On 18 September 2026, we hosted our webinar on cyber resilience, during which we discussed the impact of the EU Cyber Resilience Act (CRA) and the key steps organizations should take to prepare for its new cybersecurity requirements.
The CRA changes how cybersecurity is addressed for products with digital elements. Rather than focusing on the security of organizations and networks, the CRA introduces cybersecurity requirements for products themselves, covering their development, placement on the EU market, and post-market support.
Its scope is broad. Connected hardware and (open source) software may qualify as products with digital elements where they have a direct or indirect connection to a device or network and are supplied on the EU market in the context of a commercial activity. This can include anything from routers, connected devices, and industrial IoT products to operating systems, mobile applications, and business software. Certain remote data processing solutions associated with a product may also be relevant. At the same time, specific exclusions and special regimes apply, making a product-by-product scope assessment an essential first step.
From organizational cybersecurity to product responsibility
For manufacturers, the CRA makes cybersecurity an integral part of the product lifecycle. Products need to meet essential cybersecurity requirements, including secure-by-design and secure-by-default principles. Manufacturers must identify and address vulnerabilities, provide security updates, and monitor product security throughout the relevant support period. Importers and distributors also have their own verification, cooperation, and corrective-action obligations.
This means that CRA compliance cannot be treated as a one-off certification exercise. Product development, vulnerability management, post-market monitoring, and governance need to work together throughout the lifecycle.
Evidence will be as important as implementation
Being secure is not enough: organizations must also be able to demonstrate compliance. Technical documentation should capture, among other things, the product architecture, cybersecurity risk assessment, security controls, testing, Software Bill of Materials (SBOM), vulnerability-handling arrangements, and update and support policy. This documentation should remain current, traceable, and capable of being provided to market surveillance authorities.
Product classification is another important step. The CRA distinguishes between the default category, important products in Classes I and II, and critical products. The classification can affect the applicable conformity assessment route and whether third-party involvement is required.
The first obligations already apply
The CRA is no longer only a 2027 implementation project. Since 11 September 2026, manufacturers are subject to reporting obligations for actively exploited vulnerabilities and severe incidents affecting product security. These include an early-warning requirement within 24 hours and a further notification within 72 hours.
The broader CRA regime becomes fully applicable on 11 December 2027, including the essential cybersecurity requirements, conformity assessment, and CE-marking requirements.
What should organizations do now?
Preparation should start with a product inventory and documented scope and classification assessment. Organizations can then identify gaps against the CRA, establish clear ownership, integrate security requirements into development processes, and ensure that vulnerability and incident reporting procedures are operational. Technical documentation, SBOM, and risk-assessment processes should be built into existing product governance rather than added shortly before market placement. Existing security frameworks can provide a useful foundation, but they need to be mapped against the CRA's specific requirements.
Finally, the CRA should also be reflected in the supply chain. Contracts with software, component, and technology suppliers should address vulnerability information, security updates, support periods, remediation responsibilities, and the evidence manufacturers need to demonstrate compliance. Ultimately, contractual allocation can support compliance, but does not replace the statutory responsibilities imposed by the CRA. The key message is therefore straightforward: start early and integrate CRA readiness into product development, governance, and contracting rather than treating it as a stand-alone compliance project.
Relive our webinar
Related news:
How can we help?
Discover our expertise