Skip to content
  • AUDIT & CERTIFICATION
    • ISO 42001
    • ISO 27001
    • ISO 27701
    • EU AI ACT
  • TRAINING
    • ISO 42001 LEAD AUDITOR
    • EU AI ACT
  • PARTNERS
    • GLOBAL NETWORK
    • AUDITOR COMMUNITY
  • RESOURCES
  • ABOUT US
  • AUDIT & CERTIFICATION
    • ISO 42001
    • ISO 27001
    • ISO 27701
    • EU AI ACT
  • TRAINING
    • ISO 42001 LEAD AUDITOR
    • EU AI ACT
  • PARTNERS
    • GLOBAL NETWORK
    • AUDITOR COMMUNITY
  • RESOURCES
  • ABOUT US
    • Español
Contact us
    • Español
  • AUDIT & CERTIFICATION
    • ISO 42001
    • ISO 27001
    • ISO 27701
    • EU AI ACT
  • TRAINING
    • ISO 42001 LEAD AUDITOR
    • EU AI ACT
  • PARTNERS
    • GLOBAL NETWORK
    • AUDITOR COMMUNITY
  • RESOURCES
  • ABOUT US
Contact us
November 25, 2024

EU Cyber Resilience Act Published: Key Insights and Deadlines

The EU Cyber Resilience Act introduces cybersecurity rules for digital products, with compliance deadlines starting in 2026 and full enforcement by 2027.

Share:

On 20 November 2024, the EU published the Cyber Resilience Act (CRA) in its Official Journal, introducing a new framework to strengthen cybersecurity in digital products. The CRA establishes consistent rules to address vulnerabilities, improve security, and ensure products remain safe throughout their lifecycle.

What Is the Cyber Resilience Act?

The CRA introduces mandatory cybersecurity standards for products with digital elements (PDEs), such as connected devices, software, and IoT technology. It aims to create a unified approach to cybersecurity, replacing fragmented national regulations and reducing the risks posed by insecure products.

Key Objectives

  • Enhance Security: Ensure digital products are designed and maintained to address cybersecurity risks.
  • Improve Transparency: Require manufacturers to disclose security practices and support timelines.
  • Simplify Compliance: Provide a harmonised framework for businesses operating in multiple EU countries.

Who Needs to Comply?

The CRA applies to manufacturers, importers, distributors, and retailers of PDEs in the EU. Exemptions apply to sectors such as medical devices and motor vehicle systems, which are already governed by existing regulations.


What Are the Key Requirements?

Core Obligations

  • Secure Design: Products must include measures to protect user data and prevent vulnerabilities.
  • Risk Assessments: Manufacturers must evaluate and document cybersecurity risks throughout the product lifecycle.
  • Ongoing Updates: Security updates must be provided regularly to address vulnerabilities.

High-risk products, such as firewalls and password managers, will be subject to more rigorous testing, including third-party evaluations to ensure compliance with CRA standards.


Support for SMEs

Recognising the challenges faced by small and medium-sized enterprises (SMEs), the CRA offers simplified compliance guidance. Open-source software projects intended for commercial use will also benefit from reduced regulatory requirements.


How Will the CRA Be Enforced?

Monitoring and Penalties

  • Oversight: ENISA and national authorities will monitor compliance through checks and coordinated inspections.
  • Penalties for Non-Compliance: Severe breaches can result in fines of up to €15 million or 2.5% of global turnover.

Authorities will also conduct regular “sweeps” to ensure businesses meet the CRA’s standards, with particular focus on cross-border issues.


Timeline for Implementation

  • June 2026: Conformity notifications for assessment bodies begin.
  • September 2026: Rules for incident reporting take effect.
  • December 2027: All CRA requirements become mandatory.

The EU Cyber Resilience Act marks a major step forward in improving the safety and transparency of digital products. Manufacturers and businesses are encouraged to start preparing now by assessing their current practices, identifying gaps, and aligning their processes with the CRA’s requirements. Early action will help ensure a smooth transition and maintain market readiness.

You May Also Be Interested In

US Congress Cracks Down on Deepfakes

DeepMind Employees Unite Against Military-Linked AI Projects

U.S. and China Race to Bring AI into the Classroom

EU AI Act Setback:Standards Won’t Arrive Until 2026

Contact Us

Let us know how we can assist you by completing this short form.

Zertia
  • About us
  • Contact Us
  • Resources
Services
  • ISO 42001
  • ISO 27001
  • ISO 27701
  • EU AI Act
Partners
  • Global Network
  • Auditor Comunity
Information
  • Certification Procedures​
  • Impartiality Policy
  • Media
Social
  • LinkedIn
  • Youtube
Memberships
  • IAPP
  • INCITS
  • EU AI Pact
  • AI & Partners
  • © 2025 Zertia | All Rights Reserved
  • Legal Notice
  • Terms and Conditions of Use
  • Privacy Policy
  • Cookies Policy
We Care About Your Privacy

We use our own and third-party cookies to compile statistics on the use of the website in order to identify faults and improve the content and configuration of the website. We also use own and third party cookies to remember some options you have chosen (language, for example) and to show you advertising related to your preferences, based on a profile developed from your browsing habits (for example, from the web pages visited).

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
3rd Party Cookies
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc. Keeping this cookie enabled helps us to improve our website.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Show Purposes
{title} {title} {title}
We Care About Your Privacy
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
3rd Party Cookies
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc. Keeping this cookie enabled helps us to improve our website.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Show Purposes
{title} {title} {title}
Thank you for contacting us
Your message has been sent successfully, we will contact you as soon as possible.