Business.gov.nl uses cookies to improve the website. These functional and analytical cookies do not contain your personal data. Do you want to watch video content? Third parties may place tracking cookies to track your online behaviour. You can refuse these tracking cookies. How cookies are used on Business.gov.nl.

Products must meet mandatory cybersecurity requirements (CRA)

Published by:
Netherlands Enterprise Agency, RVO
1 min read
Nederlandse versie
Effective date of this change in law: 11 December 2027

For whom?

  • manufacturers of products with a digital component and software
  • authorised representatives appointed by the manufacturers to carry out obligations on their behalf
  • importers bringing such products to the EU market
  • distributors selling products with a digital component

What changes?

The Cyber Resilience Act (CRA) is an EU Act that aims to enhance the security of products with digital elements. The CRA is also known as the Cyber Resilience Regulation (Verordening cyberweerbaarheid). 

The CRA sets security requirements for software and hardware with digital functions. It concerns both hardware and software that can be connected directly or indirectly to a device or network.

Reporting obligation already effective

As of 11 September 2026 manufacturers manufacturers must report actively exploited vulnerabilities and serious security incidents with their digital products.  Reporting can be done via the European CRA Single Reporting Platform or the digital reporting form of the National Cyber Security Centre (NCSC, in Dutch).

More rules from 11 December 2027

From 11 December 2027 most other rules set by the CRA will apply. Manufacturers must then

  • design and develop digital products to be secure (security by design)
  • assess the risks concerning digital security
  • address vulnerabilities during a product's support period
  • provide security updates
  • provide information on the security and safe use of the product
  • demonstrate that the product complies with the regulations

Products that meet the requirements will have CE marking. In some cases an external party must make the assessment.

Importers and distributors will also have obligations. They must, among other things, check whther products meet the requirements before they offer thesde products on the EU market. 

You can find the most important information on the new rules in the Cyber Resilience Act Guide. 

When?

  • Since 11 September 2026 manufactureurs must report serious security issues and actively exploited vulnerabilities. 
  • Most other obligations from the Cyber Resilience Act will take effect on 11 December 2027.

Amendments

More changes on this subject:

This article is related to:

How would you rate this page?(question 1 of max 3)
We are sorry to hear that. How can we improve?(question 2 of 3)

Questions relating to this article?

Please contact the Netherlands Enterprise Agency, RVO