
Cyber Resilience Act
CRA Regulation
The Cyber Resilience Act (CRA) is a new European Union regulation that introduces uniform requirements in terms of cybersecurity for all “products with digital elements” - both devices and software. The regulation was published on 24 October 2024 and came into effect on 10 December 2024.
It is one of the most important regulatory changes in the recent years because it is the first time the EU has imposed such extensive and obligatory requirements in terms of security on companies that place digital products on the market.
To put it simply, CRA constitutes “CE marking” in terms of cybersecurity. Previously, many devices (from smart refrigerators to industrial control systems) were placed on the market with gross gaps in terms of security, including “admin123” being the default password or having no option to update software.
CRA - comprehensive support from Cybernite
Why was CRA adopted?
The purpose of CRA is to:
- Increase the security of digital products, as these more and more often become the objects of attacks such as ransomware and data theft.
- Eliminate the regulatory gap- previously, a number of devices and applications were placed on the market without minimum security standards
- Facilitate clients and companies in evaluating product security thanks to clear requirements and CE marking as confirmation of compliance
- Improve the resilience of the entire EU market to cyberthreats through vulnerability management and the obligation to update software for the entire life cycle of a product
In practice, CRA is supposed to make sure that every digital product, from a smartphone to an industrial robot, is more secure for users and companies.
Who does CRA apply to?
The regulation covers all “products with digital elements”, meaning those that can connect to a network or to other devices. The resulting scope of application is very wide, including e.g.:
- IoT devices (smart home appliances, smartwatches, electronic nannies),
- Consumer devices (smartphones, TVs, laptops),
- Industrial devices connected to a network (sensors, robots, controllers),
- Mobile and computer applications, operating systems,
- Business software,
- Elements of cloud services that are a part of a digital product.
CRA applies to manufacturers, importers, and distributors. Every entity in the supply chain has clear obligations.
CRA: key dates
- 10 December 2024: CRA came into effect.
- 11 September 2026: requirements in terms of reporting vulnerabilities and incidents will start to apply. Manufacturers will have to:
- Report a major incident to CSIRT and ENISA within 24 hours,
- Send a supplementary report within 72 hours,
- Draft a full report within 14 days.
- 11 December 2027: all digital products placed on the EU market will have to be fully compliant with CRA.
This means that business has less than two years (until the end of 2027) to fully adapt products and processes.
What obligations does CRA introduce?
A. Security by design and security by default
Products have to be designed in such a way that they have built-in security mechanisms - not as an addition, but as an integral element. This means no more weak default passwords, protection against unauthorized access, and minimization of collected data.
B. Cybersecurity risk assessment
The manufacturer has to:
- Carry out detailed risk analysis,
- Include the results of that analysis in technical documentation,
- Update the documentation during the product development process.
C. Vulnerability management
For the entire expected life cycle of the product:
- Vulnerabilities have to be monitored,
- Security updates have to be supplied,
- Incident management procedures have to be in place.
D. Reporting of incidents and vulnerabilities
From September 2026, quick reporting (described above) will be obligatory.
E. CE marking
Placing a product on the market will be possible only after going through compliance assessment.
F. SBOM (Software Bill of Materials)
More and more sources point to the fact that documentation will need an SBOM, so as to facilitate the tracking of vulnerabilities.
G. Obligations of importers and distributors
They have to make sure that the manufacturer has complied with the requirements and the product has:
- Full documentation,
- CE marking,
- Vulnerability management procedures.
What does that mean for business?
Companies need to get prepared for:
- Review and updating of product development processes,
- Implementation of systemic vulnerability management,
- Implementation of security be design,
- Drafting or supplementing technical documentation,
- Regular security tests,
- Ensuring updates to products for their entire life cycle.
This is a major challenge, but also an opportunity to organize security and increase competitiveness through compliance with EU requirements.
What penalties does CRA provide for?
The penalties for violations can be very high:
- Up to EUR 15 million or
- 2.5% of global annual turnover, whichever is higher
Additionally, administrative sanctions are possible, including:
- Prohibition of placing products on the market,
- Obligation to remove products from the market.
|
Type of violation |
Maximum financial penalty |
| Non-compliance with essential cybersecurity requirements |
Up to EUR 15,000,000 of 2.5% of global annual turnover |
|
Non-compliance with administrative obligations (documentation etc.) |
Up to EUR 10,000,000 of 2% of global annual turnover |
| Provision of incorrect or misleading information | Up to EUR 5,000,000 of 1% of global annual turnover |
What should companies do at the current stage?
Priorities for the next months:
- Product audit in order to determine if they fall under CRA.
- Analysis of risk and compliance gaps: current status versus the requirements.
- Implementation of security processes, including vulnerability management and incident response.
- Drafting of SBOM and technical documentation.
- Training of teams, especially in the areas of security and compliance.
- Verification of suppliers since their errors could affect the compliance of your product.
The sooner companies take actions, the smaller the risk of non-compliance in 2027.
Summary
The Cyber Resilience Act is a crucial piece of legislation regulating the security of digital products in the EU. Its primary goal is to increase the resilience of the market to cyberthreats by forcing manufacturers, importers, and distributors to comply with security standards. The key deadlines (September 2026 for obligations in terms of reporting and December 2027 for full compliance) leave limited time for preparation. The implementation of CRA is a challenge, but also a way to improve the quality and security of products, which, in the long term, may be a competitive edge.
Text by professor Grzegorz Strupczewski
Within the framework of Cybernite Status we help assess the organization’s current level of security and regulatory preparedness.
Through Cybernite Safe, we provide regular support in terms of cybersecurity management, performance of regulatory obligations, and compliance with industry standards, using the Cybersecurity as a Service (CSaaS) model.

Do you need support with respect to NIS2/KSC, CRA, DORA, or the AI Act, from confirming that you are subject to them, through gap analysis, to verification and supplementation of existing actions?
Cybernite helps organize documentation, implement the missing elements, and maintain compliance in practice.