Cyber Resilience Act (CRA)
The Cyber Resilience Act is an EU regulation that, for the first time, sets binding cybersecurity requirements for products with digital elements such as software, IoT devices or connected hardware. It obliges manufacturers, importers and distributors to apply security by design, vulnerability management and CE marking, but is not yet fully applicable: it entered into force on 10 December 2024, its main obligations apply only from 11 December 2027, and two sets of provisions apply earlier: those on the notification of conformity assessment bodies since 11 June 2026, and the reporting duties under Article 14 from 11 September 2026.
In practice
For companies that develop or distribute connected software or hardware, the duty to report actively exploited vulnerabilities and severe security incidents to the responsible authority applies from 11 September 2026, with an early warning within 24 hours. The full conformity obligations, including CE marking, apply from 11 December 2027. If you offer connected devices, an app or software with digital elements, check early whether your own products are in scope – plain websites without a “product” character are generally not covered.