• Conformity assessment
• CE marking placement
• Declaration of conformity

💡 Practical Tip:

Work with a notified body early in your process to understand specific conformity assessment requirements for your product category and risk level.

The Bottom Line

CRA requirements aren't just compliance checkboxes—they represent cybersecurity best practices that protect your customers, your business, and the broader digital ecosystem. Companies that implement these requirements early often find they reduce long-term security costs while building stronger, more trustworthy products.

Common CRA Questions

Can existing standards help with CRA compliance?

Yes, but they are voluntary — CRA does not mandate specific standards. Useful frameworks include:

  • IEC 62443-4-1 and 4-2 for secure product development practices
  • ISO/IEC 27001 for organizational security management
  • ISO/IEC 29147 and 30111 for vulnerability disclosure and handling
  • Once published, harmonised standards will provide presumption of conformity

What products are covered by CRA?

CRA covers any product with digital elements sold in the EU:

  • Software products (apps, operating systems, etc.)
  • Hardware with embedded software (IoT devices, smart appliances)
  • Connected products (anything that connects to a network)
  • Digital services that are part of a physical product

What are the CRA product categories?

CRA classifies products into four categories with different conformity assessment requirements:

  • Default category: Basic security requirements, self-assessment (Module A)
  • Important Class I (Annex III, Part I): Self-assessment if harmonised standards applied, otherwise third-party
  • Important Class II (Annex III, Part II): Always requires third-party assessment
  • Critical (Annex IV): Always requires third-party assessment or EU cybersecurity certification

What if my product is already CE marked?

Existing CE marking doesn't cover CRA requirements. You'll need to:

  • Add cybersecurity requirements to your conformity assessment
  • Update your EU declaration of conformity
  • Ensure your technical documentation covers CRA requirements
  • You may be able to use existing quality management processes

What about open source components?

CRA applies to manufacturers who place products on the EU market:

  • If you sell a product using open source, you're responsible for CRA compliance
  • Open source developers are generally not liable unless they commercialize
  • You must identify and track all open source components (SBOM)
  • Consider the security posture of your open source dependencies

When do I need to start preparing?

Start now, even though CRA takes effect in December 2027:

  • Product development cycles can take 1-3 years
  • Security-by-design requires early planning
  • Documentation and processes take time to implement
  • Third-party assessments may have long lead times

🤝 Still Feeling Overwhelmed?

EU cybersecurity laws can be complex. Our free tools and guides work great for most people, but if you're dealing with something particularly challenging or have tight deadlines, we're here to help.