OUT-LAW ANALYSIS

Cyber Resilience Act marks major shift in EU cybersecurity compliance

European Commission

The first significant implementation deadline falls on 11 September. bloodua/iStock


With the first major compliance deadline shortly arriving, businesses should turn their attention to the practical implications of the EU’s Cyber Resilience Act (CRA), one of the most ambitious cybersecurity regimes introduced to date.

The CRA, which entered into force on 10 December 2024, establishes for the first time a horizontal, EU-wide legal framework for the cybersecurity of products with digital elements. Its objective is to improve cybersecurity across the EU by imposing requirements relating to the design, development and production of products, as well as manufacturers’ vulnerability handling processes throughout the product’s expected lifetime.

The first significant implementation deadline falls on 11 September, when the reporting obligations under Article 14 of the CRA take effect. From that date, manufacturers will be required to report actively exploited vulnerabilities and severe incidents. From 11 December 2027, all CRA requirements must be fully complied with for products with digital elements made available on the EU market.

Broad scope

In principle, every product sold in the EU that contains digital elements must comply with the CRA.

The legislation defines a product with digital elements as software or hardware and associated remote data processing solutions. This includes standalone software, such as apps and programmes; hardware with embedded software, such as internet of things (IoT) devices and laptops; standalone hardware, including integrated circuits and motherboards; and combinations of hardware and software intended to work together.

The defining feature is that the product has a direct or indirect data connection to a device or network.

Not every digital product or service is covered, however. Websites that do not support the functionality of a product with digital elements fall outside the scope of the CRA. Standalone software-as-a-service (SaaS) and other cloud solutions developed independently of a manufacturer will also generally fall outside the regime unless they qualify as a remote data processing solution that is necessary for a product to perform its functions.

In addition, certain products already covered by sector-specific legislation, including medical devices, motor vehicles and aviation products, are excluded.

The CRA applies to products with digital elements made available on the EU market, meaning products supplied for distribution or use in the course of a commercial activity.

The legislation also recognises the specific nature of free and open-source software (FOSS). Where FOSS is not monetised by its manufacturer and is not made available in the course of a commercial activity, it will generally fall outside the scope of the CRA.

Manufacturers at the centre of the regime

The CRA affects a wide range of economic operators throughout the supply chain. However, manufacturers sit at the centre of the framework.

Importantly, the term “manufacturer” extends beyond traditional hardware producers. It also includes software providers and businesses that place products on the market under their own brand.

Manufacturers must meet four core sets of obligations:

  • conduct cybersecurity risk assessments and implement the resulting technical requirements
  • manage vulnerabilities throughout the product lifecycle
  • comply with reporting and transparency obligations towards authorities and users
  • prepare and maintain technical documentation and evidence of conformity

The implementation obligations under the CRA build on the well-established European Conformity (CE) marking framework. Manufacturers that already maintain these processes should be able to incorporate CRA compliance into these.

Cybersecurity by design

A central feature of the CRA is the requirement for manufacturers to ensure that products are designed, developed and produced in accordance with the legislation’s essential cybersecurity requirements.

Manufacturers must assess the cybersecurity risks associated with their products and take those risks into account throughout the planning, design, development, production, delivery and maintenance phases.

The CRA therefore places cybersecurity at the heart of the product lifecycle rather than treating it as an issue to be assessed after products are placed on the market.

Ongoing vulnerability management

The legislation also places significant emphasis on vulnerability handling throughout the entire product lifecycle.

Manufacturers must identify and document vulnerabilities and product components, including generating a software bill of materials (SBOM) in a machine-readable format. Vulnerabilities must be addressed without delay, including through the provision of security updates. Regular security testing and reviews must also be carried out.

Once a security update is available, information on remedied vulnerabilities must be made publicly available. Manufacturers must also establish and enforce a coordinated vulnerability disclosure policy.

These obligations continue after products are placed on the market. The support period determined by the manufacturer must correspond to the expected product lifetime and, as a general rule, last at least five years. Article 26 guidance published by the European Commission, however, clarifies that "five years is a floor, not a default" and that "products reasonably expected to be in use longer should have longer support periods”.

Security updates and technical documentation must remain available for at least ten years after a product is placed on the market, or for the entire duration of the support period if that period is longer.

Reporting obligations

For many organisations, the most immediate challenge will be the CRA’s reporting obligations, which take effect on 11 September.

From that date, manufacturers must report actively exploited vulnerabilities and severe incidents without undue delay after becoming aware of them. Reports must be submitted simultaneously to the designated Computer Security Incident Response Team (CSIRT) and the EU Agency for Cybersecurity (ENISA) through a single reporting platform.

Manufacturers must also provide users with clear information about identified vulnerabilities, available security updates and the applicable support period.

For an actively exploited vulnerability, organisations must submit an early warning within 24 hours, a detailed notification within 72 hours, and a final report within 14 days of a corrective measure becoming available. For a severe incident, organisations must submit an early warning within 24 hours, a detailed notification within 72 hours, and a final report within one month of the 72-hour notification.

Documentation and conformity requirements

The CRA also imposes extensive documentation obligations.

Manufacturers must prepare technical documentation before placing a product on the market and keep it up to date throughout the support period, for at least ten years. The documentation must contain all information necessary to demonstrate compliance with the CRA’s cybersecurity requirements.

In addition, manufacturers must prepare an EU declaration of conformity and affix CE marking before placing a product on the market.

Significant consequences for non-compliance

Although harmonised European standards are still being developed, businesses already have access to guidance. The European Commission’s FAQ provides interpretative guidance on the scope of the legislation and manufacturers’ obligations, while the BSI Technical Guideline series TR-03183 provides practical guidance on areas including SBOMs, vulnerability disclosure and conformity assessment. The Commission also published practical guidance on 27 July to help manufacturers, developers, and businesses of all sizes meet their obligations under the Cyber Resilience Act.

The consequences of non-compliance can be significant. The CRA provides for administrative fines of up to €15 million or 2.5% of total worldwide annual turnover. Businesses may also face market access restrictions, product recalls and increased scrutiny from market surveillance authorities.

Planning ahead

The CRA is not an abstract future project but applicable law with concrete deadlines. With reporting obligations commencing in September and full compliance required by December 2027, manufacturers should be taking steps now to establish vulnerability management processes, incident reporting procedures and compliance frameworks.

Businesses that act now to establish processes for vulnerability handling and reporting obligations, and that align product development with the new requirements, will be better placed not only to demonstrate legal compliance but also to compete in the European single market.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.