Products must meet mandatory cybersecurity requirements (CRA)
For whom?
- manufacturers of products with a digital component and software
- authorised representatives appointed by the manufacturers to carry out obligations on their behalf
- importers bringing such products to the EU market
- distributors selling products with a digital component
What changes?
The Cyber Resilience Act (CRA) is an EU Act that aims to enhance the security of products with digital elements. The CRA is also known as the Cyber Resilience Regulation (Verordening cyberweerbaarheid).Â
The CRA sets security requirements for software and hardware with digital functions. It concerns both hardware and software that can be connected directly or indirectly to a device or network.
Reporting obligation already effective
As of 11 September 2026 manufacturers manufacturers must report actively exploited vulnerabilities and serious security incidents with their digital products. Â Reporting can be done via the European CRA Single Reporting Platform or the digital reporting form of the National Cyber Security Centre (NCSC, in Dutch).
More rules from 11 December 2027
From 11 December 2027 most other rules set by the CRA will apply. Manufacturers must then
- design and develop digital products to be secure (security by design)
- assess the risks concerning digital security
- address vulnerabilities during a product's support period
- provide security updates
- provide information on the security and safe use of the product
- demonstrate that the product complies with the regulations
Products that meet the requirements will have CE marking. In some cases an external party must make the assessment.
Importers and distributors will also have obligations. They must, among other things, check whther products meet the requirements before they offer thesde products on the EU market.Â
You can find the most important information on the new rules in the Cyber Resilience Act Guide.Â
When?
- Since 11 September 2026 manufactureurs must report serious security issues and actively exploited vulnerabilities.Â
- Most other obligations from the Cyber Resilience Act will take effect on 11 December 2027.
Amendments
More changes on this subject:
- Right to repair makes product repair more appealing to consumersEffective date: in 2026