CRA Overview
Understanding the EU Cyber Resilience Act and its impact on digital products
What is the Cyber Resilience Act?
The CRA is the first EU-wide legislation introducing mandatory cybersecurity requirements for products with digital elements. Manufacturers must ensure security throughout the defined support period (proportionate to expected product lifetime, minimum 5 years unless expected lifetime is shorter), ensuring products are secure by design.
Regulation Overview
The Cyber Resilience Act (CRA) represents a paradigm shift in product cybersecurity, moving from voluntary best practices to mandatory legal requirements. This regulation ensures that all products with digital elements sold in the EU market are secure by design and remain secure throughout their defined support period.
Scope and Applicability
The CRA applies to all products with digital elements placed on the EU market, including:
Covered Products
- Consumer IoT devices
- Industrial control systems
- Network equipment
- Operating systems and firmware
- Mobile applications
- Cloud services integrated with hardware
Exemptions
- Medical devices (covered by MDR)
- Aviation products (covered by EASA)
- Motor vehicles (covered by UNECE)
- Products for national security only
- Pure volunteer open source without commercial activity
- Micro/small enterprises have lighter administrative burden
Product Categories
The CRA divides products into four categories based on their cybersecurity risk. Important Products are split into Class I (Annex III, Part I) and Class II (Annex III, Part II) with different conformity assessment requirements:
Default Products
Standard consumer products with digital elements
Requirements: Essential cybersecurity requirements, internal control assessment
Important Products (Annex III)
Class I (Part I): self-assessment if harmonised standards applied; Class II (Part II): third-party required
Requirements: Enhanced security requirements; conformity route depends on class
Critical Products (Annex IV)
Products essential for security or safety
Requirements: Strictest security requirements, mandatory third-party certification
Implementation Timeline
The CRA follows a phased implementation approach:
Entry into Force
CRA becomes law 20 days after publication
Reporting Obligations
21 months after entry into force
Harmonised Standards (Projected)
Target: 24 months for standards development
Full Application
36 months implementation period ends
Impact on Stakeholders
The CRA establishes clear obligations based on your role in the supply chain. Your classification depends on who designs the product, who places it on the EU market, and under whose name it's sold:
Manufacturers (Primary Responsibility)
- • Ensure products meet essential requirements (Annex I)
- • Implement security by design
- • Establish vulnerability management
- • Provide security updates for the support period (min. 5 years, or shorter if expected product lifetime is less)
- • Report actively exploited vulnerabilities to ENISA (24h early warning, 72h full notification)
Importers
- • Verify manufacturer compliance before import
- • Ensure proper CE marking and documentation
- • Cooperate with market surveillance authorities
- • Forward security information to manufacturers
Distributors
- • Verify CE marking and required documentation
- • Ensure secure storage and transport
- • Report suspected non-compliance to authorities
- • Support distribution of security updates
Open Source Stewards
- • Light-touch obligations only (not full conformity)
- • Document cybersecurity policy
- • Report actively exploited vulnerabilities
- • Exempt from CRA monetary penalties
Start Preparation Now
Organizations should begin compliance preparations immediately. The 36-month transition period allows time for adapting existing products and establishing new processes, but early action is essential for success.
Need CRA Compliance Support?
Our expert team can guide you through every step of CRA compliance, from initial assessment to ongoing monitoring.
Reading is one thing. Crosswalk turns the CRA into an assessment.
Crosswalk walks you through Annex I Part I and Part II, the Art. 13 and Art. 14 duties, the Annex II information to the user and the Annex VII technical documentation, per product and for the organisation. Each requirement comes with the article text next to it, the questions an auditor asks, and a place for your evidence.
- Gap analysis against the CRA articles, with what is still open in priority order
- Annex VII technical documentation compiled from your own answers
- Security testing and secure code review checklists, mapped to Annex I Part II(3)
Lite licence at €0 at launch: one project, all five laws, no payment details. Paid plans from €99 per person per month; the Lite licence comes with a 14-day trial of one of them.