What is the Cyber Resilience Act?
The Cyber Resilience Act (CRA) is the EU's answer to a familiar problem: digital products are sold with weak default passwords, without updates and with vulnerabilities that nobody takes responsibility for. The regulation makes cybersecurity a product requirement on a par with electrical safety: products with digital elements will in future need CE marking for cybersecurity as well in order to be sold in the EU. The official text and guidance can be found at the European Commission and ENISA.
Who is covered by the CRA?
The CRA targets products, not sectors: all hardware and software with digital elements made available on the EU market: routers, IoT devices, industrial equipment, operating systems, apps and much of the software in between. The obligations sit primarily with the manufacturer, but importers and distributors also carry responsibility. Exemptions include products already regulated separately (such as medical devices and cars), as well as open source software that is not supplied commercially. Products are divided into classes by criticality: the more critical (for example firewalls, hypervisors, password managers), the stricter the requirements for the conformity assessment.
CRA vs. NIS2: the differences
The two are often confused, but they divide the work between them: NIS2 regulates organisations: their risk management, processes and management accountability in critical sectors. The CRA regulates the products: the security of what is sold, regardless of who buys it. A business can therefore be covered by both (if it manufactures digital products and sits in a NIS2 sector), only one of them, or neither. Together with the GDPR, which protects personal data, they form the EU's three main pillars in this area. See also IT compliance.
Timeline: when do the requirements apply?
- December 2024: The CRA entered into force and the phase-in began.
- September 2026: The reporting obligation applies. Manufacturers must notify actively exploited vulnerabilities and serious incidents to ENISA and the national authorities within 24 hours.
- December 2027: All requirements apply in full. Products placed on the market after this date must comply with the CRA to obtain the CE mark.
The dates may seem distant, but product development has long cycles: products designed now must meet the requirements by the time they reach the market.
How to prepare
If you sell hardware or software (including embedded in machinery): map which products are covered and in which class, introduce secure-by-design in development, establish a process for vulnerability handling (including a contact channel for security researchers) and an SBOM (an inventory of software components). If you buy digital products (everyone else): use the CRA as a procurement requirement already now: ask suppliers about their update policy, support period and vulnerability handling. That is exactly the supplier management that NIS2 and a proper IT risk assessment require anyway.
How MI Support IT helps
MI Support IT helps Danish businesses translate the CRA into practice, both as an adviser when procuring equipment that must meet the requirements, and with the overall compliance effort through IT advisory and IT security. Contact us for a chat about what the CRA means for your business.