Security requirements for digital products (CRA)
Do you manufacture products with digital components? For example, smart devices, video cards, network equipment, or software such as video games, operating systems, or mobile apps? Then you must report serious security issues.
What do you need to report?
The reporting obligation applies to manufacturers of digital products. These include, for example, software, apps, smart devices and other devices with digital functions.
You must report the following issues:
- actively exploited vulnerabilities, such as faults in software or hardware and you notice that hackers are using these faults to gain access to a product
- serious security incidents that affect the security of your digital product
You report such incidents to ENISA's CRA Single Reporting Platform or via the National Cyber Security Centre’s (NCSC) online reporting form (in Dutch). NCSC will then pass it on to ENISA so it will reach the other EU countries concerned.
How soon do you have to report?
- within 24 hours: a first warning
- within 72 hours: provide more information on the problem, the product, and potential solutions
Why must you report incidents?
The reporting obligation is part of the European Cyber Resilience ACT (CRA) - also known as the Cyber Resilience Regulation (Verordening cyberweerbaarheid). This act aims to better protect digital products in the European Union.
Besides the reporting obligation, the CRA also sets a number of other requirements. These requirements will take effect from 11 December 2027.
Amendments
The information on this page can change due to:
- Products must meet mandatory cybersecurity requirements (CRA)Effective date: 11 December 2027