Regulation

Assess, manage, and demonstrate your compliance with the Cyber Resilience Act

Already in force, the Cyber Resilience Act (CRA) now imposes new cybersecurity requirements on products with digital elements. Securing connected products throughout their lifecycle is no longer optional. With Naaia, you document security guarantees, manage vulnerabilities over time, and keep control of your software dependencies.

Évaluez votre conformité
Understanding the CRA

A product-cybersecurity-based approach

The Cyber Resilience Act (CRA) establishes a European regulatory framework designed to strengthen the cybersecurity of products with digital elements. It requires organizations to integrate security throughout the entire product lifecycle, from design to withdrawal from the market.

The CRA sets out specific obligations for the various operators across the value chain, including manufacturers, importers, distributors, authorized representatives, open-source software stewards, and modifying users. Each of them must implement the measures needed to ensure product security and the management of the associated cyber risks.

The products covered are subject to requirements relating to cybersecurity, vulnerability management, post-market surveillance, and incident reporting. The level of assessment and the applicable obligations vary according to the product's criticality and its potential impact on users and infrastructures. Its scope includes digital products, software, applications, and systems incorporating artificial intelligence (AI) capabilities. The regulation notably takes into account issues related to cybersecurity, connectivity, software updates, as well as predictive or learning features that may affect user safety.

Regulatory requirements

The importance of defining the role of each operator

The CRA does not merely introduce requirements relating to the products themselves; it also assigns specific obligations to each actor involved in making a product with digital elements available on the European market. Depending on whether you are a manufacturer, importer, distributor, authorised representative, open-source software steward, or modifying user, the applicable responsibilities differ.

This classification is an essential step in identifying the relevant obligations, determining each actor's level of responsibility, and building a compliance plan tailored to your organisation.
Manufacturers must, in particular, carry out a risk analysis, compile technical documentation, ensure product traceability, and put in place mechanisms to detect and manage incidents. Importers and distributors, for their part, must verify the conformity of products and cooperate with market surveillance authorities when a product poses a risk to the health or safety of consumers.

The regulation also requires the notification of serious incidents, the organisation of product recalls where necessary, and the provision of appropriate corrective measures for the consumers concerned. In this way, the regulation strengthens the accountability of the entire supply chain.

Risk of non-compliance

What are the risks of non-compliance?

The CRA establishes a significant sanctions regime to ensure a high level of cybersecurity for digital products made available within the EU. In the event of non-compliance with the applicable requirements, the competent authorities may impose corrective measures, restrict or prohibit the product's availability on the market, or even require its withdrawal or recall. Financial penalties can reach up to €15 million or 2.5% of the company's total worldwide annual turnover for the preceding financial year, whichever is higher. Beyond the financial impact, non-compliance can also lead to significant operational, commercial, and reputational consequences for the organization.

The solution

With Naaia

Identify the products affected by the Cyber Resilience Act

Determine which products fall within the scope of the CRA.

Automatically qualify your security obligations

Automatically identify the operational actions to implement and integrate them into your governance

Streamline compliance efforts

Manage your action plans, centralise your evidence, and structure your cybersecurity processes

Manage multiple frameworks in one platform

Monitor and manage your regulatory obligations from a single, always up-to-date source of truth.

The future of AI governance starts here

Accelerate your AI transformation responsibly

Discover how to deploy AI faster, safely, and at scale. Talk to our experts.

Get a demo

Learn about other regulations & norms

Frequently asked questions

  • Which products are covered by the Cyber Resilience Act, and which categories apply?

    The CRA covers products with digital elements placed on the European Union market, whether hardware or software. The regulation applies to manufacturers, importers, distributors, authorized representatives, open-source software stewards, and modifying users, whether established within the European Union or outside it, provided that they make products with digital elements available on the European market. The CRA distinguishes several categories of products according to their level of criticality:
    (1) Products with digital elements – subject to the essential cybersecurity and vulnerability management requirements set out in the regulation
    (2) Important products of class I (for example, certain identity managers, password managers, or network equipment) – subject to enhanced assessment requirements before being placed on the market
    (3) Important products of class II (for example, certain operating systems, firewalls, or critical platforms) – subject to stricter compliance mechanisms due to their potential impact on cybersecurity
    (4) Critical products covered by specific harmonized acts or presenting a particularly high level of risk – subject to reinforced conformity assessment procedures involving, in some cases, a notified body.

    The applicable obligations therefore depend on the nature of the product, its role in the digital ecosystem, and its potential impact on users, organizations, and infrastructures.

  • What are the main Cyber Resilience Act obligations for manufacturers of digital products?

    Manufacturers of products with digital elements must meet several fundamental obligations throughout the product lifecycle, in particular:

    (1) Integrating cybersecurity by design and by default in order to reduce vulnerabilities from the earliest phases of development;
    (2) Carrying out a cybersecurity risk assessment and implementing appropriate technical and organizational measures;
    (3) Maintaining complete technical documentation demonstrating the product’s compliance with the requirements of the regulation;
    (4) Setting up a vulnerability management process, including their identification, handling, and the distribution of the necessary patches;
    (5) Ensuring post-market monitoring and surveillance in order to identify incidents and vulnerabilities affecting the product after it has been placed on the market and throughout the support period;
    (6) Notifying actively exploited vulnerabilities and significant security incidents to the competent authorities within the timeframes set out in the regulation.

    Manufacturers must also provide clear information and instructions to users, ensure the availability of security updates for the defined support period, and be able to demonstrate their compliance to market surveillance authorities.

  • How can organizations prepare for their CRA compliance?

    With the CRA coming into effect progressively, organizations must start structuring their compliance approach now around several priority actions:
    (1) Carrying out an inventory of products with digital elements in order to identify the products falling within the scope of the regulation and the operators concerned across the value chain;
    (2) Classifying products according to their level of criticality in order to determine the applicable regulatory obligations and conformity assessment methods;
    (3) Performing a gap analysis between the requirements imposed by the CRA and existing practices in secure development, vulnerability management, documentation, and surveillance;
    (4) Defining a cross-functional cybersecurity governance, involving the product, quality, compliance, legal, and cybersecurity teams in order to clearly assign responsibilities;
    (5) Setting up a compliance management platform allowing the centralization of evidence, the tracking of action plans, the documentation of risk assessments, and the management of the vulnerability lifecycle.
    Organizations that anticipate these requirements today will be able to demonstrate their compliance more effectively and secure the marketing of their products on the European market, while those that delay their preparation expose themselves to significant regulatory, operational, and financial risks.