Cyber Resilience Act Consultancy

Our Offer to You

  • Decide if the CRA applies to your products
    We compare your products characteristics with the scope of the CRA to see if it is covered.
  • Assessment of your current compliance status

    We evaluate your products, documentation and processes to identify how they align with the Cyber Resilience Act and where improvements are needed.
  • Formulate a clear path to compliance

    We create a tailored roadmap outlining the technical, procedural, and organisational steps required to meet CRA obligations efficiently.
  • Prepare and provide all required documentation
    
Including the EU Declaration of Conformity, technical files, cybersecurity risk assessments, and supporting evidence.
  • Keep you informed of regulatory updates

    We monitor CRA developments, guidance, and harmonised standards to ensure you remain up to date with all changes and deadlines.
  • Act as your Authorised Representative in the EU (if required)

    For non-EU manufacturers, we can serve as your legally appointed Authorised Representative, ensuring you maintain an official presence within the EU market.
  • Coordinate with Notified Bodies where necessary

    While only designated organisations can act as Notified Bodies, we assist by identifying appropriate partners and managing the conformity assessment process on your behalf.
  • Support implementation of technical and procedural improvements
    
We provide hands-on guidance to help integrate secure-by-design principles, vulnerability management, and other measures required for CRA compliance.

About the Cyber Resilience Act

Background on the Cyber Resilience Act (CRA)

The EU Cyber Resilience Act (CRA) introduces robust cybersecurity requirements for connected digital products, aiming to enhance the digital security landscape across the European Union. By setting consistent standards, the CRA empowers consumers and businesses to make informed decisions about the technology they use daily, while levelling the playing field for both EU and non-EU manufacturers.

The regulation is built around two primary objectives to ensure the proper functioning of the internal market:

  • Promote the development of secure digital products. 
This includes reducing the number of vulnerabilities in hardware and software at the time of market launch and requiring manufacturers to prioritise cybersecurity throughout the entire product lifecycle — from design and development to post-sale support.
  • Enable users to factor cybersecurity into their purchasing and usage decisions
. By increasing transparency and requiring clearer information on security features, the CRA helps users assess the cybersecurity of digital products more easily.

Important Dates for Cyber Resilience Act

DateRequirement
20 November 2024CRA published in the Official Journal of the EU
10 December 2024CRA entered into force to give manufacturers and others affected time to prepare.
11 June 2026Rules relating to conformity assessment bodies begin to apply
11 September 2026Vulnerability and incident reporting obligations apply
11 December 2027Full CRA compliance required

Scope of the CRA

The CRA applies to all products with digital elements that are placed on the EU market – including both hardware and software. This means that any digital product which connects directly or indirectly to a device or network falls within its scope.
The regulation is intentionally broad to cover the wide range of technologies that form today’s connected ecosystem. It applies equally to EU-based manufacturers and non-EU companies that supply products into the European market.

Products within scope include:

  • Consumer and industrial Internet of Things (IoT) devices such as smart home products, sensors, and wearables
  • Software applications, both standalone and embedded, including mobile apps and cloud-connected tools
  • Networking equipment such as routers, modems, and gateways
  • Embedded systems and firmware used in connected machinery and consumer electronics
  • Cybersecurity software such as firewalls, password managers, and antivirus tools

Certain products that are already regulated under existing EU legislation – such as medical devices, vehicles, or aviation systems – are exempt from the CRA if those regulations already contain equivalent cybersecurity requirements.

The CRA therefore establishes a baseline level of cybersecurity across all digital products, closing gaps where no such standards previously existed. It ensures that every connected digital product entering the EU market meets consistent security requirements and remains protected throughout its lifecycle.

