by Streamlex 20 January 2025
The EU Cyber Resilience Act (CRA), in force since 10 December 2024, introduces mandatory cybersecurity requirements for products with digital elements in the EU market. The legislation impacts manufacturers, importers, and distributors of hardware and software with digital components. This article outlines the key provisions of the regulation, focusing on aspects relevant to manufacturers of digital products, and explains the implementation timeline and enforcement approach.
The CRA requirements apply to all products with digital elements (PDEs) placed on the EU market. PDEs are defined broadly and encompass hardware and software with a direct or indirect connection to a device or a network. Examples of such products are smart home systems, fitness trackers, IoT sensors, networked machinery, and embedded firmware.
‘product with digital elements’ means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately (CRA Article 3(1))
The CRA explicitly excludes from its scope the following groups of PDEs:
Additional limitations and exclusions, such as those applicable to spare parts of PDEs, are also included in the CRA.
The CRA classifies PDEs into four risk-based categories, each with increasing cybersecurity and conformity assessment requirements.
The CRA establishes obligations to enhance cybersecurity throughout a product’s lifecycle:
While most of the obligations fall on manufacturers of PDEs, the CRA also imposes additional requirements on other economic operators, such as importers and distributors.
The CRA’s overall applicability will commence after a three-year period on 11 December 2027, thereby giving companies time to implement the CRA requirements. Certain provisions, however, will apply earlier.
The CRA is enforced by market surveillance authorities in each EU Member State, which oversee compliance, conduct evaluations, and impose corrective actions, including product recalls, restrictions and withdrawals. Non-compliance can result in fines:
Fines consider factors like severity, market impact, and company size, with special considerations for SMEs and startups. Consumers are entitled to enforce their rights through representative actions pursuant to Directive (EU) 2020/1828.
The CRA is part of a rapidly expanding EU digital regulatory framework, closely intertwined with the AI Act, GDPR, and NIS2 Directive. These laws create overlapping compliance obligations, requiring businesses to navigate cybersecurity, AI governance, and data protection as interconnected regulatory challenges. With 19 delegated and implementing acts still to be adopted under CRA alone, companies face ongoing regulatory uncertainty. As the EU continues to refine and expand its digital laws, companies must stay proactive and adaptable, ensuring their compliance strategies address multiple legal frameworks simultaneously. The growing complexity makes it essential to track regulatory updates and understand how different laws impact each other.
Streamlex.eu will serve as a one-stop-shop repository, helping businesses stay informed and manage compliance across the evolving EU digital landscape. Full text of the CRA, with articles conveniently linked to recitals and definitions highlighted throughout the text, is already available on StreamLex.