ECP — European Compliance Platform European Compliance Platform
Cybersecurity Compliance Guide

Cyber Resilience Act Guide: Compliance for Connected Products

The Cyber Resilience Act is the EU's first horizontal cybersecurity law for products — and it applies far beyond traditional IT. If your product connects to a network in any way, it likely falls in scope. Here's what manufacturers need to know.

What Is the Cyber Resilience Act?

The Cyber Resilience Act (Regulation (EU) 2024/2847), or CRA, is the EU's first cross-sector law setting mandatory cybersecurity requirements for products with digital elements (PDE) — a category defined broadly as any hardware or software product whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network.

In practice this covers connected consumer electronics, IoT devices, networking equipment, industrial control components, standalone software applications, firmware, and operating systems — essentially any product that connects, is remotely configurable, or exchanges data.

Key Dates

DateMilestone
10 December 2024CRA entered into force
11 September 2026Vulnerability and incident reporting obligations apply
11 December 2027Full application — essential requirements, conformity assessment, CE marking obligations

What's Excluded?

  • Products already covered by sector-specific rules with equivalent cybersecurity requirements — e.g. medical devices under MDR/IVDR, motor vehicles, civil aviation equipment, in-vehicle and marine equipment
  • Software-as-a-Service (SaaS) unless it meets the definition of a remote data processing solution that is essential for a hardware/software product to function
  • Free and open-source software developed or supplied outside the course of a commercial activity
  • Products developed exclusively for national security or military purposes
💡 Overlap with the Machinery Regulation and RED Connected machinery may need to satisfy both the CRA and the cybersecurity essential requirement in the new Machinery Regulation (EU) 2023/1230. Radio equipment previously covered by the RED Delegated Regulation 2022/30 cybersecurity requirements will generally be governed by the CRA instead once it applies, to avoid double regulation — but manufacturers should confirm which regime applies to their specific product during the transition.

Product Classification

CategoryExamplesConformity assessment
Default (≈90% of products)Most connected consumer and business productsManufacturer self-assessment
Important — Class IPassword managers, VPN clients, network management software, browsers, endpoint security softwareSelf-assessment against harmonised standards, or third-party assessment if standards not applied
Important — Class IIFirewalls, intrusion detection/prevention systems, tamper-resistant microprocessors, smart card readersThird-party (notified body) assessment generally required
CriticalHardware security modules, smart meter gateways, other products designated by the CommissionEU cybersecurity certification scheme or third-party assessment

Core Essential Requirements

  • Secure by design and by default — products must ship with a secure default configuration and minimise the attack surface
  • No known exploitable vulnerabilities at the time of placing on the market
  • Software Bill of Materials (SBOM) — manufacturers must document the components used in the product, at least at the top-level dependency
  • Vulnerability handling process covering the entire support period, including a coordinated vulnerability disclosure policy
  • Free security updates for the duration of the defined support period, delivered automatically where feasible
  • CE marking — the CRA becomes a CE-marking regulation; digital-element products must carry the CE mark and an EU Declaration of Conformity covering CRA compliance, alongside any other applicable directives (RED, Machinery, LVD, etc.)

Vulnerability and Incident Reporting

From 11 September 2026, manufacturers must notify ENISA and the relevant national CSIRT of:

  • Actively exploited vulnerabilities — early warning within 24 hours of becoming aware, full notification within 72 hours, and a final report within 14 days of a corrective measure becoming available
  • Severe incidents impacting the security of the product, on a comparable timeline

This mirrors the reporting cadence used under NIS2 and is designed to give EU authorities early visibility into supply-chain-scale vulnerabilities.

The Support Period Obligation

Manufacturers must define an expected product lifetime and provide free security updates for a support period — generally a minimum of 5 years, unless the product's realistic expected lifetime is shorter. This must be communicated to users at the point of sale and factored into engineering and supply-chain planning, since firmware/software update capability must exist for the full support period, not just the initial warranty term.

Penalties

Breach typeMaximum fine
Essential cybersecurity requirements€15,000,000 or 2.5% of worldwide annual turnover, whichever is higher
Other CRA obligations (reporting, documentation)€10,000,000 or 2% of worldwide annual turnover, whichever is higher
Incorrect, incomplete, or misleading information to authorities€5,000,000 or 1% of worldwide annual turnover, whichever is higher

Preparing Now

  1. Inventory connected products and screen each against the default/important/critical classification
  2. Build or source an SBOM process for your software supply chain
  3. Stand up a vulnerability disclosure and reporting process ahead of the September 2026 deadline
  4. Define support periods per product line and confirm your update infrastructure can deliver for that duration
  5. Engage a notified body early if you have Class II "important" or "critical" products, given expected demand ahead of the 2027 deadline

Building a Connected Product?

Submit a request on ECP describing your product's connectivity and data-processing functions. We route it to notified bodies, cybersecurity testing labs, and CRA compliance consultants who can confirm your classification and scope the work.

See How ECP Can Help

Frequently Asked Questions

What products does the Cyber Resilience Act cover?
Any hardware or software product whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network — a broad category spanning IoT, networking equipment, standalone software, and firmware. Products already covered by equivalent sector-specific cybersecurity rules (e.g. MDR/IVDR medical devices, vehicles, aviation) are excluded.
When do Cyber Resilience Act obligations take effect?
Entered into force 10 December 2024. Reporting obligations apply from 11 September 2026. Full essential requirements and conformity assessment apply from 11 December 2027.
How are products classified under the CRA?
Default products (~90%) use self-assessment. "Important" Class I products (e.g. password managers, VPNs) can often self-assess against harmonised standards; Class II (e.g. firewalls, IDS) generally need third-party assessment. "Critical" products need certification under an EU scheme or third-party assessment.
What is the vulnerability reporting timeline under the CRA?
24-hour early warning for actively exploited vulnerabilities, 72-hour full notification, and a final report within 14 days of a fix becoming available. Severe incidents follow a similar timeline.
What are the penalties for CRA non-compliance?
Up to €15 million or 2.5% of global turnover for essential requirement breaches, €10 million/2% for other obligations, and €5 million/1% for misleading information to authorities.

Find the right provider

Notified Body

Required for Class II "important" and "critical" products with digital elements.

Find a Notified Body →

Testing Laboratory

Cybersecurity, EMC, and RED testing for connected products.

Find a Testing Lab →

EU Authorized Representative

Mandatory for non-EU manufacturers placing digital-element products on the EU market.

Find an EU Representative →

Not sure which you need? See How ECP Can Help and we will match you with the right expert.