Examples of Products Covered by the CRA

To help illustrate the scope, below are examples of products that will typically fall under the CRA:

Consumer Electronics & Smart Home Devices

  • Computers and mobile devices
  • Smart light bulbs, sockets, and switches
  • Smart speakers, voice assistants, and connected televisions
  • Home security systems, cameras, and video doorbells
  • Smart thermostats and energy monitoring systems
  • Wearable fitness trackers and smartwatches

Software and Applications

  • Productivity and collaboration software
  • Communication tools and messaging platforms
  • Mobile apps connected to IoT devices
  • Cloud-based applications and SaaS platforms
  • Cybersecurity software such as VPNs, password managers, and antivirus tools

Networking & Connectivity Equipment

  • Wi-Fi routers, mesh systems, and modems
  • Gateways and IoT hubs
  • Network storage devices and smart switches

Industrial and Commercial Products

  • Connected sensors and controllers used in manufacturing
  • Industrial IoT devices and monitoring systems
  • Smart vending machines and self-service kiosks
  • Building management and automation systems

Excluded or Partially Covered Products

Some product categories are already regulated under existing EU laws that include cybersecurity provisions.

These include:

  • Medical devices (covered by the MDR and IVDR)
  • Motor vehicles (under vehicle type-approval regulations)
  • Aviation, defence, and railway systems
  • Certain radio devices (already covered under the Radio Equipment Directive)

Requirements of Economic Operators

The CRA places distinct obligations on all economic operators involved in the design, manufacture, import, and distribution of digital products within the EU market. These roles ensure that cybersecurity responsibilities are shared across the supply chain, maintaining consistent security standards from production to end user.

Manufacturers

Manufacturers hold the primary responsibility for ensuring that digital products meet the essential cybersecurity requirements of the CRA.

Their obligations include:

  • Designing and developing secure products that are free from known exploitable vulnerabilities at the time of placing them on the market.
  • Implementing secure-by-design and secure-by-default principles across the entire product lifecycle.
  • Conducting and documenting cybersecurity risk assessments.
  • Maintaining a vulnerability management process, including mechanisms for updates and patches.
  • Preparing and retaining technical documentation and an EU Declaration of Conformity.
  • Reporting actively exploited vulnerabilities and incidents to ENISA (the European Network and Information Security Agency).
  • Ensuring that products carry the CE marking to demonstrate conformity.

Manufacturers outside the EU must appoint an Authorised Representative established within the EU to act on their behalf.

Authorised Representatives

Authorised Representatives (ARs) act as the official point of contact for non-EU manufacturers. Their responsibilities include:

  • Keeping the manufacturer’s EU Declaration of Conformity and technical documentation for at least 10 years.
  • Cooperating with EU market surveillance authorities upon request.
  • Ensuring that corrective actions are taken if a product is found to be non-compliant.
  • Assisting in incident response and communication with authorities regarding vulnerabilities or recalls.

Importers

Importers are responsible for ensuring that products they bring into the EU market comply with the CRA before being made available for sale.

Their duties include:

  • Verifying that the manufacturer has completed the conformity assessment and prepared the required documentation.
  • Ensuring the product bears the CE marking and includes appropriate cybersecurity information and instructions.
  • Keeping a copy of the Declaration of Conformity for at least 10 years.
  • Taking corrective measures or withdrawing products if compliance issues arise.

Distributors

Distributors also play an important role in maintaining cybersecurity compliance.

They must:

  • Verify that products display the required markings and documentation before sale.
  • Ensure that storage and transport do not compromise the product’s cybersecurity integrity.
  • Refrain from marketing or distributing products they know (or suspect) to be non-compliant.
  • Cooperate with manufacturers, importers, and authorities during any compliance or recall process.

Shared Responsibilities

All economic operators are expected to:

  • Cooperate fully with authorities during market surveillance investigations.
  • Preserve documentation and traceability across the supply chain.
  • Ensure timely updates and security patches are made available to users.

Flowchart to Determine if the EU CRA Applies to your Products

cyber resillience flowchart

At Product Compliance Support, we assist all types of economic operators – from manufacturers and importers to distributors and authorised representatives – in understanding and fulfilling their specific CRA obligations. Our services include compliance audits, documentation support, and liaison with EU authorities to help ensure your products meet all regulatory requirements.

Read more: How to comply with the Cyber Resilience Act

Or you can read our Cyber Resilience Act FAQs