CRA Overview

Understanding the EU Cyber Resilience Act and its impact on digital products

What is the Cyber Resilience Act?

The CRA is the first EU-wide legislation introducing mandatory cybersecurity requirements for products with digital elements. Manufacturers must ensure security throughout the defined support period (proportionate to expected product lifetime, minimum 5 years unless expected lifetime is shorter), ensuring products are secure by design.

Regulation Overview

The Cyber Resilience Act (CRA) represents a paradigm shift in product cybersecurity, moving from voluntary best practices to mandatory legal requirements. This regulation ensures that all products with digital elements sold in the EU market are secure by design and remain secure throughout their defined support period.

36 months
Implementation period
All
Digital products covered
5+ years
Minimum security support

Scope and Applicability

The CRA applies to all products with digital elements placed on the EU market, including:

Covered Products

  • Consumer IoT devices
  • Industrial control systems
  • Network equipment
  • Operating systems and firmware
  • Mobile applications
  • Cloud services integrated with hardware

Exemptions

  • Medical devices (covered by MDR)
  • Aviation products (covered by EASA)
  • Motor vehicles (covered by UNECE)
  • Products for national security only
  • Pure volunteer open source without commercial activity
  • Micro/small enterprises have lighter administrative burden

Product Categories

The CRA divides products into four categories based on their cybersecurity risk. Important Products are split into Class I (Annex III, Part I) and Class II (Annex III, Part II) with different conformity assessment requirements:

Default Products

Standard consumer products with digital elements

Requirements: Essential cybersecurity requirements, internal control assessment

Important Products (Annex III)

Class I (Part I): self-assessment if harmonised standards applied; Class II (Part II): third-party required

Requirements: Enhanced security requirements; conformity route depends on class

Critical Products (Annex IV)

Products essential for security or safety

Requirements: Strictest security requirements, mandatory third-party certification

Implementation Timeline

The CRA follows a phased implementation approach:

Entry into Force

CRA becomes law 20 days after publication

December 10, 2024
100%

Reporting Obligations

21 months after entry into force

September 2026
75%

Harmonised Standards (Projected)

Target: 24 months for standards development

June 2026
25%

Full Application

36 months implementation period ends

December 2027
0%
Article Article 1 · Subject matter and scope
View on EUR-Lex

Impact on Stakeholders

The CRA establishes clear obligations based on your role in the supply chain. Your classification depends on who designs the product, who places it on the EU market, and under whose name it's sold:

Manufacturers (Primary Responsibility)

  • • Ensure products meet essential requirements (Annex I)
  • • Implement security by design
  • • Establish vulnerability management
  • • Provide security updates for the support period (min. 5 years, or shorter if expected product lifetime is less)
  • • Report actively exploited vulnerabilities to ENISA (24h early warning, 72h full notification)

Importers

  • • Verify manufacturer compliance before import
  • • Ensure proper CE marking and documentation
  • • Cooperate with market surveillance authorities
  • • Forward security information to manufacturers

Distributors

  • • Verify CE marking and required documentation
  • • Ensure secure storage and transport
  • • Report suspected non-compliance to authorities
  • • Support distribution of security updates

Open Source Stewards

  • • Light-touch obligations only (not full conformity)
  • • Document cybersecurity policy
  • • Report actively exploited vulnerabilities
  • • Exempt from CRA monetary penalties

Start Preparation Now

Organizations should begin compliance preparations immediately. The 36-month transition period allows time for adapting existing products and establishing new processes, but early action is essential for success.

Need CRA Compliance Support?

Our expert team can guide you through every step of CRA compliance, from initial assessment to ongoing monitoring.

Crosswalk · From the team behind this site

Reading is one thing. Crosswalk turns the CRA into an assessment.

Crosswalk walks you through Annex I Part I and Part II, the Art. 13 and Art. 14 duties, the Annex II information to the user and the Annex VII technical documentation, per product and for the organisation. Each requirement comes with the article text next to it, the questions an auditor asks, and a place for your evidence.

  • Gap analysis against the CRA articles, with what is still open in priority order
  • Annex VII technical documentation compiled from your own answers
  • Security testing and secure code review checklists, mapped to Annex I Part II(3)
An example CRA report, as the app produces it (PDF)

Lite licence at €0 at launch: one project, all five laws, no payment details. Paid plans from €99 per person per month; the Lite licence comes with a 14-day trial of one of them.

🤝 Still Feeling Overwhelmed by CRA?

The Cyber Resilience Act has a lot of moving parts. Our free tools work great for most people, but if you're dealing with something really complex or have a tight deadline, we can help you figure it out faster.