The European Union’s Cyber Resilience Act (CRA) is introducing new cybersecurity standards to ensure digital products are safer for users. While the legislation officially took effect on December 10, 2024, companies will have until December 11, 2027, to fully comply with its requirements.
The CRA applies to digital products that connect to networks, including both software and hardware. This means everything from smart home devices and wearables to industrial equipment will need to meet stricter cybersecurity standards. However, products already regulated under specific EU laws, such as medical and automotive devices, are excluded.
The law is designed to address growing concerns about cybersecurity vulnerabilities by requiring stronger protections from the outset. Companies will need to ensure products are developed with security in mind and continue to provide necessary updates after release.
The new regulations impact several key players in the supply chain:
While physical products typically include the Authorised Representative’s details on the product label, packaging, or printed materials, digital-only products like applications and downloadable software require a different approach. For these, the representative’s name and address must be made easily accessible in digital format. This can be done through in-app menus, digital help sections, user agreements, or wherever product information is displayed online. The essential requirement is that the contact information is clearly linked to the product and readily available to users and authorities, in line with the transparency demands of the Cyber Resilience Act.
Businesses involved in developing or distributing digital products in the EU should act now to meet the CRA’s cybersecurity standards. Start by reviewing existing products for potential vulnerabilities and ensure they are designed with security features active by default. Establish a clear process for issuing updates and reporting security issues. Educate relevant teams on CRA compliance, adopt industry-recognized security frameworks, and document all security measures thoroughly. If you operate from outside the EU, appointing a reliable Authorised Representative is a critical step to ensure lawful market access and to manage communications with regulators.
The CRA will be implemented gradually:
Failure to comply could result in steep penalties, with fines of up to €15 million or 2.5% of a company’s global revenue.
With enforcement approaching, companies producing digital products must act now to ensure compliance, strengthen security measures, and protect users from cyber threats.