← All guides

EU Cyber Resilience Act (CRA): Cybersecurity Requirements for Connected Products

Updated 2026-08-03

The EU Cyber Resilience Act (CRA, Regulation 2024/2847) establishes mandatory cybersecurity requirements for products with digital elements sold in the EU. From December 2027, manufacturers must ensure products are secure by design, provide security updates for the product's expected lifetime, and handle vulnerabilities responsibly. Products must carry CE marking demonstrating cybersecurity compliance.

Primary sources

This page is grounded in the primary materials below. Rules change, so open the source and confirm the current version before acting.

FAQ

What products are covered by the Cyber Resilience Act?+

The CRA covers all products with digital elements that are directly or indirectly connected to another device or network. This includes IoT devices (smart home products, wearables), software (operating systems, applications), and hardware with embedded software. Exceptions include open-source software (non-commercial), medical devices, and vehicles (covered by other regulations).

What are the cybersecurity obligations for manufacturers?+

Manufacturers must: design and develop products with essential cybersecurity requirements (secure by default, no known vulnerabilities, data protection), conduct conformity assessments, provide security updates for the support period, establish vulnerability handling processes, and report actively exploited vulnerabilities to ENISA within 24 hours.

When does the CRA take effect?+

The CRA entered into force on December 10, 2024. Manufacturers must report actively exploited vulnerabilities from September 11, 2026. The main obligations for manufacturers, importers, and distributors apply from December 11, 2027, including the requirement for CE marking for cybersecurity.

How does this affect importers of smart/IoT products?+

Importers must verify that the manufacturer has conducted conformity assessments, the product bears CE marking, and technical documentation is available. Importers must not place non-compliant products on the market and must ensure products are accompanied by required documentation and instructions in the appropriate EU language.

What is the difference between important and critical products?+

The CRA classifies products into two categories: 'important' Class I (e.g., operating systems, routers, smart home devices) and 'important' Class II (e.g., firewalls, intrusion detection systems, industrial control systems). Class II products require third-party conformity assessment. 'Critical' products (with digital elements serving essential functions) also require third-party assessment.

What happens if a vulnerability is discovered after sale?+

Manufacturers must handle vulnerabilities throughout the product's expected lifetime. This includes providing security updates, notifying users of vulnerabilities, and reporting actively exploited vulnerabilities to ENISA within 24 hours. Importers and distributors who become aware of vulnerabilities must notify the manufacturer and market surveillance authorities.

Continue checking

Want to know how these rules apply to you?

Enter DTC and marketplace sales, inventory locations and order values by market to see which information is still outstanding.

Run my free checkView sample reportView sources and scope

This is a preliminary self-check, not tax advice. Decisions on registration, tax charging or collection, return filing and payment should be confirmed with a qualified professional. Questionnaire answers are used only to generate the result; see the Privacy Policy for details.