Basic Information

Upcoming Cyber Resilience Act (CRA)

The European Union's Cyber Resilience Act (CRA) entered into force on 10 December 2024 and establishes mandatory cybersecurity requirements for products with digital elements, including software, connected devices, and their components.

Manufacturers, importers, and other economic operators must ensure that products are designed, developed, and maintained with cybersecurity in mind throughout their support period. Products that comply with the CRA requirements will continue to bear the CE marking, demonstrating conformity with EU cybersecurity requirements.

From 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe security incidents to the relevant authorities through the EU's reporting framework. The CRA's main obligations, including the essential cybersecurity requirements and vulnerability handling processes, become fully applicable on 11 December 2027.

Organisations placing products with digital elements on the EU market should already be preparing their compliance programmes, product security processes, vulnerability management procedures, and technical documentation to meet the CRA requirements. This requires typically some preparations:

Implement Security by Design in planning, design, development, production, delivery and maintenance phases. As importer you have to present that the product was designed with security in mind.

Make products' security updates available for at least 5 years and instruct customers on how to update the product.

Handle vulnerabilities effectively when they appear for the expected product lifetime or for a period of five years. There are exceptions.

Report any actively exploited vulnerabilities & incidences.

Demonstrating compliance with the Cyber Resilience Act (CRA) increasingly involves European standards. Harmonised European Standards (hENs) provide a recognised route to demonstrating conformity with the corresponding CRA requirements and, once cited in the Official Journal of the European Union, can provide a presumption of conformity.

The standards cover both general cybersecurity requirements and requirements for specific product categories. Horizontal standards address overarching aspects such as cybersecurity principles, risk assessment, secure product development and vulnerability handling. Product-specific, or vertical, standards provide more detailed cybersecurity requirements and assessment criteria for particular categories of products with digital elements.

The first CRA-related European standards are now progressing through the approval process. In particular, ETSI is developing the ETSI EN 304 6xx series, covering product categories such as browsers, VPNs, network management systems, SIEM systems and operating systems. In August 2026, ETSI submitted 17 vertical CRA standards for the European approval process with the aim of having them adopted as harmonised European Standards.

Manufacturers should therefore identify the standards relevant to their products and monitor their status. Draft standards may already provide useful guidance for implementation, but the legal presumption of conformity applies only once a standard has been formally harmonised and its reference has been published in the Official Journal of the European Union.

Offerings

I offer you, based on technical security and privacy knowledge, scientific research, practical experiences in technology developments and active particpation during the definition of the Cyber Resilience Act:

  1. Security Engineering and Safety Compliance Comprehensive security engineering services, ensuring potential safety requirements are addressea,d while also considering data protection regulations and breach reporting protocols.

  2. Comprehensive Cybersecurity and Technology Consulting Consulting services covering a wide range of topics, including cybersecurity, software development, governance, compliance, cloud, open source, artificial intelligence, technical planning, and technical evaluation; supporting businesses, organisations, and individuals in navigating complex technical landscapes.

  3. Strategic Cybersecurity Consulting I provide expert guidance on strategic and business-related cybersecurity challenges for your products, validating your processes, helping you align the CRA's security measures with business objectives.

That's all at a very high-level. Let's get in contact to prepare a deep dive addressing your demand.