Skip to Content

The Cyber Resilience Act (CRA): what changes for your digital products

The CRA introduces, for the first time, European cybersecurity requirements that apply directly to products — connected objects, software, embedded systems. The deadline may seem distant, but the decisions that determine it (design, supply chain) are being made now.

BCIT Formation logo
BCIT Formation is rated Excellent
4.7 · Trustpilot
🎓 1,000+ learners trained

What is the Cyber Resilience Act?

The Cyber Resilience Act (European cyber resilience regulation) requires manufacturers, importers and distributors of “products with digital elements” — connected objects, embedded software, industrial systems, standalone software — to guarantee a minimum level of security throughout the product lifecycle, from design onward (“security by design”).

The regulation entered into force at the end of 2024. Notification obligations for actively exploited vulnerabilities apply from September 2026, and most of the regulation — security requirements, CE marking — from December 2027. A deadline that may seem distant, but that requires reviewing design processes and a supply chain that cannot be transformed in just a few weeks.

Key points of the CRA

Security by design

Cybersecurity must be built into the product from the design stage, not added afterwards — a change in mindset for many R&D teams.

Vulnerability management

Detection, remediation and documentation of vulnerabilities throughout the product's life, with a formalized process.

Notification within 24 hours

Any actively exploited vulnerability or severe incident must be reported to the competent authority within 24 hours (early warning).

Long-term updates

The manufacturer must provide security fixes throughout the announced support period for the product, backed by technical documentation.

Who is concerned?

The CRA applies to manufacturers of digital products sold in the European Union, to their importers and distributors, as well as to software publishers embedded in physical systems or distributed independently (including SaaS in some cases). Most affected organizations are concerned through their products or software components, rarely through their internal information system alone — this is what distinguishes the CRA from texts such as NIS2 or DORA. The first step is to map precisely which products, and which digital components they embed, fall within the scope of the regulation.

A product governance issue, not only IT

Unlike most cyber regulations, the CRA directly affects product design and development processes — not only the information system. This means involving R&D, purchasing and supply chain teams from the specification phase. Breaches of essential requirements may be sanctioned up to €15 million or 2.5% of annual worldwide turnover, whichever is higher — a level comparable to the GDPR. Good news: much of the work overlaps with an ISO 27001 ISMS already in place or with an EBIOS risk analysis— foundations to reuse rather than duplicate.

Preparing for the CRA, step by step

1

Map the products concerned

Identify which products and digital components sold in the EU fall within the scope of the regulation.

2

Assess the gap

Compare your current design, testing and maintenance practices with the CRA's essential requirements.

3

Integrate security by design

Adapt the development lifecycle so that security requirements are taken into account from the specification stage.

4

Structure vulnerability management

Set up a process to detect, remediate and document vulnerabilities throughout the product's lifecycle.

5

Equip the notification process

Define the process for notifying an actively exploited vulnerability to the competent authority within 24 hours.

6

Document and maintain

Build the expected technical documentation and plan security updates over the announced support period.

Why get support from BCIT?

Clarify your scope

We identify precisely which products and components are concerned, and translate the CRA into concrete obligations for your teams.

Shared foundations

We build on your ISO 27001 or existing risk management approach to avoid duplication.

From diagnosis to steering

From mapping your products through to implementing the notification process, we support you at every stage. Our security audits and our penetration tests complete the approach on the technical side.

Does the CRA apply to you? Let's review it

Let's take 15 minutes to identify the products concerned and lay the first building blocks of a realistic compliance roadmap.