The rise of connected products is profoundly reshaping professional practices, while considerably widening the surface exposed to cyber threats. Connected objects, software, applications, network equipment, industrial components, and products embedding artificial intelligence: the majority of digital technologies today rely on software components that may be exposed to security vulnerabilities.
In response, the European Union adopted Regulation (EU) 2024/2847, better known as the Cyber Resilience Act (CRA), which establishes horizontal cybersecurity requirements for products with digital elements made available on the European market. Beyond a purely technical approach, the CRA reflects a paradigm shift: cybersecurity is no longer an add-on feature or a selling point, but a regulatory requirement that must be built into the product from the design stage and maintained throughout its lifecycle.
This article offers a comprehensive guide to the Cyber Resilience Act: its objectives, its scope, the product classification it introduces, the obligations it places on each operator in the value chain, and its application timeline.
1. The objectives of the Cyber Resilience Act: securing products and holding operators accountable
The Cyber Resilience Act forms part of the European Union’s cybersecurity strategy and responds to a threefold finding by the legislator: an insufficient level of cybersecurity across many digital products, frequently inadequate management of vulnerabilities after placing on the market, and a lack of transparency preventing users from assessing the actual security level of the products they acquire.
Historically, regulatory requirements relating to products focused on the moment of placing on the market. The CRA adopts a significantly broader logic by requiring cybersecurity to be taken into account at the design stage, during development, at the commercialisation stage, then after placing on the market and throughout the product’s expected period of use.
The Regulation therefore rests on two main objectives: guaranteeing users a high level of cybersecurity for products with digital elements, from design and throughout their lifecycle, so as to enable an informed choice; and organising the continuous management of vulnerabilities, with products receiving the security patches and updates needed to maintain the expected level of protection over time.
2. The scope of the CRA: a broad perimeter with targeted exclusions
1. The material criterion: the notion of a product with digital elements
The CRA applies to products with digital elements, defined as a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. The Regulation applies, however, only to products whose intended or reasonably foreseeable use includes a direct or indirect, logical or physical, connection to a device or network.
This may cover standalone downloadable software, and firmware and software intended to be integrated into an electronic information system where placed on the market separately, among others. Conversely, websites that do not support the functionality of such a product, as well as cloud services that are not designed and developed under the responsibility of the manufacturer of the product concerned, do not constitute products with digital elements.
2. The territorial criterion: making available on the Union market
The CRA applies as soon as the product is made available on the market of the European Union, that is, supplied for distribution or use there in the course of a commercial activity, whether for payment or free of charge. The operator’s place of establishment is irrelevant in this respect: a manufacturer established outside the Union may be fully subject to the Regulation if its product is intended for the European market.
3. The exclusions provided for by the Regulation
In order to avoid regulatory overlap, the CRA excludes from its scope products already covered by specific sectoral frameworks. Excluded are medical devices and in vitro diagnostic medical devices, products certified in the field of civil aviation under Regulation (EU) 2018/1139, products intended for motor vehicles and their trailers covered by Regulation (EU) 2019/2144, and marine equipment falling under Directive 2014/90/EU.
The Regulation also excludes certain spare parts manufactured to the same specifications as the components they replace, and products developed or modified exclusively for national security or defence purposes, as well as those specifically designed to process classified information. Finally, a more general clause sets aside application of the CRA where other Union rules lay down requirements covering all or part of the risks addressed by the essential cybersecurity requirements of Annex I, provided they guarantee an identical or higher level of protection.
3. A risk-based approach: product classification
The CRA adopts a risk-based approach allowing products with digital elements to be classified according to the impact that exploitation of a vulnerability affecting them would have. This classification is decisive, since it determines the conformity assessment procedure the manufacturer must follow before placing the product on the market.
The classification rests on the product’s core functionality, meaning its principal functionality, the one that characterises its essential purpose. The fact that a product incidentally incorporates a browser, a firewall or an operating system is not enough to give it the core functionality of the corresponding category. Conversely, performing functions additional to those described in the categories of Annexes III and IV does not cause the product to lose the classification flowing from its principal functionality.
1. Products falling within the default category
These are all products with digital elements other than important products and critical products. They are subject to the essential cybersecurity requirements of Annex I and to the vulnerability-handling requirements, but may in principle be subject to internal control carried out by the manufacturer under its own responsibility.
2. Important products falling under Annex III
A product qualifies as important where its core functionality corresponds to a category listed in Annex III and where it performs either functions essential to the cybersecurity of other products, networks or services, or a function carrying a significant risk of adverse effects by virtue of its capacity to disrupt, control or damage other products, or to harm the health, safety or security of users through direct manipulation.
