The CRA in 60 Seconds
The Cyber Resilience Act (CRA, Regulation 2024/2847) is an EU regulation that sets mandatory cybersecurity requirements for products with digital elements — hardware and software — sold in the EU market. It requires manufacturers to design, develop, and maintain products with cybersecurity in mind throughout their lifecycle.
Think of it as the CE marking requirement, but for cybersecurity. If your product connects to a network, the CRA probably applies to you.
Who Does the CRA Apply To?
Products with Digital Elements
Any product that includes software or connects to a device or network:
- IoT devices: Smart home devices, industrial sensors, wearables, connected appliances
- Software: Operating systems, browsers, VPNs, password managers, firewalls, SIEM
- Hardware: Routers, switches, smart cards, industrial controllers
- Embedded systems: Automotive components, medical device software, industrial automation
Excluded: Medical devices (regulated under MDR), aviation (EASA), motor vehicles (type approval), national security, military, and open-source software developed non-commercially.
Open-source exception: Non-commercial open-source is excluded, BUT a new "open-source steward" role was created for organisations that systematically support open-source used in commercial products (e.g., Red Hat for Ansible, Linux Foundation projects).
Product Categories
- Default (self-assessment): ~90% of products. Manufacturer self-assesses compliance.
- Important Class I: Higher-risk products like identity management systems, VPNs, network management, SIEM, routers, operating systems. Third-party assessment OR harmonised standards.
- Important Class II: Highest-risk products like hypervisors, firewalls, tamper-resistant microprocessors, industrial automation. Mandatory third-party conformity assessment.
- Critical: Defined by delegated acts. Hardware security modules, smart meter gateways, smartcard-related products.
Kubernetes Recipes
Practical guide for container orchestration and deployment — hands-on patterns you can use today.
View on Amazon →Essential Requirements
- Security by design: Products designed and developed with security from the start
- No known exploitable vulnerabilities: Products must be delivered without known exploitable vulnerabilities
- Secure default configuration: Secure out of the box — no default passwords
- Vulnerability handling: Manufacturers must have a coordinated vulnerability disclosure process
- Security updates: Free security updates for the expected product lifetime (minimum 5 years)
- SBOM: Software Bill of Materials documenting all components (top-level dependencies minimum)
- Incident reporting: Actively exploited vulnerabilities reported to ENISA within 24 hours
Key Deadlines
- 11 September 2026: Vulnerability and incident reporting obligations apply (manufacturers must report actively exploited vulnerabilities to ENISA)
- 11 December 2027: Full CRA requirements apply — all products with digital elements must comply
- Ongoing: Security updates must be provided for the product's expected lifetime
Back-End Infrastructure: Servers, Secure APIs and Data
Build secure back-end infrastructure from the ground up. In collaboration with Starweaver.
Start on Coursera →CRA and AI
AI-enabled products with digital elements are explicitly covered. The CRA works alongside the EU AI Act:
- High-risk AI systems that are also products with digital elements must comply with both the AI Act and the CRA
- A single conformity assessment can cover both regulations where requirements overlap
- SBOM requirements are particularly relevant for AI: documenting ML frameworks, model dependencies, and training pipeline components
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
