Skip to main content

The 7-Step Guide to the EU Cyber Resilience Act (CRA)

Dirk Leopold Dirk Leopold 5 min read
The 7-Step Guide to the EU Cyber Resilience Act (CRA)

Provocative question: Will your product still be legally sellable in Europe after December 2027?

Digital connectivity offers immense opportunities, but also creates unprecedented security risks. The EU is responding to this challenge with the Cyber Resilience Act (CRA) — a directly applicable law that shifts responsibility for cybersecurity from end users to manufacturers and distributors.

The CRA is not optional. It is the new entry ticket to the EU market. Let me show you how to master the complexity and turn compliance into a competitive advantage.

1. The Broad Scope and Tight Deadlines

At its core, the CRA applies to almost all products that contain hardware or software and can connect to the internet or another device. This includes:

  • Consumer devices: Smart-home solutions, wearables, connected toys.
  • Industrial technology: Routers, firewalls, industrial control systems (ICS).
  • Software: Operating systems, mobile and desktop applications.

Watch out: deadlines!

Many are looking ahead to 2027, but the pressure starts considerably earlier:

  • September 2026: The mandatory reporting obligation for actively exploited vulnerabilities and serious security incidents begins.
  • December 2027: The full application of all CRA requirements becomes mandatory.

For violations of the fundamental cybersecurity requirements, fines of up to €15 million or 2.5% of total global annual turnover apply, whichever is higher.

2. The Chain of Responsibility: Who Is Liable?

The CRA distributes obligations across the entire supply chain, covering the so-called “economic operators”:

  • Manufacturers: Primary responsibility lies here. They must conduct the Cybersecurity Risk Assessment (TARA), demonstrably design the product securely, and maintain technical documentation throughout the entire product lifecycle.
  • Importers: They are responsible for verifying that the manufacturer has fulfilled all CRA obligations (e.g. CE marking and documentation). Importers thus assume direct liability.
  • Distributors: They must ensure that the product carries a valid CE marking and that all required instructions and information are included before it is sold to the end customer.

Every link in this chain can be held accountable for non-compliance.

3. The Foundation: Secure by Design & Threat Analysis

The CRA requires the implementation of technical measures into the product itself:

  • Secure by Default: Delivery in the most secure state (e.g. no universal passwords, deactivation of unnecessary services).
  • Minimised attack surface: Limiting potential entry points for cyberattacks in the product design.
  • Integrity and confidentiality: Protection of data and commands through robust authentication and modern encryption.

The key to meeting these requirements is the Cybersecurity Risk Assessment, specifically Threat Analysis and Risk Assessment (TARA). TARA is not a one-off document — it is a continuous process that must be carried out at every phase of the product lifecycle.

My expert advice: Avoid the “spreadsheet trap”! A manual TARA is inefficient and error-prone. Dedicated tools like itemis SECURE provide a structured methodology (aligned with IEC 62443) and automation to create revision-safe technical documentation and integrate it into your agile workflow.

4. The Supreme Discipline: Vulnerability Handling

The greatest organisational challenge is vulnerability and incident management after market introduction:

  • 24-hour reporting obligation: Manufacturers must report actively exploited vulnerabilities and serious incidents to ENISA within 24 hours. This requires a practised, fast-reacting incident response team (PSIRT).
  • Software Bill of Materials (SBOM): You must create and maintain an “ingredient list” of all software components (including open-source libraries) in a machine-readable format (e.g. SPDX or CycloneDX). This is essential for rapid response to new vulnerabilities in third-party components.
  • CVD Policy: A public Coordinated Vulnerability Disclosure policy and a dedicated contact point must be established so that external security researchers can report vulnerabilities responsibly.

5. Market Access, Conformity and Lifecycle Obligations

Compliance is demonstrated through a conformity assessment procedure that concludes with the affixing of the CE marking. The procedure depends on the risk class of your product:

  • Standard products: Self-assessment by the manufacturer.
  • Important and critical products (e.g. firewalls, operating systems): Require a stricter assessment, often involving a notified body or even a European cybersecurity certificate.

Extended responsibility over the lifecycle:

The CRA significantly extends manufacturer responsibility:

  • Minimum support period: You must provide free security updates for the entire expected product lifetime (but at least five years).
  • Documentation archiving: All technical documents, including risk assessments and SBOMs, must be retained for at least ten years after the product is placed on the market.

6. The Holistic View: Interplay with Other EU Regulations

The CRA does not exist in isolation. A coherent compliance strategy must account for its interaction with other legislation:

  • CRA & NIS2: The NIS2 Directive addresses the security of organisational entities (infrastructure), while the CRA governs the security of products. A CRA-compliant product helps NIS2-obligated operators meet their own security requirements.
  • CRA & GDPR: The General Data Protection Regulation protects personal data. A secure product (CRA compliance) is the technical foundation for Privacy by Design and protects against data breaches, which in turn constitute GDPR violations.
  • CRA & AI Act: For high-risk AI systems classified as digital products, requirements overlap. Fulfilling CRA requirements is often considered sufficient to meet the corresponding cybersecurity requirements of the AI Act.

7. Compliance Roadmap: The Seven-Step Plan

Implementation requires a clear strategy. Start now with the following steps:

  1. Assess and classify your portfolio: Determine the applicability and risk class (Standard, Important, Critical) of your products to define the correct conformity path.
  2. Conduct a detailed gap analysis: Audit your products and processes against the technical and procedural requirements of the CRA.
  3. Integrate a Secure Development Lifecycle (SDL): Make threat modelling mandatory in the design phase and introduce automated security testing in the CI/CD pipeline.
  4. Create an SBOM and Vendor Management Policy: Automate the generation of the SBOM and update supplier contracts to enforce security requirements.
  5. Establish a robust vulnerability management programme: Define and practise the 24/72-hour reporting process and publish a CVD policy.
  6. Develop a documentation and conformity strategy: Create the complete technical documentation and prepare for CE marking and, where applicable, audits by notified bodies.
  7. Train teams and ensure continuous compliance: Invest in role-specific training (engineering, product management, legal) and establish processes for long-term post-market surveillance.

December 2027 is closer than you think when you consider the effort required for the necessary process and tooling changes. Those who start now with a structured, tool-supported strategy not only secure market access — they build demonstrable product resilience.

CRA compliance with itemis SECURE — How to implement TARA, SBOM and vulnerability handling efficiently and in an audit-proof way: itemis SECURE →

Dirk Leopold

Executive Vice President Digital Engineering

Dirk Leopold bridges complex engineering requirements and cybersecurity standards in the automotive and IoT domains. As a driving force behind itemis SECURE, he has deep expertise in Threat Analysis and Risk Assessment (TARA) and “Security by Design” methodologies. As a speaker, he focuses on how standards like ISO/SAE 21434 and the Cyber Resilience Act (CRA) impact the future of connected products. He is co-founder and president of CRAIG, an online community supporting the introduction of the CRA across Europe.

More Articles on This Topic