Class I covers, in particular, identity and privileged access management systems, standalone and embedded browsers, password managers, malware-detection software, products with a VPN function, SIEM systems, boot managers, operating systems, routers, modems and switches, as well as certain smart home products, connected toys, and personal wearable health-monitoring products not covered by medical device legislation.
Class II, reserved for products where exploitation of a vulnerability would be liable to cause very serious repercussions, comprises hypervisors and container runtime systems, firewalls and intrusion detection and prevention systems, as well as tamper-resistant microprocessors and microcontrollers.
3. Critical products falling under Annex IV
This category covers products whose core functionality corresponds to a category in Annex IV — hardware devices with security boxes, smart-meter gateways, smart cards or similar devices — and in respect of which there is either a critical dependency of essential entities within the meaning of the NIS 2 Directive, or a risk that incidents or exploited vulnerabilities would cause serious disruption to critical supply chains in the internal market.
IV. Value chain operators and their obligations
The CRA does not target manufacturers alone: it assigns specific obligations to every actor involved in making a product with digital elements available on the European market. The first step is therefore to determine one’s role under the CRA, since this defines the exact perimeter of the applicable responsibilities.
1. The manufacturer
The manufacturer is the natural or legal person who develops or manufactures a product with digital elements, or has it designed, developed or manufactured, and markets it under its own name or trademark, whether for payment, monetisation or free of charge.
The bulk of the burden falls on the manufacturer, and it is not limited to a one-off check before commercialisation: the manufacturer must ensure a level of cybersecurity appropriate to the identified risks from the design stage, and then maintain it throughout the support period. Its obligations are organised around three phases.
- Before placing on the market, it designs a product compliant with the essential cybersecurity requirements, documents its risk assessment, draws up the technical documentation, applies the relevant conformity assessment procedure, then draws up the EU declaration of conformity and affixes the CE marking.
- When placing on the market, it informs users and designates a single point of contact.
- After placing on the market, it handles vulnerabilities throughout the support period, notifies actively exploited vulnerabilities and severe incidents, takes the necessary corrective measures, and cooperates with market surveillance authorities.
2. The authorised representative
Established in the Union, the authorised representative acts on behalf of the manufacturer under a written mandate, for the performance of specified tasks. Drafting that mandate is the central compliance act: it cannot cover the manufacturer’s substantive obligations relating to design, development, production, risk assessment and vulnerability handling, but must at minimum cover document retention, the transmission of information to authorities upon reasoned request, and cooperation on measures intended to eliminate risks.
3. The importer and the distributor
The importer, established in the Union, places on the market a product bearing the name or trademark of a person established outside the Union. It acts as a filter at the entry point of the European market: it is for the importer to ensure, before any placing on the market, that the manufacturer has in fact discharged its own compliance obligations.
The distributor, who makes the product available without altering its properties, exercises a more formal control, centred on vigilance and information flow: due care, refraining from making the product available in the event of serious doubt as to conformity, alerting the manufacturer in the event of a vulnerability, and cooperating with the authorities.
That said, an importer or distributor who places a product on the market under its own name or trademark, or who makes a substantial modification to it, is considered a manufacturer and then becomes subject to the full set of corresponding obligations.
4. The modifying user and the open-source software steward
The CRA introduces two new figures. The modifying user is any person who makes a substantial modification to a product with digital elements and makes it available on the market; that person is then subject to the same requirements as the manufacturer, for the modified part or for the product as a whole where the modification affects its overall cybersecurity.
The open-source software steward is a legal person, necessarily distinct from the manufacturer, that provides systematic and sustained support for the development of products qualifying as free and open-source software intended for commercial activities, and ensures their viability. Its obligations vary according to its actual involvement: every steward must put in place and verifiably document a cybersecurity policy and cooperate with the competent authorities.
5. The essential cybersecurity requirements
A product with digital elements may only be made available on the market if it satisfies the essential requirements of Annex I, Part I, and if the processes put in place by the manufacturer comply with those of Annex I, Part II, relating to vulnerability handling.
These requirements can be understood along four axes.
The first, ensuring an appropriate level of cybersecurity, rests on security by design and by default: taking into account known and reasonably foreseeable risks, limiting attack surfaces, remediating vulnerabilities through regular updates, and recording and monitoring relevant internal activity. The second concerns data and its governance: confidentiality, integrity, minimisation in light of the product’s purpose, and the ability for users to securely delete their data. The third, incident handling, requires protecting the availability of essential functions, limiting the exploitation of flaws, and providing for corrective and resilience measures. The fourth brings together technical documentation and the information owed to users, including the designation of a single point of contact and communication of the end date of the support period.
