CRA, EU Cyber Resilience Act: everything your business needs to know starting in 2026
On December 10, 2024, the European Union’s Cyber Resilience Act (CRA) came into effect. This regulation establishes mandatory cybersecurity requirements for products with digital components on the European market and provides for a phased implementation through December 2027.
The CRA represents a milestone in the EU’s strategy to strengthen its digital autonomy and protect consumers and businesses in a digital environment that is increasingly vulnerable to threats. The Regulation also covers technologies related to connectivity and network management.
Approved by the European Parliament and the Council of the EU, the legislation was published as Regulation (EU) 2024/2847 in the Official Journal of the European Union. It amends Regulation (EU) No. 168/2013, Regulation (EU) 2019/1020, and Directive (EU) 2020/1828. The regulation applies to the twenty-seven member states of the European Union, including Spain, which must provide resources to market surveillance authorities.
Some of its provisions are already in effect. The chapter on the notification of conformity assessment bodies has been in effect since June 11, 2026, and the obligations to report actively exploited vulnerabilities and serious incidents set forth in Article 14 have been in effect since September 11, 2026. The Regulation will take full effect on December 11, 2027.
Table of Contents
Purpose of the Cyber Resilience Act
The Cybersecurity Resilience Act (CRA) establishes common cybersecurity standards for products containing digital components—whether hardware or software—marketed in the EU.
The law imposes strict cybersecurity requirements on manufacturers, importers, and distributors to ensure comprehensive cyber resilience throughout the entire lifecycle of each product. This ranges from smart home devices to more complex operating systems in critical national infrastructure.
Its purpose is to improve the overall level of cybersecurity and ensure that products are designed and developed with a level of security appropriate to the risk, reducing vulnerabilities and, where applicable, preventing them from reaching the market with known exploitable vulnerabilities.
In addition, it aims to help users better understand the cybersecurity of the products they use daily and reduce risks for both businesses and their customers.
Areas of application
The EU Cyber Resilience Act applies to products with digital components that are sold on the European market. These include Internet of Things (IoT) devices, such as home cameras, refrigerators, televisions, toys, smartwatches, and fitness trackers. It also covers antivirus software, wearables, and other hardware and software products.
It may also cover certain remote processing solutions linked to the operation of a product with digital elements. Software-as-a-Service (SaaS) or cloud services are not automatically included simply because they are digital services.
Thus, certain categories—such as specific medical devices and vehicles, which are already subject to other specific EU regulations—are excluded.
The CRA also establishes specific treatment for free and open-source software. Software provided outside of a commercial activity is not subject to the same obligations as a marketed product.
Requirements for market participants
The affected products must comply with a series of essential cybersecurity requirements. Therefore, manufacturers, importers, and distributors must take into account aspects such as:
- Designing and manufacturing products to minimize vulnerabilities.
- Conducting a risk assessment.
- Maintaining technical documentation.
- Managing vulnerabilities and providing the necessary security updates during the support period.
- Affix the CE (European Conformity) marking to the product.
- Have a vulnerability management policy in place.
- Provide transparent information regarding the support period.
- Implement security-by-design and security-by-default mechanisms.
- Assume responsibility if the manufacturer introduces modified products or products marketed under a different brand.
- Report actively exploited vulnerabilities and serious incidents in the cases provided for by the Regulation.
The notification obligations under Article 14 also apply to products with digital components falling within the scope of the CRA that were placed on the market before December 11, 2027.
The CRA is particularly relevant to the connectivity sector. “Significant products with digital elements” include categories directly related to networks, such as network management systems, physical and virtual network interfaces, and routers, among others.
Implementation deadlines for the Cyber Resilience Act
The CRA is being implemented in phases:
December 10, 2024: Regulation (EU) 2024/2847 enters into force.
June 11, 2026: The provisions of Chapter IV regarding the notification of conformity assessment bodies take effect.
September 11, 2026: The notification obligations set forth in Article 14 take effect.
December 11, 2027: General implementation of the Regulation.
The transition period allows market participants, particularly small and medium-sized enterprises, to gradually adapt their products, processes, and cybersecurity management systems to the new regulatory framework.
More information: Official Journal of the European Union and Cyber Resilience Act.
Relevant articles
- We're talking about
- News and Trends
- Infrastructure and Networks
- Cibersecurity and Data