Foundations

What is the EU Cyber Resilience Act?

A plain-English guide to the CRA — what it is, who it applies to, and why it matters.

The Cyber Resilience Act (CRA) — formally Regulation (EU) 2024/2847 — is the European Union's first law that sets mandatory cybersecurity requirements for products rather than for organisations or networks. In simple terms: if you sell a product that contains software or connects to a network, the CRA says that product must be secure by design, stay secure through updates, and that you must handle vulnerabilities responsibly.

It fills a long-standing gap. For years, connected devices and software could be placed on the EU market with little or no security assurance, and buyers had no easy way to tell a well-secured product from a poorly secured one. The CRA changes that by making cybersecurity a condition of putting a product on the market — enforced through the same CE marking system used for product safety.

What does "products with digital elements" mean?

The CRA applies to products with digital elements — a deliberately broad term. It covers any software or hardware product, and its remote data-processing solutions, whose intended purpose includes a direct or indirect connection to a device or network. That includes:

A handful of categories are carved out because they are already regulated elsewhere (for example certain medical devices, aviation, and cars) or are pure cloud services governed by other rules. But for the vast majority of connected products, the starting assumption is: you are in scope.

Not sure whether your product qualifies? Our companion article, "Is my product in scope of the CRA?", walks through the exclusions and gives you a decision path.

Who has obligations?

The CRA places duties on economic operators along the supply chain, with the heaviest responsibilities on the manufacturer — the party that develops or has a product developed and markets it under their own name or brand. Manufacturers must:

Importers and distributors have lighter, mostly verification-focused duties — checking that the manufacturer has done its job before a product moves down the chain.

The three ideas at the heart of the CRA

1. Security by design and by default

Products should be built to reduce risk from the start, and ship in a secure configuration out of the box — not rely on the customer to harden them later. That means things like minimising the attack surface, protecting data, and not shipping with well-known default passwords.

2. Security across the whole lifetime

Compliance is not a one-time gate at launch. Manufacturers must keep the product secure for a support period appropriate to the product (with a general expectation of at least five years unless the product is used for less), by identifying and fixing vulnerabilities and delivering updates.

3. Transparency and accountability

Users should get clear information about how to use the product securely and how long it will be supported. And when something goes seriously wrong — an exploited flaw or a severe incident — manufacturers must tell the authorities quickly rather than quietly.

How is it enforced?

The CRA rides on the EU's established product-conformity framework. Depending on how the product is classified by risk, the manufacturer either self-assesses conformity or must involve an independent notified body. Once satisfied, the manufacturer draws up the Declaration of Conformity and applies the CE marking — the same mark you already see on electronics and toys, now also standing for cybersecurity. National market-surveillance authorities can investigate, demand corrective action, order products off the market, and impose significant fines for non-compliance.

Why it matters — even before the deadline

The CRA's main obligations apply from December 2027, with certain reporting duties starting earlier in 2026. That sounds far off, but security-by-design decisions are made early in a product's life. Retrofitting an update mechanism, an SBOM process, or a vulnerability-handling workflow into a shipped product is far more expensive than building it in now. Manufacturers who start early turn the CRA from a compliance scramble into a competitive advantage — demonstrably secure products that buyers, especially in regulated sectors, will increasingly demand.

Where ComplyPS fits: ComplyCRA takes you through exactly these steps — classify your product's risk, self-assess against Annex I, generate an SBOM and scan it for known vulnerabilities, and track your readiness — with all of your data processed privately. Open ComplyCRA →

This article is general information, not legal advice. Refer to the official text of Regulation (EU) 2024/2847 for authoritative wording.

← All CRA Insights Next: Is my product in scope? →