Quick answer: The EU Cyber Resilience Act (CRA) makes cybersecurity a requirement for selling products with digital elements in the EU. Reporting obligations took effect on September 11, 2026, and full product compliance requirements apply on December 11, 2027. Non-compliant products may be restricted from the EU market.
For manufacturers, the CRA changes cybersecurity from a best practice to a business requirement. If you cannot demonstrate that a product meets the regulation's requirements, you may not be able to place it on the EU market.
For companies that rely on Europe for revenue and growth, the question is straightforward: will your products be ready when the CRA takes full effect?
In Part One of this series, we'll cover what the CRA requires, which products are in scope, key compliance deadlines, and what manufacturers need to do now. Part Two will explore how connected product data and a digital thread can help support compliance.
Cybersecurity Is Now a Market-Access Requirement
The Cyber Resilience Act, officially known as Regulation (EU) 2024/2847, establishes cybersecurity requirements for products with digital elements sold in the European Union. The regulation applies regardless of where a manufacturer is headquartered and covers the entire product lifecycle, from design and development through maintenance and vulnerability management.
Manufacturers must not only release secure products but also maintain security throughout the product's support period. That includes managing vulnerabilities, providing security updates, and demonstrating ongoing compliance.
For business leaders, the key point is simple: the CRA is not just a cybersecurity regulation. It is a product compliance requirement tied directly to market access. Compliance will require coordination across engineering, software development, product management, quality, regulatory, service, and supply chain teams.
What does the CRA cover?
The CRA covers products with digital elements. This means hardware or software whose intended or reasonably foreseeable use includes a direct or indirect connection to a device or network.
Examples of Products Covered by the CRA
- Smart home devices and building controls
- Industrial IoT products, PLCs, sensors, gateways
- Connected equipment with telematics
- Software applications and components
If a product connects to something and is made available in the EU, the safe assumption is that the CRA is in play until a product-level assessment proves otherwise.
Why the four product categories matter
The CRA divides products into four categories: Default, Important Class I, Important Class II, and Critical. The classification determines the level of scrutiny and whether a manufacturer can self-assess or must undergo third-party conformity assessment. Higher-risk products face greater documentation, testing, and certification requirements.
Classifying each product early is a leadership priority, because the category drives cost, timeline, documentation depth, and whether an external assessment body must be engaged before launch.
What countries does the CRA apply to?
The CRA applies across all 27 EU Member States. Its scope is based on where a product is sold, not where it is designed or manufactured, meaning companies outside Europe may still be subject to the regulation if they place products on the EU market.
This has significant implications for any product built through a complex, global supply network. A product designed in one country, developed by distributed teams, assembled using software and components from multiple suppliers, and delivered through European channels may require coordinated evidence from across the entire product and software supply chain.
Which products are exempt from the CRA?
Certain products covered by sector-specific regulations, including some medical devices, vehicles, aviation products, and marine equipment, are exempt. However, manufacturers should assess products individually, as some components and software may still fall within the CRA's scope. Exemptions are narrower than they may appear, so it is best to perform a product-level assessment rather than assume that everything supplied into the program is automatically excluded.
Where does the CRA stand today, and how much time is left?
Three dates define the CRA timeline, and the middle one has now arrived:
- December 10, 2024: The CRA Entered into Force
- September 11, 2026: Vulnerability and Incident Reporting Obligations Began
- December 11, 2027: Full Compliance Requirements Take Effect
While reporting obligations are already in force, manufacturers have until December 2027 to complete broader compliance activities.
What must companies do to comply with the CRA?
At an executive level, the obligations can be organized into five connected capabilities.
Identify products in scope
Manufacturers need a clear inventory of products sold in the EU, the software and components they contain, and the CRA classification and conformity-assessment route that applies to each.
Build security into products
The CRA requires manufacturers to apply security-by-design principles throughout the product lifecycle, including risk assessment, development, testing, and release.
Manage vulnerabilities
Organizations must be able to identify, assess, remediate, and disclose vulnerabilities throughout a product's support period. They must also maintain a software bill of materials (SBOM) to quickly determine which products are affected when vulnerabilities emerge in third-party components.
Demonstrate compliance
Manufacturers must maintain technical documentation, complete the required conformity assessment, issue an EU declaration of conformity, and apply CE marking before placing a compliant product on the EU market.
Prepare for reporting and corrective action
The CRA imposes strict reporting requirements for actively exploited vulnerabilities and severe incidents. Manufacturers must be able to rapidly assess affected products, notify authorities, communicate with customers, and deploy corrective actions when necessary.
How must companies respond when a product is non-compliant?
When non-compliance is discovered, manufacturers must quickly determine impact, implement corrective actions, update documentation, notify relevant parties, and, where necessary, restrict distribution or conduct a withdrawal or recall.
The challenge is speed and precision. Organizations must quickly identify affected products, trace the source of a vulnerability, determine impacted customers, validate a fix, and coordinate a response. The more precisely they can identify impacted products, the faster and less costly the remediation. Broad, over-scoped recalls drive unnecessary costs, disrupt unaffected customers, and delay action for those truly at risk.
That level of precision is difficult to achieve when product, software, test, supplier, and installed-base data is scattered across spreadsheets, emails, and disconnected systems.
Who enforces the CRA, and what are the penalties?
National market-surveillance authorities in each EU Member State are responsible for enforcing the CRA. They can investigate products, require corrective actions, restrict sales, or order product withdrawals and recalls. ENISA supports reporting infrastructure and cross-border coordination.
Violations can result in fines of up to €15 million or 2.5% of global annual turnover, whichever is higher. However, the business impact often extends beyond financial penalties. Non-compliance can lead to delayed product launches, costly recalls, increased remediation expenses, reputational damage, and restrictions on placing products on the EU market.
For many manufacturers, the greatest risk is not the fine itself, but the potential loss of access to the EU market.
CRA readiness is an enterprise product-lifecycle issue
CRA compliance is not solely a cybersecurity challenge. It requires coordination across engineering, software, quality, service, and regulatory teams throughout the product lifecycle.
Companies with a connected digital thread can more easily trace requirements, software components, product configurations, vulnerabilities, and corrective actions, making compliance faster and less costly.
In Part Two, we'll explore how manufacturers can build that foundation. Cybersecurity is becoming essential for market access across all industries. Learn more below with a look into MedTech's journey with the Cyber Resilience Act.
Why MedTech Manufacturers Should Pay Attention to the CRA
Cybersecurity is becoming essential to market access. Learn how it will affect MedTech manufacturers.
Read Now
Topics
Requirements Management
Up Next
Subscribe to the industrial newsletter
Stay informed on the latest trends, insights, and innovations in industrial digital transformation. Get expert perspectives delivered straight to your inbox.
Subscribe Now