Decide if the CRA applies to your products We compare your products characteristics with the scope of the CRA to see if it is covered.
Assessment of your current compliance status We evaluate your products, documentation and processes to identify how they align with the Cyber Resilience Act and where improvements are needed.
Formulate a clear path to compliance We create a tailored roadmap outlining the technical, procedural, and organisational steps required to meet CRA obligations efficiently.
Prepare and provide all required documentation Including the EU Declaration of Conformity, technical files, cybersecurity risk assessments, and supporting evidence.
Keep you informed of regulatory updates We monitor CRA developments, guidance, and harmonised standards to ensure you remain up to date with all changes and deadlines.
Act as your Authorised Representative in the EU (if required) For non-EU manufacturers, we can serve as your legally appointed Authorised Representative, ensuring you maintain an official presence within the EU market.
Coordinate with Notified Bodies where necessary While only designated organisations can act as Notified Bodies, we assist by identifying appropriate partners and managing the conformity assessment process on your behalf.
Support implementation of technical and procedural improvements We provide hands-on guidance to help integrate secure-by-design principles, vulnerability management, and other measures required for CRA compliance.
The EU Cyber Resilience Act (CRA) introduces robust cybersecurity requirements for connected digital products, aiming to enhance the digital security landscape across the European Union. By setting consistent standards, the CRA empowers consumers and businesses to make informed decisions about the technology they use daily, while levelling the playing field for both EU and non-EU manufacturers.
The regulation is built around two primary objectives to ensure the proper functioning of the internal market:
Promote the development of secure digital products. This includes reducing the number of vulnerabilities in hardware and software at the time of market launch and requiring manufacturers to prioritise cybersecurity throughout the entire product lifecycle — from design and development to post-sale support.
Enable users to factor cybersecurity into their purchasing and usage decisions . By increasing transparency and requiring clearer information on security features, the CRA helps users assess the cybersecurity of digital products more easily.
Important Dates for Cyber Resilience Act
Date
Requirement
20 November 2024
CRA published in the Official Journal of the EU
10 December 2024
CRA entered into force to give manufacturers and others affected time to prepare.
11 June 2026
Rules relating to conformity assessment bodies begin to apply
11 September 2026
Vulnerability and incident reporting obligations apply
11 December 2027
Full CRA compliance required
Scope of the CRA
The CRA applies to all products with digital elements that are placed on the EU market – including both hardware and software. This means that any digital product which connects directly or indirectly to a device or network falls within its scope. The regulation is intentionally broad to cover the wide range of technologies that form today’s connected ecosystem. It applies equally to EU-based manufacturers and non-EU companies that supply products into the European market.
Products within scope include:
Consumer and industrial Internet of Things (IoT) devices such as smart home products, sensors, and wearables
Software applications, both standalone and embedded, including mobile apps and cloud-connected tools
Networking equipment such as routers, modems, and gateways
Embedded systems and firmware used in connected machinery and consumer electronics
Cybersecurity software such as firewalls, password managers, and antivirus tools
Certain products that are already regulated under existing EU legislation – such as medical devices, vehicles, or aviation systems – are exempt from the CRA if those regulations already contain equivalent cybersecurity requirements.
The CRA therefore establishes a baseline level of cybersecurity across all digital products, closing gaps where no such standards previously existed. It ensures that every connected digital product entering the EU market meets consistent security requirements and remains protected throughout its lifecycle.
Examples of Products Covered by the CRA
To help illustrate the scope, below are examples of products that will typically fall under the CRA:
Consumer Electronics & Smart Home Devices
Computers and mobile devices
Smart light bulbs, sockets, and switches
Smart speakers, voice assistants, and connected televisions
Home security systems, cameras, and video doorbells
Smart thermostats and energy monitoring systems
Wearable fitness trackers and smartwatches
Software and Applications
Productivity and collaboration software
Communication tools and messaging platforms
Mobile apps connected to IoT devices
Cloud-based applications and SaaS platforms
Cybersecurity software such as VPNs, password managers, and antivirus tools
Networking & Connectivity Equipment
Wi-Fi routers, mesh systems, and modems
Gateways and IoT hubs
Network storage devices and smart switches
Industrial and Commercial Products
Connected sensors and controllers used in manufacturing
Industrial IoT devices and monitoring systems
Smart vending machines and self-service kiosks
Building management and automation systems
Excluded or Partially Covered Products
Some product categories are already regulated under existing EU laws that include cybersecurity provisions.
These include:
Medical devices (covered by the MDR and IVDR)
Motor vehicles (under vehicle type-approval regulations)
Aviation, defence, and railway systems
Certain radio devices (already covered under the Radio Equipment Directive)
Requirements of Economic Operators
The CRA places distinct obligations on all economic operators involved in the design, manufacture, import, and distribution of digital products within the EU market. These roles ensure that cybersecurity responsibilities are shared across the supply chain, maintaining consistent security standards from production to end user.
Manufacturers
Manufacturers hold the primary responsibility for ensuring that digital products meet the essential cybersecurity requirements of the CRA.
Their obligations include:
Designing and developing secure products that are free from known exploitable vulnerabilities at the time of placing them on the market.
Implementing secure-by-design and secure-by-default principles across the entire product lifecycle.
Conducting and documenting cybersecurity risk assessments.
Maintaining a vulnerability management process, including mechanisms for updates and patches.
Preparing and retaining technical documentation and an EU Declaration of Conformity.
Reporting actively exploited vulnerabilities and incidents to ENISA (the European Network and Information Security Agency).
Ensuring that products carry the CE marking to demonstrate conformity.
Manufacturers outside the EU must appoint an Authorised Representative established within the EU to act on their behalf.
Authorised Representatives
Authorised Representatives (ARs) act as the official point of contact for non-EU manufacturers. Their responsibilities include:
Keeping the manufacturer’s EU Declaration of Conformity and technical documentation for at least 10 years.
Cooperating with EU market surveillance authorities upon request.
Ensuring that corrective actions are taken if a product is found to be non-compliant.
Assisting in incident response and communication with authorities regarding vulnerabilities or recalls.
Importers
Importers are responsible for ensuring that products they bring into the EU market comply with the CRA before being made available for sale.
Their duties include:
Verifying that the manufacturer has completed the conformity assessment and prepared the required documentation.
Ensuring the product bears the CE marking and includes appropriate cybersecurity information and instructions.
Keeping a copy of the Declaration of Conformity for at least 10 years.
Taking corrective measures or withdrawing products if compliance issues arise.
Distributors
Distributors also play an important role in maintaining cybersecurity compliance.
They must:
Verify that products display the required markings and documentation before sale.
Ensure that storage and transport do not compromise the product’s cybersecurity integrity.
Refrain from marketing or distributing products they know (or suspect) to be non-compliant.
Cooperate with manufacturers, importers, and authorities during any compliance or recall process.
Shared Responsibilities
All economic operators are expected to:
Cooperate fully with authorities during market surveillance investigations.
Preserve documentation and traceability across the supply chain.
Ensure timely updates and security patches are made available to users.
Flowchart to Determine if the EU CRA Applies to your Products
At Product Compliance Support, we assist all types of economic operators – from manufacturers and importers to distributors and authorised representatives – in understanding and fulfilling their specific CRA obligations. Our services include compliance audits, documentation support, and liaison with EU authorities to help ensure your products meet all regulatory requirements.