The Cyber Resilience Act, in plain language.
The Cyber Resilience Act is an EU regulation that makes cybersecurity a legal requirement for products with digital elements. If your product contains software or connects to a network or another device, and you sell it in the EU, it almost certainly applies to you.
What it requires
Products must be secure by design, ship free of known exploitable vulnerabilities, receive security updates over a defined support period, and carry a software bill of materials. Manufacturers must run a process for handling and reporting vulnerabilities, and keep technical documentation. Compliance is confirmed through a conformity assessment, after which the product carries its CE mark.
The dates that matter
After that date, a non-compliant product cannot legally be sold in the EU, and the penalties reach 15 million euro or 2.5 percent of global annual turnover. Importers and distributors share the liability, so the pressure runs through the whole supply chain.
Who has to act
Manufacturers of connected products, and the importers and distributors who place them on the EU market. Most small and mid-size manufacturers have no in-house security team and are not yet ready.
Are you in scope for the CRA?
Answer five quick questions about your product. Nothing is stored or sent. You will get an instant read and a downloadable summary.
Once you know roughly where you stand, a readiness assessment turns that into a precise plan. Book a call.