Cyber Resilience Act: What Digital Product Providers Must Know About Authorised Representatives and Compliance

The European Union’s Cyber Resilience Act (CRA) is introducing new cybersecurity standards to ensure digital products are safer for users. While the legislation officially took effect on December 10, 2024, companies will have until December 11, 2027, to fully comply with its requirements.

What the Cyber Resilience Act Covers

The CRA applies to digital products that connect to networks, including both software and hardware. This means everything from smart home devices and wearables to industrial equipment will need to meet stricter cybersecurity standards. However, products already regulated under specific EU laws, such as medical and automotive devices, are excluded.

The law is designed to address growing concerns about cybersecurity vulnerabilities by requiring stronger protections from the outset. Companies will need to ensure products are developed with security in mind and continue to provide necessary updates after release.

Who Is Affected?

The new regulations impact several key players in the supply chain:

  • Manufacturers must integrate cybersecurity features into product design, eliminate known vulnerabilities before launch, and provide security updates throughout the product’s lifecycle. They must also report and fix any security weaknesses that arise.
  • Importers and Distributors will be responsible for verifying that products comply with CRA requirements before they enter the EU market. Digital products must also carry the CE marking as proof of compliance.
  • Consumers will benefit from stronger security protections and greater transparency about the cybersecurity features of the products they purchase.

Digital Products and the Role of Authorised Representatives

While physical products typically include the Authorised Representative’s details on the product label, packaging, or printed materials, digital-only products like applications and downloadable software require a different approach. For these, the representative’s name and address must be made easily accessible in digital format. This can be done through in-app menus, digital help sections, user agreements, or wherever product information is displayed online. The essential requirement is that the contact information is clearly linked to the product and readily available to users and authorities, in line with the transparency demands of the Cyber Resilience Act.

Ensuring Your Digital Products Meet CRA Compliance

Businesses involved in developing or distributing digital products in the EU should act now to meet the CRA’s cybersecurity standards. Start by reviewing existing products for potential vulnerabilities and ensure they are designed with security features active by default. Establish a clear process for issuing updates and reporting security issues. Educate relevant teams on CRA compliance, adopt industry-recognized security frameworks, and document all security measures thoroughly. If you operate from outside the EU, appointing a reliable Authorised Representative is a critical step to ensure lawful market access and to manage communications with regulators.

Deadlines and Penalties for Non-Compliance

The CRA will be implemented gradually:

  • By June 2026, the EU will establish organizations responsible for ensuring compliance.
  • By September 2026, manufacturers must begin reporting cybersecurity vulnerabilities and incidents.
  • By December 2027, all relevant digital products must meet the new standards.

Failure to comply could result in steep penalties, with fines of up to €15 million or 2.5% of a company’s global revenue.

With enforcement approaching, companies producing digital products must act now to ensure compliance, strengthen security measures, and protect users from cyber threats.