Cyber Resilience Act (CRA)
Product-Level Security for the European Digital Market
The Cyber Resilience Act, Regulation (EU) 2024/2847, establishes horizontal EU cybersecurity requirements for products with digital elements.
While the NIS2 Directive and DORA primarily address the operational resilience and ICT risk management of organisations, the CRA focuses on the security of digital products placed on the EU market. It introduces requirements covering product design, development, vulnerability handling, security updates, conformity assessment and CE marking.
The CRA applies to hardware and software products made available on the EU market, including certain remote data-processing solutions that are integral to a product. Important exclusions and special rules apply, including for some medical, automotive, aviation, marine, defence and national-security products, and for free and open-source software developed or supplied outside a commercial activity.
Four Core Areas of CRA Compliance
1. Security by Design and by Default
Manufacturers must design, develop and produce products with digital elements in accordance with the essential cybersecurity requirements in Annex I. Key requirements include:
- Making products available without known exploitable vulnerabilities;
- Applying secure-by-default configurations;
- Protecting confidentiality, integrity and availability according to the product's cybersecurity risk;
- Limiting attack surfaces, including external interfaces, to what is necessary;
- Protecting data, commands, programs and configurations against unauthorised access or modification;
- Reducing the impact of security incidents through appropriate technical measures; and
- Providing security updates, including automatic updates where required or appropriate.
The precise controls depend on the product's intended purpose, operating environment and documented cybersecurity risk assessment. Encryption and automatic updates are therefore not unconditional requirements for every product.
2. Vulnerability Handling and Support
Manufacturers must maintain processes for identifying, documenting and addressing vulnerabilities throughout the declared support period. Core obligations include:
- Support period: The manufacturer must determine, document and communicate the period during which vulnerabilities will be handled. This period must normally be at least five years, unless the product is expected to be used for less than five years. Where expected use is longer, the support period should reflect that longer period.
- Security updates: Security updates must be made available without undue delay and, as a rule, free of charge. A limited exception may apply where a manufacturer and a business user agree otherwise for a tailor-made product.
- Software Bill of Materials: Manufacturers must prepare an SBOM in a commonly used, machine-readable format, covering at least the product's top-level dependencies.
- Coordinated vulnerability disclosure: Manufacturers must maintain and enforce a coordinated vulnerability disclosure policy and provide an accessible contact point through which vulnerabilities can be reported.
- Dependency monitoring: Manufacturers must assess third-party and open-source components and take appropriate action when vulnerabilities affect the product.
The CRA does not generally require manufacturers to publish their complete SBOM or provide it automatically to every customer. Access may nevertheless be addressed contractually or required by a competent authority.
3. Reporting of Actively Exploited Vulnerabilities and Severe Incidents
From 11 September 2026, manufacturers will have mandatory reporting obligations for: actively exploited vulnerabilities contained in their products; and severe incidents having an impact on the security of their products.
Reports must be submitted through the CRA's single reporting platform, which routes the information to ENISA and the designated national CSIRT. The main deadlines are:
- Within 24 hours: An early warning containing the information available at that time.
- Within 72 hours: A vulnerability notification or incident notification with more detailed information, including the nature, severity and impact of the issue and any available indicators or mitigations.
- Actively exploited vulnerability: A final report no later than 14 days after a corrective or mitigating measure becomes available.
- Severe security incident: A final report generally no later than one month after the 72-hour incident notification.
Manufacturers must also inform affected users without undue delay where this is necessary to help them apply corrective or risk-mitigation measures.
4. Product Classification and Conformity Assessment
The applicable conformity assessment route depends on the product category and whether relevant harmonised standards, common specifications or European cybersecurity certification schemes are used:
Product category Illustrative examples General conformity route Products not listed in Annex III or IV General business software, connected consumer products and other hardware or software within the CRA's scope Internal production control, commonly referred to as manufacturer self-assessment or Module A Important products - Class I Identity and privileged-access management systems, password managers, standalone VPN products and anti-malware products Module A may be available where the manufacturer fully applies relevant harmonised standards, common specifications or an applicable certification scheme. Otherwise, third-party assessment is required Important products - Class II Firewalls, intrusion-detection or prevention systems, hypervisors, container runtime systems and certain tamper-resistant processors or microcontrollers Third-party conformity assessment, such as EU-type examination with production control or full quality assurance Critical products Hardware security modules, certain smart-meter gateways and smart cards Certification requirements may be established through Commission delegated acts under an appropriate European cybersecurity certification scheme The examples above are illustrative. Annexes III and IV of the CRA, together with any subsequent delegated acts, should be consulted when classifying a specific product.
A product that successfully completes the applicable conformity assessment must have an EU Declaration of Conformity and bear the CE marking before being placed on the EU market.
Impact on Luxembourg Organisations
Sector Principal impact Software developers and technology vendors Commercial software packages, libraries, SDKs, firmware and on-premises products may fall within the CRA. Vendors should introduce secure development practices, vulnerability-management processes, SBOM generation, technical documentation and the appropriate conformity assessment. Pure SaaS is not automatically within scope, although an integral remote data-processing solution may be covered. Financial entities subject to DORA CRA-conformant products may provide useful product-security evidence for ICT procurement and third-party risk management. However, CRA conformity does not replace the financial entity's DORA obligations, contractual controls, due diligence or ongoing monitoring. NIS2 essential and important entities CRA evidence can support supply-chain security assessments. NIS2 entities may also introduce contractual requirements for vulnerability disclosure, security updates, support periods and access to appropriate component or SBOM information. Importers Luxembourg importers placing products from outside the EU on the market must verify the applicable conformity assessment, CE marking, EU Declaration of Conformity, technical documentation and required manufacturer information. Distributors Distributors must act with due care and verify that products carry the required CE marking and are accompanied by the required information. They must not make a product available where they have reason to believe that it does not comply with the CRA. CRA conformity should be treated as one component of wider ICT, NIS2 and DORA risk management, rather than as a substitute for organisation-specific security controls.
Legislative Framework Reference
Level Legislation (or equivalent) Comments 1 CRA Regulation (EU) 2024/2847 EU Law which entered into force on 10 December 2024. Most provisions apply from 11 December 2027. Article 14 reporting obligations apply from 11 September 2026.