Cyber Resilience Act
The CRA turns cybersecurity into a property of the product. Anyone placing software or connected devices on the market no longer answers only for defects but owes security across the whole support period.
Product law has so far said little about cybersecurity. The Cyber Resilience Act changes that. Security becomes a property a product must have before it may reach the market, and must keep across its support period.
The timeline
12/2024
Entry into force
The regulation enters into force, with duties applying in stages.
09/2026
Reporting duties
Early warning within 24 hours, further detail within 72 hours.
12/2027
Full application
Essential security requirements, conformity assessment, CE marking, vulnerability handling across the lifecycle.
Duties by role
Security by design, conformity assessment before placing on the market, technical documentation, security updates across the declared support period, and reporting of exploited vulnerabilities.
Only place compliant products on the market. Check that conformity assessment, marking and documents exist, and do not ship where there is doubt.
Act with due care, check marking and documents, and take action as soon as there are indications of non-conformity.
Anyone distributing a product under their own name or brand, or substantially modifying it, takes on the manufacturer duties in full. Integrators and resellers are caught by this more often than they realise.
What to prepare now
- Product inventory: which of the things we ship fall under the regulation?
- Role assessment per product, including where we become the manufacturer
- Set the support period and state it to customers
- A record of the components in use, so vulnerabilities stay attributable
- A reporting process for 24 and 72 hours, with named owners and deputies
- Supplier contracts: who tells us about a vulnerability, and when?
- Alignment with the NIS2 duties where both apply
How we help
We classify products and roles, put the reporting paths into a form that works under time pressure, and adjust contracts with suppliers and customers. Where CRA and NIS2 duties overlap, we settle the order beforehand.
Connected products in your range?
We work out which duties apply to you and what has to be in place by when.
Ask for a classificationFrequently asked questions
Does the CRA concern us at all?
It covers products with digital elements made available on the EU market. That runs from consumer devices through business software to industrial systems. It binds not only manufacturers but importers and distributors, each with their own duties. Anyone distributing someone else's software under their own name, or substantially modifying it, becomes a manufacturer themselves.
Which deadlines apply?
The regulation entered into force in December 2024. Since 11 September 2026 the reporting duties for actively exploited vulnerabilities and severe security incidents have applied. The remaining requirements bite from 11 December 2027. The reporting duty therefore arrives long before the rest of the regime.
What about open source software?
Open software not supplied in the course of a commercial activity is in principle excluded. The line runs along commercial activity, not along the licence type. Anyone building open components into their own product and distributing it cannot rely on the exception and answers for everything they ship.