Launcher

Type to filter results. Use arrow keys to navigate, Enter to select.

Preferences

You've reached the end of the results

The Cyber Resilience Act, Regulation (EU) 2024/2847, establishes horizontal EU cybersecurity requirements for products with digital elements.

While the NIS2 Directive and DORA primarily address the operational resilience and ICT risk management of organisations, the CRA focuses on the security of digital products placed on the EU market. It introduces requirements covering product design, development, vulnerability handling, security updates, conformity assessment and CE marking.

The CRA applies to hardware and software products made available on the EU market, including certain remote data-processing solutions that are integral to a product. Important exclusions and special rules apply, including for some medical, automotive, aviation, marine, defence and national-security products, and for free and open-source software developed or supplied outside a commercial activity.

  • Four Core Areas of CRA Compliance
    1. Security by Design and by Default

    Manufacturers must design, develop and produce products with digital elements in accordance with the essential cybersecurity requirements in Annex I. Key requirements include:

    • Making products available without known exploitable vulnerabilities;
    • Applying secure-by-default configurations;
    • Protecting confidentiality, integrity and availability according to the product's cybersecurity risk;
    • Limiting attack surfaces, including external interfaces, to what is necessary;
    • Protecting data, commands, programs and configurations against unauthorised access or modification;
    • Reducing the impact of security incidents through appropriate technical measures; and
    • Providing security updates, including automatic updates where required or appropriate.

    The precise controls depend on the product's intended purpose, operating environment and documented cybersecurity risk assessment. Encryption and automatic updates are therefore not unconditional requirements for every product.

    2. Vulnerability Handling and Support

    Manufacturers must maintain processes for identifying, documenting and addressing vulnerabilities throughout the declared support period. Core obligations include:

    • Support period: The manufacturer must determine, document and communicate the period during which vulnerabilities will be handled. This period must normally be at least five years, unless the product is expected to be used for less than five years. Where expected use is longer, the support period should reflect that longer period.
    • Security updates: Security updates must be made available without undue delay and, as a rule, free of charge. A limited exception may apply where a manufacturer and a business user agree otherwise for a tailor-made product.
    • Software Bill of Materials: Manufacturers must prepare an SBOM in a commonly used, machine-readable format, covering at least the product's top-level dependencies.
    • Coordinated vulnerability disclosure: Manufacturers must maintain and enforce a coordinated vulnerability disclosure policy and provide an accessible contact point through which vulnerabilities can be reported.
    • Dependency monitoring: Manufacturers must assess third-party and open-source components and take appropriate action when vulnerabilities affect the product.

    The CRA does not generally require manufacturers to publish their complete SBOM or provide it automatically to every customer. Access may nevertheless be addressed contractually or required by a competent authority.

    3. Reporting of Actively Exploited Vulnerabilities and Severe Incidents

    From 11 September 2026, manufacturers will have mandatory reporting obligations for: actively exploited vulnerabilities contained in their products; and severe incidents having an impact on the security of their products.

    Reports must be submitted through the CRA's single reporting platform, which routes the information to ENISA and the designated national CSIRT. The main deadlines are:

    • Within 24 hours: An early warning containing the information available at that time.
    • Within 72 hours: A vulnerability notification or incident notification with more detailed information, including the nature, severity and impact of the issue and any available indicators or mitigations.
    • Actively exploited vulnerability: A final report no later than 14 days after a corrective or mitigating measure becomes available.
    • Severe security incident: A final report generally no later than one month after the 72-hour incident notification.

    Manufacturers must also inform affected users without undue delay where this is necessary to help them apply corrective or risk-mitigation measures.

    4. Product Classification and Conformity Assessment

    The applicable conformity assessment route depends on the product category and whether relevant harmonised standards, common specifications or European cybersecurity certification schemes are used:

    Product categoryIllustrative examplesGeneral conformity route
    Products not listed in Annex III or IVGeneral business software, connected consumer products and other hardware or software within the CRA's scopeInternal production control, commonly referred to as manufacturer self-assessment or Module A
    Important products - Class IIdentity and privileged-access management systems, password managers, standalone VPN products and anti-malware productsModule A may be available where the manufacturer fully applies relevant harmonised standards, common specifications or an applicable certification scheme. Otherwise, third-party assessment is required
    Important products - Class IIFirewalls, intrusion-detection or prevention systems, hypervisors, container runtime systems and certain tamper-resistant processors or microcontrollersThird-party conformity assessment, such as EU-type examination with production control or full quality assurance
    Critical productsHardware security modules, certain smart-meter gateways and smart cardsCertification requirements may be established through Commission delegated acts under an appropriate European cybersecurity certification scheme

    The examples above are illustrative. Annexes III and IV of the CRA, together with any subsequent delegated acts, should be consulted when classifying a specific product.

    A product that successfully completes the applicable conformity assessment must have an EU Declaration of Conformity and bear the CE marking before being placed on the EU market.

  • Impact on Luxembourg Organisations
    SectorPrincipal impact
    Software developers and technology vendorsCommercial software packages, libraries, SDKs, firmware and on-premises products may fall within the CRA. Vendors should introduce secure development practices, vulnerability-management processes, SBOM generation, technical documentation and the appropriate conformity assessment. Pure SaaS is not automatically within scope, although an integral remote data-processing solution may be covered.
    Financial entities subject to DORACRA-conformant products may provide useful product-security evidence for ICT procurement and third-party risk management. However, CRA conformity does not replace the financial entity's DORA obligations, contractual controls, due diligence or ongoing monitoring.
    NIS2 essential and important entitiesCRA evidence can support supply-chain security assessments. NIS2 entities may also introduce contractual requirements for vulnerability disclosure, security updates, support periods and access to appropriate component or SBOM information.
    ImportersLuxembourg importers placing products from outside the EU on the market must verify the applicable conformity assessment, CE marking, EU Declaration of Conformity, technical documentation and required manufacturer information.
    DistributorsDistributors must act with due care and verify that products carry the required CE marking and are accompanied by the required information. They must not make a product available where they have reason to believe that it does not comply with the CRA.

    CRA conformity should be treated as one component of wider ICT, NIS2 and DORA risk management, rather than as a substitute for organisation-specific security controls.

  • Legislative Framework Reference
    LevelLegislation (or equivalent)Comments
    1CRA Regulation (EU) 2024/2847EU Law which entered into force on 10 December 2024. Most provisions apply from 11 December 2027. Article 14 reporting obligations apply from 11 September 2026.