Logo of the website creation company Stack & Co.
Secura

Solutions

European Cyber Resilience Act: what every company selling in Europe needs to know

Read: 7 minutes

An unlocked padlock rests on a computer keyboard.

European Cyber Resilience Act: What Every Business Selling in Europe Needs to Know

The EU Cyber Resilience Act (CRA) officially entered into force on December 11, 2024, setting a new global benchmark for cybersecurity requirements for connected products. Any manufacturer, importer, or distributor placing hardware or software products with digital elements on the EU market must comply, or face fines of up to €15 million or 2.5% of global annual turnover.

What is the Cyber Resilience Act?

The Cyber Resilience Act (CRA) is a landmark piece of legislation designed to address a fundamental gap: the EU market was flooded with digital products that had inadequate cybersecurity, with no common framework to hold manufacturers accountable. From routers and connected objects to enterprise software, the CRA now mandates that:

  • Products are designed according to the principle of security-by-default

  • Manufacturers provide security updates throughout the product's life cycle

  • Vulnerabilities are reported to ENISA within 24 hours of discovery.

  • Products bear the CE marking, demonstrating cybersecurity compliance.

Who is affected?

The CRA applies to almost all products with a digital component that can connect to a network or another device. This includes:

  • Consumer IoT devices (connected TVs, thermostats, fitness trackers)

  • Industrial control systems and SCADA components

  • Operating systems and cloud software

  • Mobile applications

  • Network infrastructure hardware

Critical products — such as firewalls, VPNs, password managers, and industrial automation systems — are subject to stricter Class II requirements, including mandatory third-party audits.

Key Dates

Milestone

Date

The CRA enters into force

December 2024

Vulnerability reporting obligations apply.

September 2026

Full compliance required

December 2027

What Should Businesses Do Now?

  1. Conduct a product inventory: Identify all products within the scope of the CRA.

  2. Perform a cybersecurity risk assessment for each product line.

  3. Update your Software Development Life Cycle (SDLC) to integrate security-by-design.

  4. Establish a vulnerability disclosure policy and an incident reporting process.

  5. Engage with a notified body if your products fall under Class I or Class II.

The CRA is not just a checkbox compliance exercise; it represents a fundamental shift in how digital products must be designed, developed, and maintained. Organizations that start their compliance journey now will be in a much better position than those that wait.

Don't wait for a security breach.

The average cost of a data breach is $4.88 million.

Create a free website with Framer, the website builder loved by startups, designers and agencies.