What is the Cyber Resilience Act: the EU cybersecurity regulation for digital products
By the QuantumSec team
The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847, adopted by the European Parliament and the Council of the EU in October 2024. It is the first legal framework in the European Union to impose mandatory cybersecurity requirements on products with digital elements —hardware and software— before they can be placed on the European market. If your company manufactures, imports or distributes any kind of technology product in the EU, the CRA affects you directly.
Why the Cyber Resilience Act exists
For years, the cybersecurity of digital products was left to the voluntary discretion of manufacturers. The result: IoT devices with identical default passwords across millions of units, enterprise software with no security update process, home routers with known vulnerabilities left unpatched. Cyberattacks that exploit these weaknesses cost the European economy more than 5.5 billion euros a year, according to the European Commission. The CRA responds to this by establishing a mandatory minimum cybersecurity threshold that all products with digital elements must meet before accessing the EU single market. The core idea is simple: security must be designed into the product from the start —security by design— and not bolted on later as a patch.
Which products the CRA applies to
The CRA applies to any product with digital elements that has direct or indirect network connectivity and is placed on the EU market. This includes connected hardware (routers, IP cameras, industrial and consumer IoT devices, wearables, connected medical devices not covered by the MDR), software with components installable on the client (desktop applications, firmware, operating systems, enterprise software, plugins) and software components embedded in other products (libraries, SDKs, modules). The exclusions are: open source software with no commercial purpose, pure SaaS services with no client-installable components, medical devices regulated by the MDR, civil aviation products and defence equipment. A key point: if your SaaS service includes a desktop agent, an installable connector or a plugin that communicates with your cloud infrastructure, that component falls within the scope of the CRA even if the rest of your service is pure cloud.
The CRA's four product categories
The CRA classifies products into four categories according to their potential risk level, which determines the type of conformity assessment required.
Default products: the category covering the vast majority of products with digital elements. Manufacturers can carry out a conformity self-assessment following the requirements of Annex I.
Class I (higher risk): includes identity and access management software, password managers, web browsers, antivirus software, network device managers, general-purpose operating systems, home routers and consumer firewalls. For these products the manufacturer can self-assess only if it applies a European harmonised standard in full; otherwise, third-party assessment is required.
Class II (critical): hypervisors, server operating systems, industrial firewalls, intrusion detection and prevention systems, security microcontrollers, smart cards, public key infrastructures (PKI) and trusted platform modules (TPM). These mandatorily require an audit by a notified body.
IACS products: industrial control systems with a critical function in infrastructure, subject to specific requirements for OT/ICS environments.
The essential requirements of Annex I
Annex I of the CRA defines two groups of essential cybersecurity requirements.
Product requirements (Part I): the product must have no known exploitable vulnerabilities at the time it is placed on the market; it must ship with a secure-by-default configuration; it must protect stored and transmitted data through encryption; it must minimise its attack surface; it must resist unauthorised access attempts; it must ensure software integrity through secure update mechanisms; it must offer security event logging functions; and it must contain no hidden functionality or backdoors.
Vulnerability management requirements (Part II): the manufacturer must identify and document vulnerabilities throughout the entire product lifecycle; it must make security updates available free of charge for at least five years; it must have a coordinated vulnerability disclosure (CVD) policy; it must notify ENISA of actively exploited vulnerabilities within 24 hours (early warning) and 72 hours (formal notification); and it must give users clear information about the product's security support period.
The deadlines you need to keep in mind
The CRA has three important milestones.
23 October 2024: the regulation entered into force. Manufacturers must already start preparing.
11 August 2026: the requirements for reporting incidents and actively exploited vulnerabilities to ENISA become applicable. Companies must have their reporting process operational before this date.
11 September 2026: the notified bodies (which will carry out third-party conformity assessments for Class I and II products) must be designated and operational.
11 December 2027: the date the CRA fully applies. All products with digital elements placed on the European market from this date must fully comply with the regulation's requirements and bear the CE cybersecurity marking.
The CE cybersecurity marking
Like other European product regulations, the CRA introduces the CE marking as a sign of conformity with the cybersecurity requirements. A product without the CE cybersecurity marking cannot be placed on the European market from 11 December 2027. The process varies by product category: manufacturers of Default products carry out a self-assessment and issue the EU declaration of conformity; those of Class I and II products must go through a notified body.
FAQ
Does the CRA apply only to European companies or also to those selling into the EU from abroad?
The CRA applies to any product placed on the European market, regardless of where the manufacturer is based. A manufacturer based in the US, India or South Korea selling its products in the EU must comply with the CRA. If it has no presence in the EU, the importer that places the product on the European market assumes the manufacturer's obligations.
Does the CRA apply to software updates of products already on the market?
Yes. The CRA applies to significant software updates that substantially modify the product's security characteristics. Minor security updates or vulnerability patches are not considered a 'placing on the market' of a new product, but the manufacturer remains obliged to provide them free of charge for at least five years.
What is the EU declaration of conformity under the CRA?
It is the document the manufacturer issues under its own responsibility declaring that the product meets all the essential cybersecurity requirements of the CRA. It must include the identification of the product and the manufacturer, the requirements deemed met, the harmonised standards applied, and a statement of responsibility. It must be kept for 10 years and be available to the market surveillance authorities.