The Cyber Resilience Act (CRA) is an EU regulation that establishes mandatory cybersecurity requirements for products with digital elements placed on the EU market. Its objective is to improve cybersecurity throughout a product's lifecycle by ensuring manufacturers build security into products from the outset and continue to manage cybersecurity risks after sale.
The CRA applies to a broad range of connected hardware and software products, including consumer devices, industrial equipment, embedded software, operating systems, and standalone software. Manufacturers must identify and mitigate cybersecurity risks during design and development, produce technical documentation, conduct conformity assessments, and issue a Declaration of Conformity before placing products on the market. Products must also be supplied with security information, clear instructions, and benefit from support periods.
A key feature of the CRA is its focus on the entire product lifecycle. Manufacturers are required to monitor vulnerabilities, provide security updates without undue delay, and maintain coordinated vulnerability disclosure processes. Where appropriate, products should support automatic security updates enabled by default while allowing users to opt out. Actively exploited vulnerabilities and severe security incidents must be reported within specified timeframes.
The CRA also introduces obligations for importers and distributors to verify that products meet the regulation before making them available in the EU. Products considered to present higher cybersecurity risks are classified as Important or Critical products and are subject to more rigorous conformity assessment procedures.
Non-compliance can result in significant penalties, including fines of up to EUR15 million or 2.5% of worldwide annual turnover, whichever is higher. The CRA is intended to create a consistent baseline of cybersecurity across the EU, improve consumer confidence, and strengthen the resilience of Europe's digital economy.
In this report we summarise the key provisions of the CRA regulation, discuss the concept of automatic security updates ‘where applicable’ in some detail, and also seek to dispel some of the more frequent misunderstandings that we hear in discussions with IoT industry stakeholders. We also highlight a key interaction between the CRA and the EU’s NIS 2 Directive.