Skip to content
Call, 0511 – 47 55 58 11

Cyber Resilience Act

The CRA turns cybersecurity into a property of the product. Anyone placing software or connected devices on the market no longer answers only for defects but owes security across the whole support period.

Product law has so far said little about cybersecurity. The Cyber Resilience Act changes that. Security becomes a property a product must have before it may reach the market, and must keep across its support period.

The timeline

  1. 12/2024

    Entry into force

    The regulation enters into force, with duties applying in stages.

  2. 09/2026

    Reporting duties

    Early warning within 24 hours, further detail within 72 hours.

  3. 12/2027

    Full application

    Essential security requirements, conformity assessment, CE marking, vulnerability handling across the lifecycle.

Duties by role

Security by design, conformity assessment before placing on the market, technical documentation, security updates across the declared support period, and reporting of exploited vulnerabilities.

Only place compliant products on the market. Check that conformity assessment, marking and documents exist, and do not ship where there is doubt.

Act with due care, check marking and documents, and take action as soon as there are indications of non-conformity.

Anyone distributing a product under their own name or brand, or substantially modifying it, takes on the manufacturer duties in full. Integrators and resellers are caught by this more often than they realise.

What to prepare now

How we help

We classify products and roles, put the reporting paths into a form that works under time pressure, and adjust contracts with suppliers and customers. Where CRA and NIS2 duties overlap, we settle the order beforehand.

Connected products in your range?

We work out which duties apply to you and what has to be in place by when.

Ask for a classification

Frequently asked questions

Does the CRA concern us at all?

It covers products with digital elements made available on the EU market. That runs from consumer devices through business software to industrial systems. It binds not only manufacturers but importers and distributors, each with their own duties. Anyone distributing someone else's software under their own name, or substantially modifying it, becomes a manufacturer themselves.

Which deadlines apply?

The regulation entered into force in December 2024. Since 11 September 2026 the reporting duties for actively exploited vulnerabilities and severe security incidents have applied. The remaining requirements bite from 11 December 2027. The reporting duty therefore arrives long before the rest of the regime.

What about open source software?

Open software not supplied in the course of a commercial activity is in principle excluded. The line runs along commercial activity, not along the licence type. Anyone building open components into their own product and distributing it cannot rely on the exception and answers for everything they ship.

Related