The Cyber Resilience Act is the first EU regulation with binding cybersecurity minimum requirements for all connected products on the EU market. It applies across products and industries.
Scope. Products with digital elements are affected: hardware and software with a data connection. The obligations apply to manufacturers, but also to importers and distributors who make such products available in the EU.
Core principles. Security by Design: build security in from the concept phase. Security by Default: secure default configuration at the point of delivery. Lifecycle responsibility: vulnerability management, update management and reporting obligations throughout the entire support period.
Penalties. Violations of the essential cybersecurity requirements can result in fines of up to €15 million or 2.5% of global annual turnover, whichever is higher.
The Three Critical Dates
10 December 2024: The CRA entered into force.
11 September 2026: Reporting obligations take effect. Actively exploited vulnerabilities and serious incidents must be reported to ENISA: early warning within 24 hours, full notification within 72 hours, final report no later than 14 days after a remedy is available. → What manufacturers need to build before September 2026
11 December 2027: Full application. All requirements apply to products placed on the EU market, including conformity assessment, CE marking and technical documentation.
Cyber Resilience Act – Full application
Seconds
00
Days
00
Hours
00
Minutes
00
Seconds
Click to switch view