Together, these requirements form the fundamental bedrock of the Cyber Resilience Act, designed to guarantee a high level of security when products with digital elements are placed on the market.
6. Conformity assessment procedures
The level of scrutiny applied in the conformity assessment varies according to the product category.
For products in the default category, internal control (module A), carried out by the manufacturer under its own responsibility, is in principle sufficient.
For important products in Class I, internal control remains available provided the manufacturer fully applies relevant harmonised standards, common specifications, or European cybersecurity certification schemes reaching at least the “substantial” assurance level. Failing that, or where no such reference frameworks exist, the product must undergo assessment by a notified body, either through EU-type examination followed by conformity to type (modules B + C) or through full quality assurance (module H).
For important products in Class II, third-party involvement is mandatory: modules B + C, module H, or, where available and appropriate, a European cybersecurity certification scheme at an assurance level of at least substantial.
For critical products, European cybersecurity certification becomes mandatory where a delegated act of the Commission so provides and a relevant scheme is available. In the absence of such an act, the manufacturer applies one of the procedures laid down for important products in Class II.
Finally, a specific regime applies to products qualifying as free and open-source software that fall within the categories of Annex III: their manufacturers may demonstrate conformity using one of the general procedures, including internal control, provided the technical documentation is made available to the public at the time the product is placed on the market.
7. A phased application timeline and a significant sanctions regime
1. Staggered entry into application
Having entered into force on 10 December 2024, the CRA provides for staggered application. Chapter IV, on the notification of conformity assessment bodies, has applied since 11 June 2026.
The obligations to report actively exploited vulnerabilities and severe incidents laid down in Article 14 have applied since 11 September 2026, and target manufacturers, modifying users, and open-source software stewards involved in developing the product. The Regulation becomes fully applicable, to all operators, from 11 December 2027.
2. The sanctions regime
Three ceilings structure the regime, with the higher amount applying in each case.
- Non-compliance with the essential requirements of Annex I or with the obligations of Articles 13 and 14 applicable to manufacturers may give rise to a fine of up to €15 million or 2.5% of total worldwide annual turnover.
- Failure to comply with other obligations, such as those of authorised representatives, importers and distributors, or those relating to the EU declaration of conformity, CE marking, and technical documentation, is capped at €10 million or 2% of turnover.
- Supplying incorrect, incomplete, or misleading information to notified bodies or authorities is sanctioned up to €5 million or 1% of turnover.
These fines are not exclusive: they may be imposed in addition to any other corrective or restrictive measure applied for the same infringement — bringing the product into compliance, restricting or prohibiting its availability, or withdrawing or recalling it.
Conclusion: cybersecurity as a governance requirement
With the Cyber Resilience Act, the European Union takes a further step in regulating the digital sphere. The Regulation is not limited to governing incidents or cyberattacks: it imposes a deeper transformation, consisting in embedding cybersecurity from the product design stage and maintaining that level of protection throughout the product’s lifetime.
For manufacturers, authorised representatives, importers, distributors, open-source software stewards, and modifying users, what is at stake goes beyond technical security alone. It is a matter of demonstrating genuine cybersecurity governance, combining the qualification of each actor’s role, product classification, risk management, vulnerability handling, technical documentation, post-market surveillance, and traceability of decisions.
How to structure your CRA compliance?
Five priority actions make it possible to launch the process without waiting for the December 2027 deadline:
1. Carry out an inventory of products with digital elements to identify those falling within scope and the operators concerned across the value chain;
2. Classify these products according to their criticality in order to determine the applicable obligations and assessment routes;
3. Perform a gap analysis between the CRA’s requirements and existing practices in secure development, vulnerability handling, documentation, and monitoring;
4. Define cross-functional governance involving the product, quality, compliance, legal, and cybersecurity teams; and
5. Put in place a management platform centralising evidence, action plans, risk assessments, and the vulnerability lifecycle.
Anticipating the interplay of digital regulations with Naaia
With Naaia, automatically identify the products concerned by the CRA, determine the obligations applicable to each actor in your value chain, and steer your compliance through an operational, centralised, and continuously updated action plan. By centralising the mapping of products and systems, the qualification of roles and use cases, the management of obligations, and the traceability of decisions, Naaia helps organisations move from fragmented compliance to co
