European Cyber Resilience Act: what every company selling in Europe needs to know
Read: 7 minutes

European Cyber Resilience Act: What Every Business Selling in Europe Needs to Know
The EU Cyber Resilience Act (CRA) officially entered into force on December 11, 2024, setting a new global benchmark for cybersecurity requirements for connected products. Any manufacturer, importer, or distributor placing hardware or software products with digital elements on the EU market must comply, or face fines of up to €15 million or 2.5% of global annual turnover.
What is the Cyber Resilience Act?
The Cyber Resilience Act (CRA) is a landmark piece of legislation designed to address a fundamental gap: the EU market was flooded with digital products that had inadequate cybersecurity, with no common framework to hold manufacturers accountable. From routers and connected objects to enterprise software, the CRA now mandates that:
Products are designed according to the principle of security-by-default
Manufacturers provide security updates throughout the product's life cycle
Vulnerabilities are reported to ENISA within 24 hours of discovery.
Products bear the CE marking, demonstrating cybersecurity compliance.
Who is affected?
The CRA applies to almost all products with a digital component that can connect to a network or another device. This includes:
Consumer IoT devices (connected TVs, thermostats, fitness trackers)
Industrial control systems and SCADA components
Operating systems and cloud software
Mobile applications
Network infrastructure hardware
Critical products — such as firewalls, VPNs, password managers, and industrial automation systems — are subject to stricter Class II requirements, including mandatory third-party audits.
Key Dates
Milestone | Date |
|---|---|
The CRA enters into force | December 2024 |
Vulnerability reporting obligations apply. | September 2026 |
Full compliance required | December 2027 |
What Should Businesses Do Now?
Conduct a product inventory: Identify all products within the scope of the CRA.
Perform a cybersecurity risk assessment for each product line.
Update your Software Development Life Cycle (SDLC) to integrate security-by-design.
Establish a vulnerability disclosure policy and an incident reporting process.
Engage with a notified body if your products fall under Class I or Class II.
The CRA is not just a checkbox compliance exercise; it represents a fundamental shift in how digital products must be designed, developed, and maintained. Organizations that start their compliance journey now will be in a much better position than those that wait.
Don't wait for a security breach.
The average cost of a data breach is $4.88 million.
