The Cyber Resilience Act (CRA): what changes for your digital products
The CRA introduces, for the first time, European cybersecurity requirements that apply directly to products — connected objects, software, embedded systems. The deadline may seem distant, but the decisions that determine it (design, supply chain) are being made now.
What is the Cyber Resilience Act?
The Cyber Resilience Act (European cyber resilience regulation) requires manufacturers, importers and distributors of “products with digital elements” — connected objects, embedded software, industrial systems, standalone software — to guarantee a minimum level of security throughout the product lifecycle, from design onward (“security by design”).
The regulation entered into force at the end of 2024. Notification obligations for actively exploited vulnerabilities apply from September 2026, and most of the regulation — security requirements, CE marking — from December 2027. A deadline that may seem distant, but that requires reviewing design processes and a supply chain that cannot be transformed in just a few weeks.
Key points of the CRA
Security by design
Cybersecurity must be built into the product from the design stage, not added afterwards — a change in mindset for many R&D teams.
Vulnerability management
Detection, remediation and documentation of vulnerabilities throughout the product's life, with a formalized process.
Notification within 24 hours
Any actively exploited vulnerability or severe incident must be reported to the competent authority within 24 hours (early warning).
Long-term updates
The manufacturer must provide security fixes throughout the announced support period for the product, backed by technical documentation.
Who is concerned?
The CRA applies to manufacturers of digital products sold in the European Union, to their importers and distributors, as well as to software publishers embedded in physical systems or distributed independently (including SaaS in some cases). Most affected organizations are concerned through their products or software components, rarely through their internal information system alone — this is what distinguishes the CRA from texts such as NIS2 or DORA. The first step is to map precisely which products, and which digital components they embed, fall within the scope of the regulation.
A product governance issue, not only IT
Unlike most cyber regulations, the CRA directly affects product design and development processes — not only the information system. This means involving R&D, purchasing and supply chain teams from the specification phase. Breaches of essential requirements may be sanctioned up to €15 million or 2.5% of annual worldwide turnover, whichever is higher — a level comparable to the GDPR. Good news: much of the work overlaps with an ISO 27001 ISMS already in place or with an EBIOS risk analysis— foundations to reuse rather than duplicate.
Preparing for the CRA, step by step
Map the products concerned
Identify which products and digital components sold in the EU fall within the scope of the regulation.
Assess the gap
Compare your current design, testing and maintenance practices with the CRA's essential requirements.
Integrate security by design
Adapt the development lifecycle so that security requirements are taken into account from the specification stage.
Structure vulnerability management
Set up a process to detect, remediate and document vulnerabilities throughout the product's lifecycle.
Equip the notification process
Define the process for notifying an actively exploited vulnerability to the competent authority within 24 hours.
Document and maintain
Build the expected technical documentation and plan security updates over the announced support period.
Why get support from BCIT?
Clarify your scope
We identify precisely which products and components are concerned, and translate the CRA into concrete obligations for your teams.
Shared foundations
We build on your ISO 27001 or existing risk management approach to avoid duplication.
From diagnosis to steering
From mapping your products through to implementing the notification process, we support you at every stage. Our security audits and our penetration tests complete the approach on the technical side.
Does the CRA apply to you? Let's review it
Let's take 15 minutes to identify the products concerned and lay the first building blocks of a realistic compliance roadmap.
The Cyber Resilience Act (CRA): what changes for your digital products
The CRA introduces, for the first time, European cybersecurity requirements that apply directly to products — connected objects, software, embedded systems. The deadline may seem distant, but the decisions that determine it (design, supply chain) are being made now.
What is the Cyber Resilience Act?
The Cyber Resilience Act (European cyber resilience regulation) requires manufacturers, importers and distributors of “products with digital elements” — connected objects, embedded software, industrial systems, standalone software — to guarantee a minimum level of security throughout the product lifecycle, from design onward (“security by design”).
The regulation entered into force at the end of 2024. Notification obligations for actively exploited vulnerabilities apply from September 2026, and most of the regulation — security requirements, CE marking — from December 2027. A deadline that may seem distant, but that requires reviewing design processes and a supply chain that cannot be transformed in just a few weeks.
Key points of the CRA
Security by design
Cybersecurity must be built into the product from the design stage, not added afterwards — a change in mindset for many R&D teams.
Vulnerability management
Detection, remediation and documentation of vulnerabilities throughout the product's life, with a formalized process.
Notification within 24 hours
Any actively exploited vulnerability or severe incident must be reported to the competent authority within 24 hours (early warning).
Long-term updates
The manufacturer must provide security fixes throughout the announced support period for the product, backed by technical documentation.
Who is concerned?
The CRA applies to manufacturers of digital products sold in the European Union, to their importers and distributors, as well as to software publishers embedded in physical systems or distributed independently (including SaaS in some cases). Most affected organizations are concerned through their products or software components, rarely through their internal information system alone — this is what distinguishes the CRA from texts such as NIS2 or DORA. The first step is to map precisely which products, and which digital components they embed, fall within the scope of the regulation.
A product governance issue, not only IT
Unlike most cyber regulations, the CRA directly affects product design and development processes — not only the information system. This means involving R&D, purchasing and supply chain teams from the specification phase. Breaches of essential requirements may be sanctioned up to €15 million or 2.5% of annual worldwide turnover, whichever is higher — a level comparable to the GDPR. Good news: much of the work overlaps with an ISO 27001 ISMS already in place or with an EBIOS risk analysis— foundations to reuse rather than duplicate.
Preparing for the CRA, step by step
Map the products concerned
Identify which products and digital components sold in the EU fall within the scope of the regulation.
Assess the gap
Compare your current design, testing and maintenance practices with the CRA's essential requirements.
Integrate security by design
Adapt the development lifecycle so that security requirements are taken into account from the specification stage.
Structure vulnerability management
Set up a process to detect, remediate and document vulnerabilities throughout the product's lifecycle.
Equip the notification process
Define the process for notifying an actively exploited vulnerability to the competent authority within 24 hours.
Document and maintain
Build the expected technical documentation and plan security updates over the announced support period.
Why get support from BCIT?
Clarify your scope
We identify precisely which products and components are concerned, and translate the CRA into concrete obligations for your teams.
Shared foundations
We build on your ISO 27001 or existing risk management approach to avoid duplication.
From diagnosis to steering
From mapping your products through to implementing the notification process, we support you at every stage. Our security audits and our penetration tests complete the approach on the technical side.
Does the CRA apply to you? Let's review it
Let's take 15 minutes to identify the products concerned and lay the first building blocks of a realistic compliance roadmap.